CHICK-FIL-A recently reported a data breach involving a credential stuffing attack on its customers' online accounts, primarily affecting the Chick-fil-A One loyalty program. The attack occurred between June 17-19 and utilized credentials sourced from third-party data breaches and phishing. Stolen information may include names, email addresses, membership numbers, and partial payment card details. Affected accounts were logged out, passwords reset, and stolen balances replenished.
Although the exact number of affected individuals is unknown, estimates suggest thousands may have been impacted. The incident highlights the lucrative nature of credential stuffing attacks for cybercriminals.