Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: credential-stuffing (2 articles)Clear

Chick-fil-A says attackers hijacked loyalty accounts using passwords stolen elsewhere

Chick-fil-A has disclosed a data breach following credential stuffing attacks against customer loyalty accounts. In this kind of attack there is no flaw in the targeted company's systems: attackers take username and password pairs harvested from unrelated breaches and replay them automatically against a login page, and any customer who reused a password elsewhere has their account opened. Loyalty and rewards accounts are attractive because they often hold stored balances, order history, and partial payment details, and they tend to receive less scrutiny than banking logins. Affected customers are advised to change their password.

Check
Chick-fil-A customers should change their account password immediately and change it anywhere else the same password was used, then enable multi-factor authentication where the service offers it.
Affected
Customers who reused a password from another breached service on their Chick-fil-A account; attackers replay stolen credential pairs automatically, and reuse alone is enough for an account takeover.
Fix
Use a unique password per service and a password manager. Organizations should rate limit and monitor login attempts, watch for credential stuffing patterns, and offer multi-factor authentication on consumer accounts.

Dashlane locks out users after external brute-force attack triggers automated account suspensions; no system compromise, accounts restored

Password manager Dashlane locked out multiple users after an external brute-force attack triggered its automated account-suspension defenses. Affected users received emails about suspicious access requests and device-registration codes from foreign locations they did not initiate, prompting confusion about whether the messages were themselves phishing. Dashlane confirmed the suspensions were a built-in security response to credential-stuffing-style login attempts and said there is no evidence its systems were compromised. The company opened an investigation on May 31 at 15:19 UTC and marked it resolved by 22:30 UTC, with all affected accounts unsuspended. The episode shows account-lockout defenses working as designed, though the user-experience and phishing-confusion fallout is real.

Check
If your team uses Dashlane and saw lockouts, confirm accounts are restored and that the device-registration emails were legitimate, not phishing. Verify no unauthorized devices were registered.
Affected
Dashlane users targeted by external credential-stuffing/brute-force. No Dashlane system compromise reported; risk is account-takeover attempts and phishing confusion from legitimate-but-unexpected security emails.
Fix
Enable the strongest available MFA on Dashlane. Use a unique high-entropy master password. Treat unexpected device-registration codes as suspicious and verify via Dashlane's status page, not email links.