Feed aggregator

Chick-fil-A loyalty accounts hijacked using stolen passwords

Malware Bytes Security - Wed, 07/22/2026 - 8:46am

Fast-food chain Chick-fil-A is warning customers after attackers hijacked loyalty accounts using stolen passwords in a credential stuffing attack.

Chick-fil-A says it detected suspicious login activity against some Chick-fil-A One accounts in June and launched an investigation. The company later concluded that unauthorized parties ran an automated credential stuffing attack against its website and mobile app between June 17 and June 19, 2026, using usernames and passwords obtained from previous data breaches or other third‑party sources. Chick-fil-A says it reset passwords and ended active sessions for affected accounts while investigating the incident.

Credential stuffing is an attack where criminals take username–password pairs stolen from one service and automatically try them on many other websites and apps to see where they still work. Because many people reuse passwords, attackers often gain access to accounts without ever breaking into the company’s systems in the traditional sense.

So, some may conclude that there are two sides to this. On the one hand, customers who reuse passwords across multiple sites make credential stuffing attacks much more likely to succeed. On the other, companies also have a responsibility to put protections in place to detect and block automated credential stuffing attacks before accounts are compromised.

How it works

To understand how it works, we’ve created a typical scenario:

  • Cybercriminals obtain large lists of breached credentials from previous data breaches, dark web markets, or public dumps.
  • They use automated tools to fire those credentials at login endpoints for popular services like retailers, banks, and loyalty programs.
  • They take over accounts where the credentials still work, then siphon off stored value, personal data, or loyalty rewards, or resell the access to other criminals.

To a victim, this may seem like a breach at the company, but technically speaking, the cybercriminals already had the credentials and were able to enrich their database with additional information about the victims.

What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

SCAN NOW

According to Chick-fil-A’s breach notifications, the attackers may have accessed a combination of:

  • Name and email address.
  • Chick-fil-A One membership number and mobile pay number.
  • QR codes associated with the account.
  • The balance of any Chick-fil-A credit, such as gift cards or rewards on the account.
  • The last four digits of the stored credit or debit card number.

If you saved more details in your Chick-fil-A One account, attackers may also have seen:

  • Birthdate (month and day).
  • Phone number.
  • Physical address.
Advice for Chick-fil-A customers

The real problem is that, over the years, we’ve designed and adopted a system that no longer works well for most people: passwords. We tell people not to reuse them and to use a password manager to keep track of unique passwords for every account. But for many people, password managers still seem complicated or untrustworthy. I’m afraid the same may turn out to be true for passkeys.

If you have or suspect you had a Chick-fil-A One account, you should act even if you haven’t received a letter.

  • Set a new, unique password for your Chick-fil-A One account that you do not use anywhere else. And if you’ve used the same password elsewhere, change it on those accounts too.
  • If you cannot log in because your account was locked or reset, follow Chick-fil-A’s recovery process.
  • Turn on multi-factor authentication (MFA) if you haven’t already. Chick-fil-A supports MFA for Chick-fil-A One accounts using a verified mobile phone number.
  • Be aware that attackers can use the exposed data to craft more convincing phishing messages and scams.
Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Categories: Malware Bytes

Hubs outside London have made some headway in the UK fintech sector, but overall funding has dropped

Computer Weekly Feed - Wed, 07/22/2026 - 8:36am
Hubs outside London have made some headway in the UK fintech sector, but overall funding has dropped
Categories: Computer Weekly

Paidwork breach exposes data of 23 million users: Check if you’re affected

Malware Bytes Security - Wed, 07/22/2026 - 7:34am

A data breach at Paidwork, a platform that pays people small amounts to complete online microtasks, has exposed personal and financial information of more than 23 million users.

According to public breach reports, the intrusion took place in March 2026, with the stolen database first advertised on a cybercrime forum in April as an 11 GB dump allegedly taken from Paidwork’s production systems.

The exposed data reportedly includes full names, email and home addresses, phone numbers, dates of birth, gender, education details, bank account numbers, transaction records, device and IP information, profile photos, personal interests, and passwords stored as hashes.

That is a lot of sensitive information to hand over to a site that, for many users, pays only a few cents per task.

Why this kind of breach matters

For cybercriminals, a dataset like this is a goldmine for targeted phishing, account takeover, and identity fraud. Banking details and transaction histories can be abused directly, while combinations of email addresses, password hashes, and personal details make credential stuffing and social engineering much easier. Even if passwords were hashed with bcrypt, weak or reused passwords can still be cracked and tried elsewhere.

Many Paidwork users likely signed up with their “throwaway” email and a reused password, thinking the risk was low because the amounts involved were tiny. But attackers do not care how much you earned. They care how much they can make by abusing your data.

Data for pennies, risk for years

More than anything, this breach is a reminder to think critically about who you give your personal information to.

Before you hand over your full name, home address, date of birth, and bank details to a site that pays a few cents per task, ask yourself whether the trade-off is worth it.

If any service wants sensitive data, check what security and privacy commitments it makes, whether it offers meaningful support in case of a breach, and whether you can limit what you share to the minimum needed. When in doubt, keep high-value data like banking details and copies of ID reserved for organizations that genuinely need them and can be held accountable when they fail to protect them.

Check if your data was exposed

While Paidwork has not publicly acknowledged the alleged breach, the stolen data is reportedly circulating in criminal circles, and we have indexed it in our Digital Footprint Scanner so you can check whether your information was exposed.

Use our Digital Footprint Scanner to check whether your email address appears in known breach data, including data associated with this incident. If it does, treat it as a prompt to take action rather than a cause for panic:

  • Change your password on Paidwork (if you still use the service) and on any other accounts where you reused the same or a similar password.
  • Enable multi-factor authentication (MFA) wherever possible, especially on email, banking, and other important accounts, and consider using a password manager to generate and store unique passwords for every site.
  • Monitor bank statements for unexpected withdrawals or suspicious activity.
  • Be prepared for phishing emails, texts, and phone calls. Cybercriminals can use the leaked information to make their scams more convincing.
  • Consider an identity monitoring or identity theft protection service.

What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

SCAN NOW

Categories: Malware Bytes

Ask HN: People who are opposed to advertising, how do you promote your business?

Hacker News - Wed, 07/22/2026 - 7:31am

How do you promote your business or yourself (your services)?

Comments URL: https://news.ycombinator.com/item?id=49005063

Points: 1

# Comments: 0

Categories: Hacker News

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

Security Week - Wed, 07/22/2026 - 7:29am

CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.

The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek.

Categories: SecurityWeek

The Boring Frontier of Robotics

Hacker News - Wed, 07/22/2026 - 7:27am
Categories: Hacker News

Ask HN: A Minimalist Messaging Platform

Hacker News - Wed, 07/22/2026 - 7:22am

Seeking thoughts on idea of Minimalist Messaging, looking at current state of affairs especially referring to existing dominant players, none has actually hit the right balance of Privacy & Usability, we are thinking to build a platform which is minimalist , no feature bloat, Zero data selling and surveillance, no phone numbers required. Our focus is primarily on Privacy and Usability. Appreciate feedback , you can be as critical as you can, don't hesitate, thanks.

Comments URL: https://news.ycombinator.com/item?id=49004978

Points: 1

# Comments: 0

Categories: Hacker News

Ask HN: Is Your Work Stressful?

Hacker News - Wed, 07/22/2026 - 7:17am

Do you regularly feel pressure at work? Why? Did you know it's the leading factor of aging?

Comments URL: https://news.ycombinator.com/item?id=49004935

Points: 1

# Comments: 0

Categories: Hacker News

Pages