Chick-fil-A, a popular US fast-food chain, has announced a data breach resulting from a credential stuffing attack that compromised its customers’ online accounts. The incident primarily impacted the Chick-fil-A One loyalty and rewards program.
Details of the Cyber Attack
The credential stuffing attack, executed between June 17-19, targeted the Chick-fil-A mobile application and website. Attackers used credentials obtained from third-party breaches, phishing campaigns, and malware to access customer accounts.
On July 13, Chick-fil-A confirmed that the attackers might have accessed sensitive information from the breached accounts. The exposed data includes names, email addresses, membership numbers, mobile pay numbers, partial payment card details, and even phone numbers, addresses, and birth dates in certain cases.
Company Response and Remedial Actions
In response to the breach, Chick-fil-A has logged affected users out of their accounts, reset passwords, and removed stored payment methods. They have also replenished account balances and added extra rewards for those impacted by unauthorized transactions.
The exact number of affected individuals remains uncertain, but reports to the attorneys general in Texas and Massachusetts suggest that the figure could reach thousands or tens of thousands. SecurityWeek is awaiting further updates from Chick-fil-A regarding the total number of individuals impacted.
Implications and Broader Context
Chick-fil-A operates over 3,000 restaurants with more than 200,000 employees. Credential stuffing attacks have proven to be highly profitable for cybercriminals, as demonstrated by the 2022 DraftKings attack, which resulted in significant financial gains for the perpetrators before their capture and sentencing.
This breach underlines the ongoing threat posed by credential stuffing attacks, emphasizing the need for robust cybersecurity measures to protect customer information. As similar incidents continue to occur, organizations must remain vigilant and proactive in safeguarding their data.
The incident at Chick-fil-A reflects broader challenges in the cybersecurity landscape, where companies must contend with increasingly sophisticated attacks. Ensuring the security of customer data remains a critical priority for businesses worldwide.
