Chick-fil-A Says Credential-Stuffing Attack May Have Exposed Customer Data Across 10 States

Chick-fil-A Says Credential-Stuffing Attack May Have Exposed Customer Data Across 10 States

By
Key Takeaways
  • Credential-Stuffing Attack: Attackers used usernames and passwords obtained from a third-party source to access a limited number of Chick-fil-A One loyalty accounts between June 17 and June 19.
  • Customer Data Potentially Exposed: The affected accounts may have contained names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes, the last four digits of payment card numbers, gift card balances, and, for some customers, birth dates, phone numbers, and mailing addresses.
  • Customers Notified in 10 States and D.C.: Chick-fil-A is notifying affected customers in the District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont following its investigation.
  • Company Took Remedial Steps: Chick-fil-A logged affected customers out of their accounts, removed stored payment methods, restored impacted Chick-fil-A One balances, added rewards to affected accounts, and said it is enhancing its security, monitoring, and fraud controls.
Deep Dive

A Chick-fil-A One account contains more than reward points. It can also hold payment methods, gift card balances, and enough personal information to make it worth trying a password that worked somewhere else. That, according to breach notification letters first reported by BleepingComputer, is what happened in June, when attackers used credentials stolen from an unrelated source to gain access to a limited number of customer loyalty accounts. The campaign did not depend on breaking into Chick-fil-A's systems. It depended on customers reusing passwords.

The company said it recently detected suspicious login activity involving certain accounts and opened an investigation. It determined that between June 17 and June 19, attackers carried out an automated credential-stuffing attack against its website and mobile application using usernames and passwords obtained from a third-party source. On July 13, Chick-fil-A concluded that the attackers may have accessed information stored in affected accounts.

The company is now notifying customers in the District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont.

The scope of the information depended on what customers chose to store in their accounts. According to the notification letters, the data that may have been accessed includes names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes, the last four digits of payment card numbers, and Chick-fil-A gift card balances.

For customers who had provided additional profile information, attackers also may have viewed the month and day of birth, phone number, and mailing address. There is no indication in the notification letters that full payment card numbers were exposed. Instead, the incident centers on information already available through authenticated customer accounts after successful logins.

A Familiar Attack With Familiar Assumptions

Credential stuffing has become one of the most persistent threats facing consumer-facing businesses because it exploits behavior more than technology. Attackers collect usernames and passwords leaked in unrelated breaches, then use automated tools to test those credentials across popular online services. When customers reuse passwords, even strong security inside the target company's own network may not prevent account compromise.

Chick-fil-A said the credentials used in the attack came from a third-party source rather than from its own systems. The response focused on the accounts themselves. Chick-fil-A said it forced affected customers to log out, removed stored payment methods, restored impacted Chick-fil-A One balances, and added rewards to affected accounts as compensation for the inconvenience.

"Chick-fil-A continues to enhance its security, monitoring, and fraud controls as appropriate to minimize the risk of any similar incident in the future," the company said in its notification letter.

In a separate statement provided to CBS News, the company said it had moved quickly after identifying the incident.

"We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts," the statement said. "Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted. We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day."

The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

Oops! Something went wrong