
Chick-fil-A has issued a lengthy statement following a data breach impacting some loyalty members across the United States.
In a letter, dated 20 July, the fast-food titan admitted that it had ‘recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts’.
Upon discovery of this activity, Chick-fil-A immediately took steps to prevent any further unauthorised activity.
An investigation into the attack, launched by unauthorised parties, has begun, the notice stated.
Advert
A spokesperson told People Magazine that all impacted accounts in Vermont, Iowa, Rhode Island, Maryland, North Carolina, Oregon, Massachusetts, New Mexico, New York, and Washington D.C. have been secured and restored.
Operatives continue to communicate directly with all customers who may have been impacted, as per the outlet.

“We sincerely apologise for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day,” the spokesperson added.
Information that hackers may have acquired includes names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, last four digits of credit and debit card numbers, and the amount of Chick-fil-A credit (e.g., e-gift card balance) on accounts, if any.
In the notice, the company said protective measures, including forcing log-outs and removing stored payment methods, were ‘immediately’ enacted and that Chick-fil-A One account balances had all been restored.
It’s understood that those who were impacted by the automated attack, thought to have taken place between 17 and 19 June, have been handed certain rewards, as per the publication.
“Chick-fil-A takes the protection of personal information seriously,” the company said in the letter.
“Chick-fil-A continues to enhance its security, monitoring, and fraud controls as appropriate to minimise the risk of any similar incident in the future.”
Anyone whose information was possibly compromised on 13 July should already have had their passwords reset, with the brand informing them to update the password to a ‘unique one’ as soon as possible.

Customers should also review account statements and credit reports; any errors should be reported to card companies or credit bureaus.
Meanwhile, identity theft or fraud should be reported to local law enforcement, the state Attorney General and the U.S. Federal Trade Commission.
“We regret that this incident occurred and apologise for any inconvenience it may cause you,” the company added.
The chain said that customers with questions can call the business at 888-201-5329 Monday through Friday from 9 a.m. to 9 p.m. ET.
FOODbible has contacted Chick-fil-A for further comment.