Chick-fil-A confirms customer accounts hacked in months-long cyberattack

Chick-fil-A logo
(Image credit: Chick-fil-A)

Hackers have been running an automated credential stuffing attack against Chick-fil-A, and selling compromised accounts on the black market, the company has confirmed to local authorities.

The fast food chain submitted a security notice with the California Attorney General’s Office, in which it said that between December 18 last year, and February 12 this year, it suffered a credential stuffing attack.

Credential stuffing is an automated attack in which the threat actors try countless username/password combinations, usually obtained from other data breaches, to see if the information obtained elsewhere was valid on the platform being attacked, too. Given that many users often go for the same username/password combination across a multitude of services, credential stuffing attacks are often a resounding success.

Sensitive data stolen

This also seems to have been the case with Chick-fil-A.

"Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between December 18, 2022 and February 12, 2023 using account credentials (e.g., email addresses and passwords) obtained from a third-party source. Based on our investigation, we determined on February 12, 2023 that the unauthorized parties subsequently accessed information in your Chick-fil-A One account," the company said.

During the attack, the threat actors got ahold of information such as user’s names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, masked credit and debit card numbers, and the amount of Chick-fil-A credits. It’s the latter that also determined the value of each individual account on the black market. The prices ranged from $2 to $200, and according to BleepingComputer, people have been using stolen accounts to make purchases. 

To tackle the issue, the company forced password resets on its customers, froze funds that were loaded into accounts, and removed any stored payment information. It also restored account balances and added rewards to people whose accounts had been compromised, even though technically, the company is not at fault here. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
Someone checking their credit card details online.
Hackers use CAPTCHA scam in PDF files on Webflow CDN to get past security systems
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
SearchGPT OpenAI
Hackers offer 20 million OpenAI credentials for sale, but it says there's no evidence of a breach
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand