HackingStolen CredentialsCustomer Data InvolvedMulti-Stage ChainCREDENTIALSFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
CHICK-FIL-A, INC.
bd_66680285719ef5a4 · schema v1 · pii pii-v1
Full breach record for CHICK-FIL-A, INC. →Chick-fil-A, Inc. notified the NH Attorney General of a data security incident involving unauthorized access to Chick-fil-A One accounts. Attackers used stolen credentials from a third-party source to access customer data between Dec 18, 2022 and Feb 12, 2023. 82 NH residents were affected. Data included credentials, payment info, and account balances. Chick-fil-A engaged forensic investigators, reset passwords, and froze funds.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_23e77871aa354f09Montana State AGfiled 2023-03-02Candidate
- bd_42d822511a7bfe74California State AGfiled 2023-03-02Verified
- bd_891cc84d4663e788Maine State AGfiled 2023-03-02Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/chick-fil-a-20230302.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2023
- Raw hash
- 6ed852425174f01b3afa9303762d3e2bad4935ffcf472e2465fe42dbf07a8034
Reporting entity
- Name
- CHICK-FIL-A, INC.norm: chick fil a
Victim entity
- Name
- CHICK-FIL-A, INC.norm: chick fil a
Incident
- Discovered
- Feb 12, 2023
- Materiality determined
- Feb 12, 2023
- Notification sent
- Mar 2, 2023
- Affected individuals
- 82
- Data types
- CREDENTIALSFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 18 days(18 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.