American fast-food restaurant chain Chick-fil-A has admitted that the info of greater than 13,000 prospects was stolen in a latest wave of credential stuffing assaults.
As first reported by BleepingComputer, the corporate disclosed in a knowledge breach notification filed with a number of legal professional common’s places of work that it detected assaults concentrating on its web site and cell app between June 17 and June 19 after figuring out suspicious login exercise towards sure Chick-fil-A One accounts.
Chick-fil-A stated the attackers used automated instruments and credentials “obtained from third-party sources” to hack Chick-fil-A One accounts and steal buyer knowledge.
“We not too long ago recognized a safety incident that will have impacted a restricted variety of Chick-fil-A One loyalty accounts. After discovering the difficulty, we instantly addressed it and took steps to safe and restore accounts. We’re additionally in direct contact with all prospects who could have been affected,” the corporate informed Bleeping Pc.
Throughout the assault, the attackers gained entry to prospects’ names, electronic mail addresses, Chick-fil-A One member numbers, Chick-fil-A credit score quantities, cell pay numbers, and final 4 digit mixtures of credit score/debit card numbers. Moreover, dates of delivery, cellphone numbers, and addresses might have been accessed in the event that they have been saved in a compromised account.
The corporate didn’t say what number of people had their knowledge compromised, however in a doc shared with BleepingComputer by the Maine Legal professional Basic’s Workplace on Wednesday, Chick-fil-A stated a complete of 13,322 folks have been affected by the ensuing knowledge breach.
In separate filings, the corporate knowledgeable the Texas Legal professional Basic’s Workplace that the info breach affected 2,182 Texans and the Massachusetts State Legislature that the breach affected 39 residents. Chick-fil-A can be sending knowledge breach notification letters to residents of the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
Following this incident, Chick-fil-A stated it has logged out all affected accounts, eliminated fee strategies, restored balances on all affected Chick-fil-A One accounts, and added reward funds to affected accounts as a method of apologizing. The accounts have been compromised utilizing stolen credentials from a third-party service, and Chick-fil-A suggested affected prospects to alter their passwords as quickly as attainable.
Chick-fil-A additionally revealed in March 2023 that hackers had stolen the private info of greater than 71,000 prospects after hacking their accounts in a separate sequence of credential stuffing assaults from December 2022 to February 2023.
Chick-fil-A, one among America’s largest quick meals firms, operates a community of greater than 3,000 eating places in the USA, Canada, Puerto Rico, the UK, and Singapore.

Safety groups doc 54% of profitable assaults and situation a warning on solely 14%. The remaining strikes invisibly by means of the atmosphere.
Picus’ whitepaper reveals the right way to take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
