Framing Analysis
Chick-fil-A detected an automated credential-stuffing attack on its website and app between Friday and Sunday that used third-party credentials. The company notified affected customers in 10 states and the District of Columbia after concluding on July 13 that some account data may have been accessed. Actions taken include forced logouts, removal of stored payment methods, password resets, and restoration of loyalty balances with added rewards.