**US fast-food chain Chick-fil-A has disclosed a data breach stemming from a credential stuffing attack targeting its customers’ online accounts. **

According to notifications sent to affected individuals, the attack targeted accounts on the Chick-fil-A One loyalty and rewards program.

Threat actors conducted credential stuffing attacks against the Chick-fil-A mobile app and website on June 17-19, using credentials obtained from third-party sources, which can include data breaches at other companies, phishing campaigns, and data collected by infostealer malware.

On July 13, the fast-food chain determined that the attackers may have obtained data stored in the compromised accounts.

Stolen data can include names, email addresses, Chick-fil-A membership numbers and mobile pay numbers, partial payment card numbers, account balances, and in some cases phone numbers, addresses, and dates of birth.

Affected accounts have been forcefully logged out, their passwords have been reset, and payment methods stored in them have been removed. For accounts drained by the attackers, balances have been restored and additional rewards have been added.

It’s unclear how many individuals are affected, but based on the numbers submitted to the attorneys general in Texas and Massachusetts, thousands or tens of thousands may be affected.

SecurityWeek has reached out to Chick-fil-A for information on how many people are impacted and will update this article if the company responds.

Chick-fil-A has more than 3,000 restaurants and over 200,000 team members.

Credential stuffing attacks can be highly lucrative for cybercriminals. The 2022 DraftKings attack enabled three hackers to make hundreds of thousands of dollars. However, they have all been identified and sentenced to prison.

Related: Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses

Related: Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

Related: Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife