Skip to content
Rush Commerce
Commerce & Retail Tech3 min read

Chick-fil-A credential stuffing: your loyalty app is money

Attackers ran stolen passwords against Chick-fil-A One accounts for three days in June, reaching stored credit and saved cards. Loyalty balances are cash.

Nobody breached Chick-fil-A. No zero-day, no ransomware, no vendor compromise. Attackers took username and password pairs stolen from somewhere else, replayed them against the Chick-fil-A One website and app, and walked into the accounts where customers had reused a password. Credential stuffing against a loyalty program is the least sophisticated attack in the catalog, and it works because loyalty balances are spendable money sitting behind a single reused password.

What actually happened

Chick-fil-A disclosed that unauthorized parties ran an automated credential stuffing attack against its site and mobile app between June 17 and June 19, 2026, using credentials obtained from prior breaches and other third-party sources. The company spotted suspicious login activity, and on July 13 determined that account data may have been accessed. Notifications went to attorneys general in a dozen-plus states; BleepingComputer reports the filings cover more than 13,000 customers, including 2,182 in Texas and 39 in Massachusetts.

What was in those accounts is the part retailers should read twice: names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers and QR codes, the amount of Chick-fil-A credit on the account, and the last four digits of the saved card. Birth dates, phone numbers, and addresses were exposed where customers had stored them. Chick-fil-A logged affected accounts out, stripped saved payment methods, restored balances, and added rewards as compensation.

It's also the second time. Credential stuffing hit the same program between December 2022 and February 2023, affecting more than 71,000 accounts. Three years and a full remediation cycle later, the same technique landed again — which tells you this is a structural property of consumer loyalty apps, not a one-off failure.

Why loyalty account takeover matters for your business

If you run a rewards program, a store-credit balance, a gift card system, or saved payment methods, you're running a financial product with a fast-food login page in front of it. Attackers don't need your card numbers. Stored value converts to product immediately, and a QR code that pays at the counter is a bearer instrument. Your fraud loss shows up as inventory, not chargebacks, so it's easy to miss for weeks.

Three controls do most of the work here, and none of them require a new vendor. First, rate-limit and fingerprint the login endpoint — credential stuffing is high-volume, low-success traffic, and a failure-rate spike per IP, ASN, or device is a detection you can build in an afternoon. Second, check new and changed passwords against known-breached lists at signup and reset; the k-anonymity API from Have I Been Pwned lets you do it without ever sending the password. Third, put a step-up in front of the actions that move value: adding a payment method, transferring credit, redeeming a large balance, or logging in from a new device. Full MFA on a fast-food app is a conversion tax nobody will accept. A one-time code on the three actions that actually cost you money is not.

Key takeaways

  • Attackers ran credential stuffing against Chick-fil-A One's site and app June 17–19, 2026 using passwords stolen elsewhere; filings with state AGs cover more than 13,000 customers
  • Exposed data included membership and mobile pay numbers, QR codes, stored credit balances, and the last four digits of saved cards
  • The same program was hit the same way in 2022–2023, affecting over 71,000 accounts — this is structural, not a one-time miss
  • For your business: rate-limit and fingerprint logins, screen passwords against breach lists, and require step-up verification for payment changes, credit transfers, and new-device logins

If your customers can store value or a card in your app, you're running a financial product. We build the login hardening, velocity detection, and step-up flows that keep loyalty balances from becoming someone else's inventory. Have us review your customer accounts or see what we've built for retail.

Sources: BleepingComputer — disclosure, BleepingComputer — scope.

  • #credential-stuffing
  • #loyalty-program
  • #account-takeover
  • #retail-security
  • #ecommerce
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.