DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsData ExfiltratedTargetedIdentity (basic)Financial accountPIIMediumContained

CHICK-FIL-A, INC.

bd_156aec3386b43664 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 12, 2023

Filed

Mar 3, 2023

To disclose

19 days

Affected

2,801state residents only

Linked

6 filings

Confidence

64%
Full breach record for CHICK-FIL-A, INC.2 incidents on file

Chick-fil-A, Inc. notified customers of a supplemental data security incident involving unauthorized access to Chick-fil-A One accounts. Attackers used credentials from a third-party source to access accounts between Dec 18, 2022 and Feb 12, 2023. Data accessed included names, emails, membership numbers, and masked payment card info. Chick-fil-A engaged forensic investigators, reset passwords, and froze accounts.

South Carolina clock SC CRA notice due19 days discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 56 days
discovery → filing · 19 days

Dec 18, 2022

Begins

Feb 12, 2023

Discovered

Mar 3, 2023

Filed

vs. sector median

5 wks faster

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 1d gap

Filing propagation · 6 filings · 6 states

View merged incident ↗
Montana State AGMar 2 · first
California State AGMar 2 · first
Maine State AGMar 2 · first
South Carolina State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.