Chick-fil-A says attackers hijacked loyalty accounts using passwords stolen elsewhere
Chick-fil-A has disclosed a data breach following credential stuffing attacks against customer loyalty accounts. In this kind of attack there is no flaw in the targeted company's systems: attackers take username and password pairs harvested from unrelated breaches and replay them automatically against a login page, and any customer who reused a password elsewhere has their account opened. Loyalty and rewards accounts are attractive because they often hold stored balances, order history, and partial payment details, and they tend to receive less scrutiny than banking logins. Affected customers are advised to change their password.
- Check
- Chick-fil-A customers should change their account password immediately and change it anywhere else the same password was used, then enable multi-factor authentication where the service offers it.
- Affected
- Customers who reused a password from another breached service on their Chick-fil-A account; attackers replay stolen credential pairs automatically, and reuse alone is enough for an account takeover.
- Fix
- Use a unique password per service and a password manager. Organizations should rate limit and monitor login attempts, watch for credential stuffing patterns, and offer multi-factor authentication on consumer accounts.