bleeping-computer · Crawled Jul 22, 2026

Chick-fil-A discloses data breach after credential stuffing attacks

Read original article ↗

AI Summary

Chick-fil-A disclosed a data breach affecting an undisclosed number of customers following credential stuffing attacks between June 17 and June 19, 2026. The attackers used stolen credentials from third-party sources to gain unauthorized access to Chick-fil-A One accounts via the company's website and mobile app. Exposed data includes personal information such as names, email addresses, membership numbers, QR codes, partial card numbers, and in some cases, birth dates, phone numbers, and addresses.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.