❌

Normal view

Weekly Update 514: This Week in Data Breaches

26 July 2026 at 09:14
Weekly Update 514: This Week in Data Breaches

The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted. You've got them leading with "don't worry, your credit card is fine", the hacker leading with "they didn't respond when I tried to report it", and now news that the two parties have "come to an agreement". Maybe money was paid, or maybe Origin made some promises to restrain the hounds if commitments about data deletion were made. But both outcomes, of course, provide no guarantee that data has been nuked, so now they get to spend perpetuity waiting for the data that maybe - just maybe - it leaks. And we all should be working on precisely that assumption, just like we did with Optus and Medibank and Latitude and Ticketek and Qantas...

Weekly Update 514: This Week in Data Breaches
Weekly Update 514: This Week in Data Breaches
Weekly Update 514: This Week in Data Breaches
Weekly Update 514: This Week in Data Breaches

References

  1. Sponsored by: CoreView: Misconfigurations in Microsoft 365 leave doors open. Scan your tenant for free.

Chick-fil-A Data Breach Explained: What Customers Need to Know

24 July 2026 at 18:44

This week in scams and cybersecurity news,  

Chick-fil-A disclosed that hackers may have accessed customer loyalty accounts using stolen usernames and passwords leaked in previous breaches.  

It’s a reminder that reusing passwords across websites can be dangerous and allow one breach to snowball into many others. 

Here’s what happened and what customers need to know: 

So How Did Hackers Breach Chick-fil-A? 

Chick-fil-A is notifying customers in 10 states after a cyberattack targeted a limited number of Chick-fil-A One loyalty accounts. 

According to multiple reports, attackers used a technique known as credential stuffing, in which criminals take usernames and passwords stolen in previous data breaches and automatically test them across other websites and apps.  

If someone has reused the same password, attackers may be able to access additional accounts without ever hacking the company directly. 

Chick-fil-A said the attackers may have accessed customer information including: 

  • Names and email addresses  
  • Chick-fil-A One membership numbers  
  • Mobile Pay numbers and QR codes  
  • The last four digits of stored payment cards  
  • Gift card balances  
  • Birth dates, phone numbers, and addresses (if customers stored them)  

The company says it has logged affected users out of their accounts, removed stored payment methods, restored impacted rewards balances, and is notifying customers who may have been affected. 

Credential stuffing: 
A cyberattack where criminals use usernames and passwords stolen in previous data breaches to automatically sign in to other websites and apps. If you’ve reused the same password across multiple accounts, one breach can give attackers access to many of them. 
How to Protect Yourself: Use a unique password for every account, enable multi-factor authentication, and use a password manager to securely create and store strong passwords. 

How McAfee Helps Before, During, and After a Data Breach 

Before a breach 

Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you. 

Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info. 

Password Manager helps you create and securely store strong, unique passwords for every account, reducing the risk that one stolen password can unlock multiple accounts.  

During a breach 

Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.  

Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t. 

After a breach 

Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even more of your information. 

Other Scam News This Week 

Student loan scams are on the rise. Experts warn that changing federal student loan repayment rules are creating confusion that scammers are exploiting with fake debt relief offers, phishing emails, and identity theft schemes targeting borrowers. (PBS News) 

AI agent reportedly carried out a cyberattack. AI platform Hugging Face says an autonomous AI agent executed a sophisticated attack against its internal systems from start to finish; an early example of AI taking on an active role in cyberattacks rather than simply assisting human hackers. (Axios) 

Paidwork breach reportedly exposes 23 million users. Security researchers say data from the microtask platform may include names, addresses, phone numbers, bank account details, and password hashes, highlighting how even smaller online accounts can become valuable targets for cybercriminals. (Malwarebytes) 

And we’ll be back next week with more news.  

The post Chick-fil-A Data Breach Explained: What Customers Need to Know appeared first on McAfee Blog.

❌