


























Chick-fil-A is notifying customers after cybercriminals gained access to some Chick-fil-A One loyalty accounts in a credential stuffing attack last month.
According to the company, attackers used login credentials obtained from a third-party source between June 17 and June 19, 2026 to attempt automated logins against the company's website and mobile app. The suspicious activity was later investigated, and on July 13 Chick-fil-A determined that unauthorized parties may have accessed customer information stored in affected accounts.
“We recently identified suspicious login activity to certain Chick-fil-A One accounts”, the notice reads. “Upon discovery of this activity, Chick-fil-A immediately took steps to prevent any further unauthorized activity and began an investigation. Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source. Based on our investigation, we determined on July 13, 2026 that the unauthorized parties may have accessed information in your Chick-fil-A One account.”
Depending on what customers stored in their accounts, the restaurant chain says attackers may have accessed:
If available in affected accounts, attackers may also have viewed:
The company has not said how many customers were affected overall, although filings with the Texas Attorney General indicate that 2,182 Texas residents were impacted. Notification letters have also been sent to residents in several other states in the US including Iowa, Maryland, Massachusetts, Columbia, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont.
It’s important to note that Chick-fil-A says the attackers did not obtain customer passwords from its own systems.
Instead, criminals used credentials stolen during previous breaches elsewhere and tested them against Chick-fil-A accounts.
This technique, known as credential stuffing, continues to be a successful form of account takeover because many people still use the same password across multiple websites.
If a password from an old shopping site, forum, or social media account is leaked, criminals immediately try that same email and password combination on banking apps, streaming services, airline accounts, loyalty programs, retailers, and food delivery platforms.
Sometimes they only need one login to succeed.
If you want to read more on how cybercriminals can compromise your online accounts, check out this article on account takeover attacks:
What Is Account Takeover (ATO) And How to Protect Against It
Explore how ATO attacks work, how to identify them and learn good online practices you can adopt to protect your data, identity, and finances.
Alina BÎZGĂ

Restaurant loyalty accounts may not seem valuable at first glance, but they often contain much more than reward points.
Many include saved payment methods, billing information, personal details, and digital wallets that can be abused before the legitimate owner notices anything unusual.
Even when payment card numbers aren't fully exposed, criminals can steal rewards, place fraudulent orders, collect personal information for future phishing campaigns, or combine the stolen data with information from other breaches to build more complete identity profiles.
This isn't the first time Chick-fil-A has faced this type of attack. In 2023, the company disclosed that more than 71,000 customer accounts were compromised in a similar credential stuffing campaign that allowed attackers to access personal information and spend stored rewards balances.
Following the incident, Chick-fil-A says it has:
Even if you don't have a Chick-fil-A account, credential stuffing affects anyone who reuses passwords.
To reduce your risk:
Credential stuffing attacks usually begin long before criminals target a company like Chick-fil-A. The stolen usernames and passwords often come from breaches that took place months or even years earlier. That's why it's important to know when your personal information appears in a newly discovered breach.
Bitdefender Digital Identity Protection continuously monitors whether your email addresses, passwords, and other personal information have been exposed in known data breaches. It also alerts you when your credentials appear online, helps you understand which accounts are at risk, and provides clear recommendations so you can secure them before attackers reuse that information in credential stuffing attacks.
When combined with unique passwords and multi-factor authentication, monitoring your digital identity can significantly reduce the chances of an old breach leading to a new account takeover.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。