Chick-fil-A Loyalty Accounts Breached Again by Stolen Password Attack

Chick-fil-A is notifying customers across at least ten US states that attackers broke into Chick-fil-A One loyalty accounts using a credential stuffing attack, the same technique that compromised more than 71,000 accounts at the chain in 2023.

The company says unauthorized parties ran an automated attack against its website and mobile app between June 17 and June 19, testing username-and-password combinations pulled from unrelated third-party breaches rather than from any compromise of Chick-fil-A's own systems. An investigation concluded on July 13 that some of those login attempts succeeded, giving attackers access to whatever information customers had stored in their accounts: names, email addresses, loyalty and mobile pay numbers, QR codes, gift card and rewards balances, the last four digits of payment cards, and in some cases birth dates, phone numbers, and home addresses.

Chick-fil-A has forced password resets and logged out affected accounts, but hasn't disclosed how many customers nationwide were affected; state breach filings so far show at least 2,182 in Texas and 39 in Massachusetts, with notifications also sent to residents of the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont.

Credential stuffing doesn't rely on breaching a company's defenses at all. It exploits password reuse, feeding stolen login pairs from other services into automated bots until a match unlocks an account elsewhere. Chick-fil-A One offers multi-factor authentication through a verified phone number, but doesn't require it, the same gap that left accounts exposed to both this attack and the 2023 incident. Enabling it takes under two minutes and would block this specific attack method going forward. Anyone who reuses passwords across services, and stores payment or loyalty balances in return, remains exposed to the same technique on any other account, regardless of the brand behind it.