Photo: NoDerog / iStock Unreleased / Getty Images
Chick-fil-A recently experienced a data breach affecting its loyalty program, Chick-fil-A One, exposing sensitive customer information. Between June 17 and 19, unauthorized parties used credentials obtained from a third-party source to launch an automated attack on the company's website and mobile app. The breach potentially exposed names, email addresses, loyalty membership numbers, and the last four digits of credit and debit card numbers.
The company confirmed the breach on July 13 and took immediate action by forcing logouts on affected accounts, removing stored payment methods, and resetting impacted customers' passwords. Chick-fil-A also restored affected account balances and added rewards as a gesture of appreciation. Customers are urged to update their passwords and monitor their accounts for suspicious activity.
The breach affected customers in 10 states, including Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont, and Washington, D.C. According to a letter sent to the Massachusetts Attorney General, Chick-fil-A continues to enhance its security measures to prevent future incidents.
Chick-fil-A encourages customers to remain vigilant against potential identity theft and to review their credit reports and account statements. For more information, customers can contact Chick-fil-A's toll-free number at (888) 201-5329, available Monday through Friday from 9 a.m. to 9 p.m. Eastern Time.