Chick-fil-A data breach: What impacted customers need to do

Chick-fil-A reported that a security incident is impacting some of its customers' accounts, according to a letter sent to customers on Monday.

What we know:

The Atlanta-based fast food chain stated that it found suspicious login activity for certain Chick-fil-A One Loyalty accounts.

Chick-fil-A stated it took "immediate" steps to address the issue by securing and restoring accounts. 

The letter also added that after the company launched an investigation, it found hackers attacked its website and mobile app between June 17 and June 19 using account credentials from a third-party source. On July 13, the company found out that hackers might have accessed data from customers' Chick-fil-A One accounts. 

Chick-fil-A added that customers' names, addresses, last four digits of credit/debit card numbers, phone numbers, and email addresses might have been involved in the security incident. 

The data breach notification listed Washington, D.C., and nine other states, including North Carolina, New Mexico, Oregon, and New York, as the locations where residents need to take protective action against potential identity theft and fraud. 

What we don't know:

While Chick-fil-A confirmed that account balances have been restored, the company did not disclose exactly how many customers were affected or the specific identity of the third-party source where the hackers originally obtained the login information. 

What they're saying:

A Chick-fil-A spokesperson released the following statement: 

"We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted. We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day."

What's next:

Customers who were impacted were asked to update their Chick-fil-A password and use a strong and unique password. Chick-fil-A has also provided a reference guide to monitor and protect personal information.

Customers who were impacted and have questions can contact the company's toll-free number at 888-201-5329. 

The Source: The information in this story was gathered from the Massachusetts Office of Consumer Affairs Data Breach Information website and a statement from a Chick-fil-A spokesperson. 

Chick-fil-AAtlantaData BreachesNewsBusiness