Follow Us:

Go to the DFT Communications Facebook Page
Go to the DFT Communications Instagram
Go to the DFT Communications Linkedin Page
Go to the DFT Communications YouTube Channel

Call Now!  1-877-653-3100

SECURITY ALERT: Chick-Fil-No Way!

There’s Southern hospitality and then there’s inviting hackers to steal your customers’ data. Well, Chick-Fil-A didn’t GIVE data away, but a recent data breach resulted in personal information about customers in 10 states being poached.

 

Between June 17th and 19th, the company noticed unauthorized users trying to gain access using username and password combinations stolen from a third party. Using a technique called “credential stuffing”—where a known ID/password combination from one site is automatically tried at other sites—the hackers were able to access Chick-Fil-A’s loyalty accounts where they could view DOB and contact information, mobile pay information and QR codes, the last four digits of credit and debit cards, as well as gift card details.

 

In this instance, the security weaknesses are not with Chick-Fil-A, but with the third party. However, that doesn’t make customers’ “free peach shake!” or credit card details any less stolen.

 

As ever, the lesson here is to make sure to ALWAYS use multi-factor authentication and to choose different passwords for all your accounts. If a hacker has your username and your “always” password, they can steal it once and use it over and over. Bonus tip: If you’re a loyal Chick-Fil-A customer (especially in DC, IA, MD, MA, NM, NY, NC, OR, RI, or VT) log in to check out your loyalty account. Change your password immediately, and treat yourself to a combo—whether you’re celebrating or commiserating.