HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
CHICK-FIL-A, INC.
bd_42d822511a7bfe74 · schema v1 · pii pii-v1
Full breach record for CHICK-FIL-A, INC. →Chick-fil-A, Inc. disclosed that unauthorized parties launched an automated attack against its website and mobile application between December 18, 2022, and February 12, 2023. The attackers used account credentials (email addresses and passwords) obtained from a third-party source to access Chick-fil-A One accounts. Affected data included names, email addresses, membership numbers, masked payment card numbers, and potentially phone numbers and addresses. Chick-fil-A responded by resetting passwords, removing stored payment methods, and freezing account funds.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_23e77871aa354f09Montana State AGfiled 2023-03-02Candidate
- bd_66680285719ef5a4New Hampshire State AGfiled 2023-03-02Verified
- bd_891cc84d4663e788Maine State AGfiled 2023-03-02Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-563781
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2023
- Raw hash
- 7169cf5dc51308e976851938f7cb5794979e290ddfa37ae027b58d77442309f4
Reporting entity
- Name
- CHICK-FIL-A, INC.norm: chick fil a
Victim entity
- Name
- CHICK-FIL-A, INC.norm: chick fil a
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Mar 2, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.