Chick-fil-A

NJCCIC Data Breach Notification

Original Release Date: 1/12/2023

Chick-fil-A has launched an investigation after multiple customers reported suspicious activity on their accounts. The customers posted on various social media platforms stating that their accounts were accessed, accrued reward points were used, and orders were placed using the saved payment method. A researcher also noted that hackers were observed selling stolen accounts on cybercriminal marketplaces for between $2-$200, depending on how much money or reward points were in the account or if a payment method was linked. The fast-food chain insists that the fraudulent activity is not due to a compromise of Chick-fil-A Inc.’s internal systems. Chick-fil-A has since disabled the creation of new accounts and banned the use of disposable email addresses. In the event that suspicious activity is detected, customers are advised to immediately change passwords, remove any stored payment methods, and review Chick-fil-A's recently launched a support webpage.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.