A law firm is exploring legal action against Atlanta-based Chick-fil-A after a cybersecurity incident exposed information tied to some Chick-fil-A One loyalty accounts.
The investigation centers on a June cyberattack that targeted the restaurant chain’s rewards program. According to Chick-fil-A, unauthorized users gained access to a limited number of customer accounts through an automated “credential stuffing” attack, a method that uses email addresses and passwords previously exposed in unrelated data breaches.
The company said the incident occurred between June 17 and June 19. Information that may have been accessed includes customers’ email addresses, phone numbers, mailing addresses, birth dates (month and day only), Chick-fil-A One account details, and the last four digits of stored payment cards. Chick-fil-A says it secured affected accounts, restored impacted rewards balances, and notified customers who may have been affected.
Florida-based Dapeer Law, P.A. has announced it is investigating a possible class-action lawsuit on behalf of affected customers. The firm is encouraging individuals who received a Chick-fil-A data breach notification to determine whether they may qualify to participate if litigation moves forward.
Chick-fil-A emphasized that it acted quickly after discovering the breach, stating that protecting customer information remains a top priority. The company apologized for the incident and said it continues working to maintain the trust of its customers.
While the full scope of the breach has not been publicly disclosed, the incident serves as another reminder for consumers to use unique passwords, enable multi-factor authentication whenever available, and regularly monitor online accounts for suspicious activity
(Photo by Gary Hershorn/Getty Images)
















No comments