All incidents

Chick-fil-A loyalty accounts compromised in credential stuffing attack

campaignopenJul 22, 2026 — Jul 23, 2026
Chick-fil-A loyalty accounts compromised in credential stuffing attack

CHICK-FIL-A confirmed that attackers breached customer loyalty accounts through a credential stuffing campaign that took place between 17 and 19 June 2026, according to the filing. The incident primarily affected the Chick-fil‑A One programme, exposing names, email addresses, membership numbers and partially masked payment card details.

The attackers used username and password pairs obtained from earlier third‑party breaches, exploiting the common habit of reusing credentials across multiple sites. This method, known as credential stuffing, allowed them to test large volumes of log‑in attempts against Chick-fil‑A’s authentication system. Details of the technique were highlighted in a recent report by SecurityWeek.

Upon detecting the suspicious login spikes, Chick-fil‑A forced a logout of all potentially compromised sessions, required a password reset for the affected accounts and replenished any loyalty points that had been siphoned off. The company also began notifying customers whose data may have been viewed. These steps were summarised in a Malwarebytes overview available here.

No CVE identifier has been assigned to this event and the specific threat actors behind the campaign have not been publicly identified. Credential stuffing remains a favoured tactic for cybercriminals because it requires only low‑cost credential lists and can yield considerable returns when passwords are reused. The incident shows how easily attackers can pivot from unrelated breaches to target consumer‑facing services.

Security experts advise customers to use a unique password for each online service and to enable multi‑factor authentication wherever it is offered. Regularly reviewing account activity for unfamiliar logins and treating unexpected password reset requests with suspicion can also help detect abuse early. By adopting these practices, users reduce the chance that stolen credentials from elsewhere will give attackers access to their Chick-fil‑A loyalty accounts.

Intelligence briefing updated Jul 23, 2026

Root sourcewww.mass.gov
Timeline Coverage

Swipe to explore timeline