인기 패스트푸드 체인 칙필레(Chick-fil-A)가 최근 자사 웹사이트와 모바일 앱을 겨냥한 해킹 공격으로 고객 개인정보가 유출됐다고 밝히며 주의를 당부했다. 이번 유출 사고로 워싱턴 DC와 메릴랜드주를 포함해 총 10개 주의 칙필레 로열티 프로그램 회원들이 직간접적인 피해를 본 것으로 나타났다.
22일 칙필레가 피해 고객들에게 발송한 안내문에 따르면, 이번 사건은 해커들이 외부 제3자 출처에서 확보한 이메일 주소와 비밀번호를 활용해 무단으로 로그인하는 이른바 ‘자동화 계정 침입 공격(Credential Stuffing)’ 방식으로 발생했다.
자체 조사 결과 해커들은 고객들의 ‘칙필레 원(Chick-fil-A One)’ 계정에 접근해 고객 성명과 전화번호, 주소, 기프트카드 잔액, 신용카드 마지막 4자리 숫자 등을 열람했거나 확보한 것으로 확인됐다. 일부 고객의 경우 계정에 저장되어 있던 적립금이나 기프트카드 금액을 실제로 도난당하는 피해를 보기도 했다.
사태를 인지한 칙필레 측은 즉시 보안 조치에 나섰다고 설명했다. 피해가 의심되는 계정의 접속을 강제로 종료하고 계정에 저장된 결제 수단을 전면 삭제했으며, 무단 도용된 계정의 적립금과 기프트카드 잔액을 원래대로 원상 복구했다. 이에 더해 피해를 입은 회원들의 비밀번호를 초기화하고 추가 보상 리워드를 지급했다.
칙필레 관계자는 유사한 사고의 재발을 막기 위해 보안 시스템과 모니터링을 대폭 강화하고 사기 방지 제어 기능을 확대하고 있다고 밝혔다. 한편 보안 전문가들은 타 사이트와 동일한 계정 정보(이메일·비밀번호)를 사용하는 이용자들에게 즉각적인 비밀번호 변경과 함께 주기적인 결제 내역 확인을 권고했다.
Chick-fil-A Alerts D.C., Maryland, and Other Customers to Data Breach
Chick-fil-A is warning customers after a cyberattack targeted its website and mobile app, resulting in a breach of personal information. The incident affects members of the fast-food chain's loyalty program across 10 states, including Maryland and Washington, D.C.
According to a notice sent to affected customers on July 22, the compromise occurred through a "credential stuffing" attack, in which hackers used email addresses and passwords obtained from an unrelated third-party source to gain unauthorized access to accounts.
A company investigation revealed that the attackers may have accessed member information within "Chick-fil-A One" accounts, including customer names, phone numbers, addresses, gift card balances, and the last four digits of stored credit card numbers. In some cases, unauthorized parties successfully stole funds from customer accounts.
Chick-fil-A stated that it took immediate protective action upon discovering the breach. The company forcibly logged out affected accounts, removed all saved payment methods, and fully restored stolen gift card and account balances. Additionally, Chick-fil-A reset passwords for the impacted accounts and credited members with promotional rewards as compensation.
Company officials noted that security systems, monitoring protocols, and fraud controls are actively being enhanced to minimize the risk of future incidents. Meanwhile, cybersecurity experts advise users who share credentials across multiple websites to update their passwords immediately and regularly review their transaction history.