Feed aggregator
Chick-fil-A loyalty accounts hijacked using stolen passwords
Fast-food chain Chick-fil-A is warning customers after attackers hijacked loyalty accounts using stolen passwords in a credential stuffing attack.
Chick-fil-A says it detected suspicious login activity against some Chick-fil-A One accounts in June and launched an investigation. The company later concluded that unauthorized parties ran an automated credential stuffing attack against its website and mobile app between June 17 and June 19, 2026, using usernames and passwords obtained from previous data breaches or other third‑party sources. Chick-fil-A says it reset passwords and ended active sessions for affected accounts while investigating the incident.
Credential stuffing is an attack where criminals take username–password pairs stolen from one service and automatically try them on many other websites and apps to see where they still work. Because many people reuse passwords, attackers often gain access to accounts without ever breaking into the company’s systems in the traditional sense.
So, some may conclude that there are two sides to this. On the one hand, customers who reuse passwords across multiple sites make credential stuffing attacks much more likely to succeed. On the other, companies also have a responsibility to put protections in place to detect and block automated credential stuffing attacks before accounts are compromised.
How it worksTo understand how it works, we’ve created a typical scenario:
- Cybercriminals obtain large lists of breached credentials from previous data breaches, dark web markets, or public dumps.
- They use automated tools to fire those credentials at login endpoints for popular services like retailers, banks, and loyalty programs.
- They take over accounts where the credentials still work, then siphon off stored value, personal data, or loyalty rewards, or resell the access to other criminals.
To a victim, this may seem like a breach at the company, but technically speaking, the cybercriminals already had the credentials and were able to enrich their database with additional information about the victims.
What do cybercriminals know about you?
Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.
According to Chick-fil-A’s breach notifications, the attackers may have accessed a combination of:
- Name and email address.
- Chick-fil-A One membership number and mobile pay number.
- QR codes associated with the account.
- The balance of any Chick-fil-A credit, such as gift cards or rewards on the account.
- The last four digits of the stored credit or debit card number.
If you saved more details in your Chick-fil-A One account, attackers may also have seen:
- Birthdate (month and day).
- Phone number.
- Physical address.
The real problem is that, over the years, we’ve designed and adopted a system that no longer works well for most people: passwords. We tell people not to reuse them and to use a password manager to keep track of unique passwords for every account. But for many people, password managers still seem complicated or untrustworthy. I’m afraid the same may turn out to be true for passkeys.
If you have or suspect you had a Chick-fil-A One account, you should act even if you haven’t received a letter.
- Set a new, unique password for your Chick-fil-A One account that you do not use anywhere else. And if you’ve used the same password elsewhere, change it on those accounts too.
- If you cannot log in because your account was locked or reset, follow Chick-fil-A’s recovery process.
- Turn on multi-factor authentication (MFA) if you haven’t already. Chick-fil-A supports MFA for Chick-fil-A One accounts using a verified mobile phone number.
- Be aware that attackers can use the exposed data to craft more convincing phishing messages and scams.
Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.
Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
Hubs outside London have made some headway in the UK fintech sector, but overall funding has dropped
Paidwork breach exposes data of 23 million users: Check if you’re affected
A data breach at Paidwork, a platform that pays people small amounts to complete online microtasks, has exposed personal and financial information of more than 23 million users.
According to public breach reports, the intrusion took place in March 2026, with the stolen database first advertised on a cybercrime forum in April as an 11 GB dump allegedly taken from Paidwork’s production systems.
The exposed data reportedly includes full names, email and home addresses, phone numbers, dates of birth, gender, education details, bank account numbers, transaction records, device and IP information, profile photos, personal interests, and passwords stored as hashes.
That is a lot of sensitive information to hand over to a site that, for many users, pays only a few cents per task.
Why this kind of breach mattersFor cybercriminals, a dataset like this is a goldmine for targeted phishing, account takeover, and identity fraud. Banking details and transaction histories can be abused directly, while combinations of email addresses, password hashes, and personal details make credential stuffing and social engineering much easier. Even if passwords were hashed with bcrypt, weak or reused passwords can still be cracked and tried elsewhere.
Many Paidwork users likely signed up with their “throwaway” email and a reused password, thinking the risk was low because the amounts involved were tiny. But attackers do not care how much you earned. They care how much they can make by abusing your data.
Data for pennies, risk for yearsMore than anything, this breach is a reminder to think critically about who you give your personal information to.
Before you hand over your full name, home address, date of birth, and bank details to a site that pays a few cents per task, ask yourself whether the trade-off is worth it.
If any service wants sensitive data, check what security and privacy commitments it makes, whether it offers meaningful support in case of a breach, and whether you can limit what you share to the minimum needed. When in doubt, keep high-value data like banking details and copies of ID reserved for organizations that genuinely need them and can be held accountable when they fail to protect them.
Check if your data was exposedWhile Paidwork has not publicly acknowledged the alleged breach, the stolen data is reportedly circulating in criminal circles, and we have indexed it in our Digital Footprint Scanner so you can check whether your information was exposed.
Use our Digital Footprint Scanner to check whether your email address appears in known breach data, including data associated with this incident. If it does, treat it as a prompt to take action rather than a cause for panic:
- Change your password on Paidwork (if you still use the service) and on any other accounts where you reused the same or a similar password.
- Enable multi-factor authentication (MFA) wherever possible, especially on email, banking, and other important accounts, and consider using a password manager to generate and store unique passwords for every site.
- Monitor bank statements for unexpected withdrawals or suspicious activity.
- Be prepared for phishing emails, texts, and phone calls. Cybercriminals can use the leaked information to make their scams more convincing.
- Consider an identity monitoring or identity theft protection service.
What do cybercriminals know about you?
Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.
Sandboxing Script Extensions with GraalVM
Article URL: https://medium.com/graalvm/sandboxing-script-extensions-with-graalvm-f192a8fb0c5f
Comments URL: https://news.ycombinator.com/item?id=49005066
Points: 1
# Comments: 0
Ask HN: People who are opposed to advertising, how do you promote your business?
How do you promote your business or yourself (your services)?
Comments URL: https://news.ycombinator.com/item?id=49005063
Points: 1
# Comments: 0
Show HN: Forkbench – a native-Mac control room for running CLI coding agent
Article URL: https://forkbench.com
Comments URL: https://news.ycombinator.com/item?id=49005061
Points: 1
# Comments: 0
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.
The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek.
Flashtools – a PNG to WebP converter that never uploads your files
Article URL: https://flashtools.app/
Comments URL: https://news.ycombinator.com/item?id=49005037
Points: 1
# Comments: 0
The Boring Frontier of Robotics
Article URL: https://www.alexinch.com/blog/boring-frontier
Comments URL: https://news.ycombinator.com/item?id=49005035
Points: 1
# Comments: 0
The Leading Deepfake Expert No Longer Trusts His Own Eyes
Article URL: https://www.nytimes.com/2026/06/14/us/ai-deepfake-hany-farid.html
Comments URL: https://news.ycombinator.com/item?id=49005018
Points: 2
# Comments: 1
Report and Recommendations for Renewing American Scientific Discovery
Article URL: https://www.whitehouse.gov/releases/2026/07/45470/
Comments URL: https://news.ycombinator.com/item?id=49005002
Points: 1
# Comments: 0
Ask HN: A Minimalist Messaging Platform
Seeking thoughts on idea of Minimalist Messaging, looking at current state of affairs especially referring to existing dominant players, none has actually hit the right balance of Privacy & Usability, we are thinking to build a platform which is minimalist , no feature bloat, Zero data selling and surveillance, no phone numbers required. Our focus is primarily on Privacy and Usability. Appreciate feedback , you can be as critical as you can, don't hesitate, thanks.
Comments URL: https://news.ycombinator.com/item?id=49004978
Points: 1
# Comments: 0
Show HN: I mapped my AI coding setup – 90 of 103 installed skills never fire
Article URL: https://github.com/Pycomet/agent-atlas
Comments URL: https://news.ycombinator.com/item?id=49004966
Points: 2
# Comments: 0
Generating optimal Minecraft farm layouts with the CP-SAT solver
Article URL: https://github.com/Serranegra/optifarm
Comments URL: https://news.ycombinator.com/item?id=49004959
Points: 1
# Comments: 0
The wall every Flutter builder hits, and the ways around it
Article URL: https://nowa.dev/blog/why-we-built-our-own-flutter-runtime/
Comments URL: https://news.ycombinator.com/item?id=49004951
Points: 1
# Comments: 0
China's AI models have Trump's AI world at war with itself
Article URL: https://www.technologyreview.com/2026/07/20/1140675/chinas-ai-models-have-trumps-ai-world-at-war-with-itself/
Comments URL: https://news.ycombinator.com/item?id=49004943
Points: 3
# Comments: 0
Ask HN: Is Your Work Stressful?
Do you regularly feel pressure at work? Why? Did you know it's the leading factor of aging?
Comments URL: https://news.ycombinator.com/item?id=49004935
Points: 1
# Comments: 0
One Too Many – Collectable Card Game (Beta Preview)
Article URL: https://onetoomany.pages.dev/
Comments URL: https://news.ycombinator.com/item?id=49004928
Points: 1
# Comments: 1
OpenAI Hacks Hugging Face, What Happened, Alignment and Paper Clips
Article URL: https://stratechery.com/2026/openai-hacks-hugging-face-what-happened-alignment-and-paper-clips/
Comments URL: https://news.ycombinator.com/item?id=49004914
Points: 2
# Comments: 0
