If you’ve eaten at Chick-fil-A lately, your spicy chicken sandwich might have come with something extra – and it isn’t waffle fries.
The country’s most popular chicken sandwich chain just got hit with a data breach targeting its most loyal customers. Chick-fil-A disclosed the incident this week, noting that it identified “suspicious login activity” on some of its Chick-fil-A One rewards program accounts last month.
After conducting an investigation, the fast food chain determined that hackers mounted an automated attack against its website and app for three days in mid June, using a list of email logins and passwords obtained through a third party. The company is letting customers know that the unauthorized users may have gained access to data stored in their Chick-fil-A One rewards program accounts, including names, email addresses, phone numbers, birth dates, addresses, and the last four digits of credit card numbers.
“Chick-fil-A takes the protection of personal information seriously,” the company said in a statement published to its website. “As soon as Chick-fil-A discovered the incident, we immediately took action to protect customers’ accounts, which included forcing log-outs of affected accounts and removing any stored payment methods. We also restored impacted customers’ Chick-fil-A One account balances.”
One login to rule them all
The technique used in the Chick-fil-A breach, known as credential stuffing, happens when hackers leverage a large list of stolen username and password combinations to see what other accounts they can gain access to. Because people reuse passwords, one set of credentials often unlocks unrelated accounts – a good reminder not to share your chicken sandwich loyalty program password with the account you use to monitor your 401K.
Based on the notification letters from the company, the breach appears to have affected Chick-fil-A customers in D.C., Maryland, Iowa, Vermont, Massachusetts, New Mexico, New York, North Carolina, Oregon, and Rhode Island. The company is encouraging customers who belong to its loyalty program to update their passwords to something unique, a step that can prevent hackers from using stolen databases to easily crack open online accounts.
Chick-fil-A encourages customers to sign up for its loyalty program to order ahead for pickup and to reap rewards like free sides and desserts. Through its app, loyalty program members collect points with their purchases that they can spend toward free items in the future. Loyalty apps have exploded in the fast food space in recent years as a way for brands to boost retention and capture more information about customers and their behavior. Fast food chains can also target discounts and special offers specifically to customers willing to sign up and hand over some data – a juicy offer with inflation cutting into even the cheapest tier of restaurant experience.
Much like the rest of the data we give up online, loyalty programs come with trade-offs. Chick-fil-A is reassuring customers that its breach is now handled, but no data is safe in the digital world – not even your stash of chicken sando points.
“As an additional way to say thank you for being a loyal Chick-fil-A customer, we have added rewards to your account,” the company said in its letter notifying customers. “Chick-fil-A continues to enhance its security, monitoring, and fraud controls as appropriate to minimize the risk of any similar incident in the future.”