Law firm investigates possible class action for Texas, Massachusetts Chick-fil-A customers
A law firm is investigating a potential class-action lawsuit following a cyberattack that exposed information tied to some Chick-fil-A One loyalty accounts.
On behalf of Chick-fil-A One account holders in Texas and Massachusetts who received data breach notifications after the June incident, Dapeer Law, P.A. announced it is reviewing potential legal claims.
According to Chick-fil-A, hackers used usernames and passwords that had been stolen or exposed elsewhere to try to access customer accounts between June 17 and June 19. The company said it determined on July 13 that attackers may have accessed information in affected accounts and began notifying impacted customers on July 20.
State filings obtained by the law firm indicate 2,221 people were affected, including 2,182 in Texas and 39 in Massachusetts.
The information that may have been accessed varies by state but could include names, email addresses, Chick-fil-A One membership numbers, mobile payment information, QR codes, the last four digits of payment card numbers, gift card balances and, for customers who stored the information, phone numbers, addresses and birth dates.
The law firm said it is evaluating whether Chick-fil-A's account security measures met legal standards during the credential-stuffing attack. The investigation does not mean a lawsuit has been filed or that Chick-fil-A has been found liable.
In a previous statement to CBS News, Chick-fil-A said it identified a security incident affecting a limited number of loyalty accounts, secured impacted accounts and notified affected customers.
"We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts," the company said. "Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted. We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day."
Chick-fil-A has encouraged affected customers to reset their passwords, use a unique password that is not shared with other websites, and monitor their Chick-fil-A One accounts, bank accounts and credit card statements for suspicious activity. The company also forced affected users to log out of their accounts, removed stored payment methods and restored impacted Chick-fil-A One balances.
