Chick-fil-A hit by credential-stuffing data breach exposing customer info

TL;DR Summary
Chick-fil-A disclosed a data breach after a June credential-stuffing attack on its Chick-fil-A One site/app that may have exposed customer data, including names, emails, membership numbers, mobile pay numbers, QR codes, Chick-fil-A credit, and the last four digits of card numbers, with possible birth dates, phone numbers, and addresses; affected accounts were logged out, payment methods removed, balances restored, and customers were urged to change passwords, with notices issued to residents in multiple states (including Texas and Massachusetts).
- Chick-fil-A discloses data breach after credential stuffing attacks BleepingComputer
- Chick-fil-A warns customers in 10 states after cyberattack exposed some loyalty accounts CBS News
- Cyberattack may have exposed some Chick-fil-A customer data USA Today
- Chick-fil-A says some customers’ information exposed in data breach WIS News 10
- Chick-Fil-A confirms data breach to rewards members WDTN.com
Reading Insights
Total Reads
0
Unique Readers
4
Time Saved
4 min
vs 5 min read
Condensed
91%
852 → 78 words
Want the full story? Read the original article
Read on BleepingComputer