Updated
Updated · FOX 5 Atlanta · Jul 22
Chick-fil-A Says Hackers Hit Loyalty Accounts in 10 States Using June 17-19 Stolen Logins
Updated
Updated · FOX 5 Atlanta · Jul 22

Chick-fil-A Says Hackers Hit Loyalty Accounts in 10 States Using June 17-19 Stolen Logins

3 articles · Updated · FOX 5 Atlanta · Jul 22

Summary

  • Chick-fil-A told customers hackers may have accessed data in some Chick-fil-A One loyalty accounts, including names, addresses, phone numbers, emails and the last four digits of payment cards.
  • June 17-19 attacks on the chain’s website and mobile app used credentials obtained from a third-party source, and Chick-fil-A said it detected possible account data access on July 13.
  • 10 jurisdictions — Washington, D.C., plus states including North Carolina, New Mexico, Oregon and New York — were listed in breach notices urging residents to guard against identity theft and fraud.
  • Chick-fil-A said it secured and restored affected accounts and balances, but did not disclose how many customers were affected or identify the third-party source of the stolen login information.
  • Impacted customers were told to reset passwords, use strong unique credentials and monitor personal information as the company contacts those potentially affected.

Insights

After a second breach in three years, is Chick-fil-A’s security fundamentally flawed?
Who is more to blame for data breaches: companies or users who reuse passwords?
As cyberattacks evolve, are passwords finally becoming obsolete for protecting our data?