Skip to content
The Nexus
SECURITYJul 22 · 12:46 UTCMALWAREBYTES LABS

Chick-fil-A loyalty accounts hijacked using stolen passwords

Chick-fil-A warned customers about a credential stuffing attack on its loyalty accounts between June 17 and June 19, 2026, where attackers used stolen passwords from previous breaches to hijack accounts. The company reset passwords and ended active sessions for affected accounts, and breach notifications indicated potential access to personal and financial information.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting