Chick-Fil-A Data Breach Exposes Customer Payment Data

Chick-Fil-A is warning customers their data may have been compromised in a recent breach.
According to the restaurant chain, suspicious login activity occurred on a Chick-Fil-A One account, enabling an unauthorized user to access customer information. The information may include:
- Names
- Email addresses
- Chick-fil-A One membership numbers and credit remaining on account
- Mobile pay numbers
- QR codes
- Last four digits of credit/debit cards
Additional information at risk may include addresses, phone numbers and the month and day of birthdates.
Security Leaders Weigh In
Ted Miracco, CEO, Approov:
The advent of AI powered attacks makes it more important than ever for companies who serve consumers through mobile apps to thwart attempts by attackers to bombard their back end login APIs via automated bots, malicious scripts, or modified apps. Automated attacks will only accelerate going forward, so to protect their customers and themselves, security hygiene dictates that servers should only accept requests from genuine, untampered mobile apps that are running on safe devices.
John Strand, Owner, Black Hills Information Security:
First, are we just going to walk past the fact that Chick-fil-A was compromised through a credential stuffing attack? There are probably a hundred jokes we could make about that, but the security lesson is much more important.
Credential stuffing sits in one of those gray areas that many organizations never fully test. Most companies hiring a penetration testing firm don’t want testers launching credential stuffing attacks against production systems, and in many cases that’s the right decision. You don’t want a security assessment accidentally accessing legitimate customer accounts, especially in highly regulated industries like financial services where the legal and compliance risks can be substantial.
The problem is that attackers don’t care about those boundaries. Organizations still need to validate that they’re resilient against these attacks, whether that’s through controlled password spraying, testing for account enumeration, or simply requiring multi-factor authentication for customer accounts. I understand the hesitation around requiring MFA because of concerns about user friction, but if MFA isn’t enabled, credential stuffing remains one of the easiest ways for attackers to compromise accounts at scale.
Security teams need to pay close attention to the areas that often go untested, either because of legal concerns or internal politics. Those gray areas are exactly where attackers tend to find their opportunities.
Seemant Sehgal, Founder & CEO, BreachLock:
Credential stuffing works because most organizations treat account authentication as a solved problem. The credentials used here came from a third-party source, which means Chick-fil-A’s own security controls were likely functioning exactly as designed, and the attack succeeded anyway. When attackers can walk in with valid credentials, the question every organization with a loyalty program or mobile account layer should be sitting with is how many of their active users are also active in a breach database somewhere.
Donald McFarlane, Advisory Board Member, Xcape, Inc.:
This incident reflects how automation is changing attacker economics, making even secondary customer applications attractive targets at scale.
Companies should assume that every internet-facing system with an authentication page will be tested continuously. Security standards cannot fall sharply simply because an application generates less revenue or appears less operationally critical.
Credential stuffing is not a sophisticated or novel attack, but it remains effective at scale. Organizations should adopt phishing-resistant authentication, including passkeys where appropriate, alongside layered controls to detect and resist automated attacks. They should also minimize the data and value held in secondary applications so that a compromised account has less to expose or steal.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!








