Skip to content

ExplainerTechnologyUnited States2 min read

Chick-fil-A says a security incident may have exposed some loyalty account data. Here’s what that means.

Chick-fil-A reported that unauthorized parties accessed some Chick-fil-A One loyalty accounts in the US, potentially exposing customer data.

Share

Topics

Chick-fil-A restaurant exterior with red striped awnings and outdoor seating area.

ATLANTA, July 23 (Nationwide Times) — Chick-fil-A says a recent security incident may have exposed personal information tied to a limited number of Chick-fil-A One loyalty accounts.

The company said it moved quickly to secure the affected accounts and notify customers who may have been impacted. In a statement quoted by FOX Business, a Chick-fil-A spokesperson said, “We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts.” The spokesperson added that once the issue was discovered, the company took steps to “immediately address, secure and restore accounts” and was communicating directly with customers who may have been affected.

What happened?

According to Chick-fil-A’s notice, unauthorized parties targeted the company’s website and mobile app between June 17 and June 19. Chick-fil-A said the attackers used account credentials obtained from a third-party source. The company notified potentially affected customers after it discovered suspicious login activity involving certain Chick-fil-A One accounts.

What information may have been exposed?

Chick-fil-A said the information that may have been compromised included names, email addresses, Chick-fil-A One membership and mobile payment numbers, the last four digits of payment cards, and the amount of Chick-fil-A credit stored in accounts.

The company did not say that the information was definitely misused, only that it may have been exposed.

What did Chick-fil-A do after the incident?

Chick-fil-A said it reset passwords for affected accounts, restored loyalty balances and added rewards to customer accounts. It also said it contacted customers who may have been impacted.

Is there an earlier notice?

The materials also include an earlier Chick-fil-A notice filed with Massachusetts on March 2, 2023. In that notice, the company said suspicious login activity involving certain Chick-fil-A One accounts occurred between Dec. 18, 2022, and Feb. 12, 2023. Chick-fil-A said it determined on Feb. 12, 2023, that unauthorized parties accessed information in affected accounts.

That earlier notice said the information may have included a name, email address, membership number, mobile pay number, QR code, masked card number and Chick-fil-A credit balance. It also said saved birthday month and day, phone number and address may have been included. The company said unauthorized parties could only view the last four digits of a payment card number.

The supplied materials do not make clear whether the March 2023 notice and the later June incident are separate events, part of a continuing issue, or later reporting on the same broader problem.

What is still unknown?

Chick-fil-A did not disclose the exact number of affected accounts. The company also did not say how the third-party credentials were obtained.

The source materials do not mention any criminal case, suspect, charge or court filing.

Share

Topics

Stacy Hughes

Stacy Hughes, born in the UK and residing in Maryland for the past decade, draws on her deep British roots and experience to highlight diverse cultures that have shaped the United Kingdom throughout its history and today.

Write to Stacy