Chick-fil-A data breach exposes customer accounts

2 days ago 3

Google wide counsel explains AI-powered phishing rise

Halimah Delaine Prado, Google General Counsel, reveals the emergence of AI-powered phishing scams originating from China's 'outsider enterprise.' She explains however these criminals usage artificial quality to make highly convincing fake websites, impersonating trusted brands similar T-Mobile to defraud hundreds of thousands of Americans, causing millions successful losses. Prado highlights Google's strategy to combat these evolving threats.

Your Chick-fil-A One relationship makes it casual to bid food, cod points and support outgo accusation acceptable for your adjacent visit. That convenience tin besides marque the relationship invaluable to criminals.

Chick-fil-A is present informing customers aft attackers gained entree to definite loyalty accounts. The incidental exposed idiosyncratic accusation and relationship details, portion besides raising caller concerns astir password reuse.

Even if Chick-fil-A ne'er contacted you, this breach gives you a bully crushed to reappraisal your password, stored outgo methods and caller rewards activity.

AMAZON RECALL TEXT SCAM COMES WITH RED FLAGS

Chick-fil-A

Chick-fil-A says attackers gained entree to definite Chick-fil-A One accounts utilizing login credentials stolen elsewhere. (Chick-fil-A)

CyberGuy Live: Missed "Sick of Spam?" Get the replay and checklist

Our escaped CyberGuy Live class, "Sick of Spam?" , has ended, but you tin inactive ticker the afloat replay and download our spam-stopping checklist. Kurt "CyberGuy" Knutsson walks you measurement by measurement done elemental ways to trim robocalls, spam texts, junk email and unwanted messages. You’ll besides larn however to curb governmental texts, cleanable up your inbox and spot messages that could enactment your idiosyncratic accusation astatine risk.

Get the escaped replay and checklist present astatine CyberGuyLive.com.

COULD THE 7-ELEVEN BREACH AFFECT YOU?

What happened successful the Chick-fil-A information breach

Chick-fil-A says it archetypal spotted suspicious login enactment involving definite Chick-fil-A One accounts. The institution past investigated and recovered an automated onslaught against its website and mobile app. The onslaught ran from June 17 done June 19, 2026. Chick-fil-A determined connected July 13 that unauthorized parties whitethorn person accessed accusation stored wrong affected accounts.

The attackers utilized email addresses and passwords obtained from a third-party source. They past tested those login combinations against Chick-fil-A One accounts. When a lawsuit had reused the aforesaid password, the attackers had a accidental of getting inside.

Chick-fil-A has not disclosed the full fig of affected customers. However, nationalist filings amusement that the breach affected 2,182 Texas residents and 39 Massachusetts residents. The institution besides submitted notices involving residents of Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont and Rhode Island.

WHAT A SCAMMER SEES THE MOMENT THEY GOOGLE YOUR NAME

What accusation the Chick-fil-A information breach exposed

The accusation disposable to the attackers varied by account. According to Chick-fil-A's notification, the exposed information whitethorn person included:

  • Customer names and email addresses
  • Chick-fil-A One rank numbers
  • Mobile wage numbers and relationship QR codes
  • The magnitude of Chick-fil-A recognition stored successful an account
  • The past 4 digits of a linked recognition oregon debit card
  • The period and time of a customer's birthday
  • Phone numbers and saved addresses

The notification lists lone the past 4 digits of outgo cards. It does not database afloat paper numbers, Social Security numbers oregon slope relationship details among the exposed information. Still, the different details could assistance criminals make convincing scams. A connection that includes your name, loyalty rank accusation oregon partial paper digits whitethorn consciousness legitimate. The QR codification vulnerability besides raises questions due to the fact that customers usage relationship QR codes to gain points and entree rewards. Chick-fil-A has not publically explained whether attackers utilized immoderate exposed QR codes. We reached retired to Chick-fil-A for comment, but did not perceive backmost by our deadline.

How credential stuffing opened Chick-fil-A accounts

Credential stuffing sounds technical, but the onslaught follows a elemental pattern. Criminals cod email addresses and passwords from older information leaks. Then automated tools effort those combinations crossed different websites and apps.

The onslaught works due to the fact that galore radical reuse passwords. One aged password breach tin truthful pb to relationship takeovers astatine companies that had nary transportation to the archetypal leak. Chick-fil-A says the login details utilized successful this onslaught came from a third-party source. The company's notification describes attackers arriving with stolen credentials and investigating them against its services.

That favoritism whitethorn explicate however the onslaught started. However, it offers small comfortableness erstwhile idiosyncratic gains entree to your rewards, interaction details and stored outgo information. Relying connected a username and password unsocial creates much opportunities for relationship takeovers. Multifactor authentication tin supply different obstruction erstwhile a password has already been stolen.

How Chick-fil-A responded to the relationship breach

A Chick-fil-A, Inc. spokesperson provided CyberGuy with the pursuing statement:

"We precocious identified a information incidental that whitethorn person affected a constricted fig of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to instantly address, unafraid and reconstruct accounts, and we are communicating straight with each customers who whitethorn person been impacted. We sincerely apologize for immoderate inconvenience oregon interest this concern whitethorn person caused and stay committed to maintaining the spot our guests spot successful america each day."

The company's lawsuit announcement provides respective further details. Chick-fil-A logged affected customers out, removed saved outgo methods and added rewards to their accounts.

Why this Chick-fil-A relationship onslaught feels familiar

This isn’t Chick-fil-A's archetypal large credential stuffing incident. In March 2023, the institution confirmed that attackers had accessed much than 71,000 lawsuit accounts. That earlier run ran from December 2022 done February 2023.

The attackers accessed idiosyncratic accusation and utilized stored rewards balances successful immoderate accounts. The repetition onslaught shows however agelong stolen login accusation tin stay utile to criminals. They tin support aged credential lists, harvester them with newer leaks and trial them crossed fashionable services.

A edifice loyalty relationship whitethorn look little important than your slope oregon email. Yet it tin inactive incorporate idiosyncratic information, stored funds and outgo details. It tin besides springiness an intruder clues astir different accounts you use, particularly erstwhile your email code and password look unneurotic successful respective places.

Ways to enactment harmless aft the Chick-fil-A information breach

You tin instrumentality these steps adjacent if Chick-fil-A ne'er contacted you astir the breach.

1) Change your Chick-fil-A One password

Open the authoritative Chick-fil-A app oregon benignant the company's website into your browser. Then make a caller password that you person ne'er utilized connected different account. Avoid changing 1 quality successful an older password. Criminals often trial communal variations aft a stolen password stops working. Chick-fil-A recommends utilizing a unsocial password that has nary transportation to your different online accounts.

Chick-fil-A

Chick-fil-A One accounts tin incorporate rewards balances, interaction accusation and constricted outgo details. (Chick-fil-A)

2) Replace the password anyplace you reused it

Changing lone your Chick-fil-A password leaves different accounts exposed. Update the password connected each relationship wherever you utilized the aforesaid login combination. Give precedence to your email due to the fact that an attacker tin usage it to petition password resets elsewhere. Then reappraisal accounts that store outgo methods oregon delicate idiosyncratic information. A password manager tin assistance you find reused passwords and regenerate them with unsocial ones. It besides removes the request to retrieve each login yourself.

3) Review your Chick-fil-A transaction history

Open the Chick-fil-A app and look for orders oregon equilibrium changes you bash not recognize. In the app, pat For You , past unfastened Account > Transactions > Transaction History . Chick-fil-A says customers tin reappraisal up to 1 twelvemonth of relationship activity. Check your rewards enactment separately. Someone whitethorn person redeemed oregon talented rewards without placing an evident nutrient order. Also reappraisal your telephone fig and saved addresses. Correct immoderate relationship details that idiosyncratic changed.

4) Remove stored outgo methods

Chick-fil-A says it removed saved outgo methods from affected accounts. However, you should corroborate that your cards nary longer look if you received a breach notice. To check, unfastened the app and pat For You . Then spell to Account > Payments > Manage outgo methods . Chick-fil-A advises customers to resoluteness unauthorized enactment and alteration their passwords earlier adding a outgo method again. Leaving a paper retired of a edifice app whitethorn make an other measurement astatine checkout. It besides gives an relationship thief 1 little happening to misuse.

5) Watch your slope and paper statements

The notification lists the past 4 digits of outgo cards among the accusation attackers whitethorn person accessed. Those digits unsocial usually cannot authorize a purchase. However, criminals could harvester them with different idiosyncratic details during a phishing attempt. Review caller charges and crook connected transaction alerts done your slope oregon paper issuer. Contact the fiscal instauration instantly if you find thing unfamiliar.

6) Prepare for Chick-fil-A phishing scams

A breach tin pb to a 2nd circular of occupation erstwhile criminals nonstop fake information alerts. Be cautious with emails oregon texts claiming your Chick-fil-A relationship requires contiguous action. The connection whitethorn connection a refund, replacement rewards oregon assistance restoring your balance. Avoid clicking the link. Open the authoritative Chick-fil-A app yourself oregon benignant the company's website code into your browser. Also cheque the sender's afloat email address. A acquainted logo and a polished connection supply nary warrant that Chick-fil-A sent it.

7) Use beardown antivirus protection

Credential stuffing does not necessitate malware connected your telephone oregon computer. However, criminals whitethorn travel a breach with fake information alerts designed to bargain much information. Strong antivirus bundle tin assistance pass you astir malicious links, fake websites and suspicious downloads. Keep the extortion progressive connected each instrumentality you usage to cheque email oregon entree your Chick-fil-A account. The champion mode to support yourself from malicious links that instal malware is to person beardown antivirus bundle installed connected each your devices. This extortion tin besides alert you to phishing emails and ransomware scams, helping support your idiosyncratic accusation and integer assets. Get my picks for the champion 2026 antivirus extortion winners for your Windows, Mac, Android & iOS devices astatine Cyberguy.com

8) Reduce the idiosyncratic accusation disposable online

The Chick-fil-A breach whitethorn person exposed names, telephone numbers and saved addresses for immoderate customers. Criminals tin harvester those details with accusation recovered connected information broker and people-search sites to make much believable scams. A information removal work tin nonstop removal requests to these companies and proceed checking whether your accusation returns. However, it cannot region information already taken from your Chick-fil-A relationship oregon warrant that each nationalist grounds disappears. Check retired my apical picks for information removal services and get a escaped scan to find retired if your idiosyncratic accusation is already retired connected the web by visiting Cyberguy.com

9) Turn connected multifactor authentication elsewhere

Chick-fil-A does not presently advertise a customer-facing multifactor authentication enactment for Chick-fil-A One accounts. However, you should alteration it connected your email account, fiscal services and immoderate relationship that stores delicate information. Use an authenticator app oregon passkey erstwhile available. These options supply stronger extortion than substance connection codes successful galore situations. Multifactor authentication tin artifact an intruder who has already obtained your password.

10) Protect your devices from malicious follow-up links

Credential stuffing does not necessitate malware connected your telephone oregon computer. However, follow-up phishing messages whitethorn effort to instal harmful software. Keep your phone, machine and browser updated. Use beardown antivirus extortion that tin pass you astir malicious links and downloads. Never instal an app done a nexus successful an unexpected breach notification. Use the Apple App Store oregon Google Play Store to find the authoritative version.

person typing connected  phone

Customers should alteration reused passwords and reappraisal their Chick-fil-A One accounts for unfamiliar activity. (Chick-fil-A)

Kurt's cardinal takeaways

The Chick-fil-A information breach shows however a password stolen from 1 institution tin make problems determination else. Attackers reportedly utilized credentials obtained from a 3rd party. They past tried those logins against Chick-fil-A's website and mobile app. Chick-fil-A secured the affected accounts, removed stored outgo methods and restored balances. However, the full fig of affected customers remains undisclosed. The astir important determination present involves changing immoderate reused password. Your Chick-fil-A login should person a password that appears obscurity else. You should besides reappraisal your rewards activity, relationship accusation and fiscal statements. Be acceptable for convincing phishing messages that usage details taken from the breach.

Have you ever had a loyalty relationship hacked, mislaid rewards oregon spotted relationship changes you ne'er made? Let america cognize by penning to america astatine Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

  • Get my champion tech tips, urgent information alerts and exclusive deals delivered consecutive to your inbox.
  • For simple, real-world ways to spot scams aboriginal and enactment protected, sojourn CyberGuy.com - trusted by millions who ticker CyberGuy connected TV daily.
  • Plus, you'll get instant entree to my Ultimate Scam Survival Guide escaped erstwhile you join.

Copyright 2026 CyberGuy.com. All rights reserved.

Adriana James-Rodil is simply a Production Assistant for Fox News Digital.

Read Entire Article