Chick-fil-A confirmed 71,473 accounts hit by credential stuffing
- Organization
- Chick-fil-A
- Exploit
- Credential Compromise
- Industry
- Restaurants
Chick-fil-A confirmed that an automated credential stuffing campaign ran against its website and mobile application between December 18, 2022 and February 12, 2023, reaching 71,473 Chick-fil-A One accounts. The chain set out the details in breach notices filed with several state attorneys general, including Maine.
The attackers did not break into Chick-fil-A's own systems. They used email address and password pairs obtained from a third-party source, meaning credentials leaked in unrelated breaches that customers had reused on their Chick-fil-A accounts, and tested them automatically at scale.
Information visible in a compromised account included the customer's name, email address, Chick-fil-A One membership number, QR code, mobile pay number, a masked payment card number showing only the last four digits, and any stored account credit. For some customers the birth month and day, phone number and address were also exposed. BleepingComputer reported that attackers spent stored rewards balances and that access to hijacked accounts was sold online for between $2 and $200 depending on the balance held.
Chick-fil-A said it forced password resets, removed stored payment methods, temporarily froze loaded funds and refunded or restored account balances, adding rewards to affected accounts where appropriate. Affected customers were notified directly.