Chick-fil-A credential stuffing: your loyalty app is money
Attackers ran stolen passwords against Chick-fil-A One accounts for three days in June, reaching stored credit and saved cards. Loyalty balances are cash.
Nobody breached Chick-fil-A. No zero-day, no ransomware, no vendor compromise. Attackers took username and password pairs stolen from somewhere else, replayed them against the Chick-fil-A One website and app, and walked into the accounts where customers had reused a password. Credential stuffing against a loyalty program is the least sophisticated attack in the catalog, and it works because loyalty balances are spendable money sitting behind a single reused password.
What actually happened
Chick-fil-A disclosed that unauthorized parties ran an automated credential stuffing attack against its site and mobile app between June 17 and June 19, 2026, using credentials obtained from prior breaches and other third-party sources. The company spotted suspicious login activity, and on July 13 determined that account data may have been accessed. Notifications went to attorneys general in a dozen-plus states; BleepingComputer reports the filings cover more than 13,000 customers, including 2,182 in Texas and 39 in Massachusetts.
What was in those accounts is the part retailers should read twice: names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers and QR codes, the amount of Chick-fil-A credit on the account, and the last four digits of the saved card. Birth dates, phone numbers, and addresses were exposed where customers had stored them. Chick-fil-A logged affected accounts out, stripped saved payment methods, restored balances, and added rewards as compensation.
It's also the second time. Credential stuffing hit the same program between December 2022 and February 2023, affecting more than 71,000 accounts. Three years and a full remediation cycle later, the same technique landed again — which tells you this is a structural property of consumer loyalty apps, not a one-off failure.
Why loyalty account takeover matters for your business
If you run a rewards program, a store-credit balance, a gift card system, or saved payment methods, you're running a financial product with a fast-food login page in front of it. Attackers don't need your card numbers. Stored value converts to product immediately, and a QR code that pays at the counter is a bearer instrument. Your fraud loss shows up as inventory, not chargebacks, so it's easy to miss for weeks.
Three controls do most of the work here, and none of them require a new vendor. First, rate-limit and fingerprint the login endpoint — credential stuffing is high-volume, low-success traffic, and a failure-rate spike per IP, ASN, or device is a detection you can build in an afternoon. Second, check new and changed passwords against known-breached lists at signup and reset; the k-anonymity API from Have I Been Pwned lets you do it without ever sending the password. Third, put a step-up in front of the actions that move value: adding a payment method, transferring credit, redeeming a large balance, or logging in from a new device. Full MFA on a fast-food app is a conversion tax nobody will accept. A one-time code on the three actions that actually cost you money is not.
Key takeaways
- Attackers ran credential stuffing against Chick-fil-A One's site and app June 17–19, 2026 using passwords stolen elsewhere; filings with state AGs cover more than 13,000 customers
- Exposed data included membership and mobile pay numbers, QR codes, stored credit balances, and the last four digits of saved cards
- The same program was hit the same way in 2022–2023, affecting over 71,000 accounts — this is structural, not a one-time miss
- For your business: rate-limit and fingerprint logins, screen passwords against breach lists, and require step-up verification for payment changes, credit transfers, and new-device logins
If your customers can store value or a card in your app, you're running a financial product. We build the login hardening, velocity detection, and step-up flows that keep loyalty balances from becoming someone else's inventory. Have us review your customer accounts or see what we've built for retail.
Sources: BleepingComputer — disclosure, BleepingComputer — scope.
- #credential-stuffing
- #loyalty-program
- #account-takeover
- #retail-security
- #ecommerce
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Agentic AI spending: $944B now, $3.35T by 2030 — read it right
A new PHD/WARC forecast puts agent-facilitated consumer spending at $944B in 2026, rising to $3.35T by 2030. That's 3.8% of consumer spend. Here's the operator read.
Read itInstacart buys Arpalus: who owns your shelf data?
Instacart acquired computer-vision startup Arpalus to turn 600,000 shoppers into a shelf-intelligence sensor network. If they run in your stores, they know your inventory better than you do.
Read it