Chick-fil-A accounts breached in credential stuffing attacks
Credential stuffing attacks continue targeting consumer loyalty programs, exposing how password reuse across services enables account takeovers without technical vulnerabilities.
Attack method and customer notification
Chick-fil-A notified customers of unauthorized account access following credential stuffing attacks targeting its mobile app and website. Attackers used credentials leaked from breaches at other services, attempting logins with previously exposed username-password pairs.
The restaurant chain detected the attack pattern and forced password resets for affected accounts. Customer names, email addresses, mobile app membership numbers, and mobile pay account numbers were accessible to attackers who successfully logged in.
Scope and exposed data
The breach notifications did not specify the total number of affected accounts. Chick-fil-A stated that financial information including credit card details and Social Security numbers were not exposed, as these are not stored in customer mobile app accounts.
Attackers who gained access could view stored payment methods and membership information linked to loyalty programs. The company emphasized that no system vulnerabilities were exploited—the attacks relied entirely on customers reusing passwords across multiple online services.
Response and mitigation
Chick-fil-A required password resets for compromised accounts and recommended customers enable multi-factor authentication. The company advised customers to use unique passwords for each online service and monitor their accounts for suspicious activity.
Credential stuffing attacks remain a common threat to consumer-facing platforms with loyalty programs, as attackers automate login attempts using credential databases from prior breaches at unrelated services.