Chick-fil-A Reports Data Breach in Rewards Program
Chick-fil-A has disclosed a data breach affecting its Chick-fil-A One rewards program accounts. Hackers used login credentials obtained from a third party to access customer information.

Chick-fil-A has reported a data security incident that impacted customer data within its Chick-fil-A One rewards program. The company identified suspicious login activity on accounts last month.
Following an investigation, the fast-food chain determined that hackers executed an automated attack against its website and app over three days in mid-June. The attackers utilized a list of email addresses and passwords acquired from a third party. The company indicated that unauthorized individuals may have accessed data within Chick-fil-A One accounts, including names, email addresses, phone numbers, birth dates, physical addresses, and the last four digits of credit card numbers.
Chick-fil-A stated that it takes the protection of personal information seriously. Upon discovering the incident, measures were immediately implemented to secure customer accounts. These actions included forcing logouts from affected accounts and removing stored payment methods. The company also restored the available rewards balances for impacted customers.
The attack method, known as credential stuffing, involves hackers using extensive lists of stolen username and password combinations to gain access to other accounts. This practice often exploits password reuse across different online services. Chick-fil-A is advising its loyalty program members to update their passwords to unique combinations to enhance security against such threats.