Chick-fil-A One accounts hit in credential-stuffing attack

Chick-fil-A disclosed a credential-stuffing attack June 17-19 that targeted Chick-fil-A One accounts and may have exposed names, emails, membership and mobile-pay numbers and partial card numbers.

Chick-fil-A disclosed that a credential-stuffing attack conducted June 17-19 targeted Chick-fil-A One loyalty accounts on the company’s mobile app and website. On July 13 the company determined attackers may have accessed data stored in compromised accounts.

Attackers used credentials obtained from third-party sources and ran automated login attempts against the app and site. The company’s notifications to affected customers list the types of information that may have been accessed: names, email addresses, Chick-fil-A membership numbers, mobile-pay numbers, partial payment card numbers and account balances. In some accounts phone numbers, addresses and dates of birth may also have been exposed.

Affected accounts were forcibly logged out, passwords were reset and any payment methods stored in accounts were removed. For accounts where funds were taken, balances were restored and additional rewards were added.

Chick-fil-A has not disclosed a final count of impacted accounts. Filings with the attorneys general in Texas and Massachusetts indicate the number could be in the thousands or tens of thousands. The chain operates more than 3,000 restaurants and has over 200,000 employees.

Credential stuffing uses automated tools to try large volumes of username-password combinations obtained from other breaches, phishing campaigns or malware that harvests credentials. When people reuse passwords across sites, attackers who find a matching credential can log in and access account details and stored payment information.

The company is reviewing the incident and notifying affected customers. Filings with state authorities may provide additional details as the investigation continues.

Articles by this author