CHICK-FIL-A, INC.
bd_42d822511a7bfe74 · schema v1 · pii pii-v1
Full breach record for CHICK-FIL-A, INC. →2 incidents on fileChick-fil-A, Inc. disclosed that unauthorized parties launched an automated attack against its website and mobile application between December 18, 2022, and February 12, 2023. The attackers used account credentials (email addresses and passwords) obtained from a third-party source to access Chick-fil-A One accounts. Affected data included names, email addresses, membership numbers, masked payment card numbers, and potentially phone numbers and addresses. Chick-fil-A responded by resetting passwords, removing stored payment methods, and freezing account funds.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 18, 2022
Begins
Mar 2, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Massachusetts State AGbd_032b3c5f38078c962023-03-02Verified
- Montana State AGbd_23e77871aa354f092023-03-02Candidate
- New Hampshire State AGbd_66680285719ef5a42023-03-02Verified
- Maine State AGbd_891cc84d4663e7882023-03-02Candidate
Show 1 more filing ↓Show fewer ↑up to 1d gap
- South Carolina State AGbd_156aec3386b436642023-03-03 · +1dVerified
Filing propagation · 6 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.