Chick-fil-A Breach: Credential Stuffing Hits 13,000 Accounts
Chick-fil-A confirmed attackers used credential stuffing to access over 13,000 customer accounts via its website and mobile app in a three-day window in June.
Chick-fil-A has confirmed that credential stuffing attacks on its website and mobile app between June 17 and June 19 compromised more than 13,000 customer accounts. Customer notification letters are going out this week.
Credential stuffing doesn’t require finding a vulnerability in the target’s own systems. Attackers take username-and-password pairs harvested from unrelated breaches — widely available in bulk — and test them at scale against the login forms of other services. It works because password reuse across accounts remains common enough to make the math reliable. The target’s security controls are beside the point; the weak link is the user’s credential hygiene elsewhere.
Thirteen thousand accounts is a contained number relative to the scale of Chick-fil-A’s app user base. That could reflect effective rate limiting during the attack window, a narrow or lower-quality credential list on the attacker’s end, or confirmed-compromise figures that don’t capture the full volume of probed accounts. Chick-fil-A hasn’t released technical details about detection or the attack surface, so the disclosed count is what we have to work with.
What gets exposed in a restaurant loyalty account takeover varies by app, but typically includes at minimum name, email, phone number, and order history — the data these programs are built around. Chick-fil-A hasn’t published a field-by-field breakdown of what attackers could read. Customers should assume their profile data was accessible during the three-day window.
The attack ran June 17–19. Notifications are arriving in late July — five weeks after the window closed. That’s consistent with standard incident-response timelines for consumer account compromises: log triage, forensic scope confirmation, legal review, and state breach notification deadlines tend to compress into a 30-to-60-day arc before disclosure goes out. It’s not fast, but it’s not irregular either.
The same disclosure pattern appeared this week with OnTrac’s network breach, where the parcel delivery company notified customers of exposed PII after a corporate network intrusion. Different attack method, same roughly five-to-six-week notification cycle. Consumer-facing businesses appear to be running on the same incident-response clock regardless of how the intrusion happened, which is worth noting — the window between breach and disclosure is long enough for attackers to monetize access well before affected customers know to act.
Credential theft campaigns have been active across multiple vectors this week. Attackers have also been hijacking hotel and conference-center Wi-Fi DNS settings to redirect users to fake Microsoft 365 login pages — a different mechanism, but the same end goal of capturing usable credentials at scale.
If you have a Chick-fil-A One account: change your password now and check whether you’ve reused that credential anywhere else. Monitor your inbox and phone for phishing or vishing that uses your name or order details — personalized lures are harder to catch than generic ones.
Found this useful? Share it.


