
Chick-fil-A hit by credential-stuffing data breach exposing customer info
Chick-fil-A disclosed a data breach after a June credential-stuffing attack on its Chick-fil-A One site/app that may have exposed customer data, including names, emails, membership numbers, mobile pay numbers, QR codes, Chick-fil-A credit, and the last four digits of card numbers, with possible birth dates, phone numbers, and addresses; affected accounts were logged out, payment methods removed, balances restored, and customers were urged to change passwords, with notices issued to residents in multiple states (including Texas and Massachusetts).
