Sometimes you want a quick bite to eat. So you hop online, create an account for your favorite joint, and get to ordering. But a lot of people make a major mistake while doing this—which some Chick-fil-A customers just found out the hard way.
On Wednesday, news broke about a Chick-fil-A data breach, with customers in ten states and the District of Columbia affected. But unlike many breaches, the fast food chain’s security wasn’t at fault. Instead, their customers’ habits were.
Hackers used an approach called credential stuffing, where an attacker plugs in stolen or leaked usernames and passwords into different websites. Because people often reuse passwords, other accounts often unlock.
This intrusion into Chick-fil-A customer accounts occurred between June 17 and 19. Confirmation from Chick-fil-A came on July 13. Data that may have been accessed includes names, membership numbers, email addresses, Mobile Pay numbers, QR codes, last four digits of saved credit or debit cards, gift card balances, and if added to the account, birth date, phone number, and physical address.
Notification letters have been sent to customers in Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont, and Washington D.C. In addition to the notifications, Chick-fil-A has removed saved payment info and logged users out of accounts.
If you’ve been affected, take these steps to protect yourself:
- Change your Chick-fil-A password to a unique one
- Same for any other sites tied to a reused password
- Watch for odd account activity on all sites you frequent
- Monitor for suspicious activity on your bank and credit card accounts
- Be wary of email or messages related to Chick-fil-A, particularly ones that ask you to click on links
Not convinced you can remember a ton of unique passwords? Let a password manager take care of that for you. Google or Apple’s built-in services are good enough and seamless. You tap, the phone auto-creates and saves the strong, unique password, and you’re done.
You can get more flexibility with a third-party app like Bitwarden, but if you’re already reusing passwords, any reputable password manager will be fine. Using one stops credential stuffing attacks cold—and by extension, keeps more of your data from appearing on the dark web. Don’t end up making yourself an easier mark for personalized scams.


