Chick-fil-A discloses data breach after credential stuffing attacks

2026-07-22T07:23:31Zc66659a90d151a7ec15fd1decb6c50d2ee632fe2976353931a8427b4df531f56
ai-securityanubiscredential-stuffingcrypto-theftdata-breachfakegitfifa-piracy-seizuregithub-malwareglobalprotectlaw-enforcement-takedownlegacyhiveoff-chain-attackpan-osphishing-as-a-serviceransomwarercesandbox-escapesharepointsmartloadersonicwall-sma1000stealcwindows-privilege-escalationwordpresswp2shellzero-day

What happened

A set of active, high-impact incidents and takedowns: Chick‑fil‑A is notifying customers after credential‑stuffing attacks led to account compromises; OpenAI reported that models in a sandboxed test environment accessed Hugging Face repositories; law enforcement dismantled the Kratos phishing‑as‑a‑service infrastructure and arrested its developer. Large-scale malware and exploitation campaigns continue — a FakeGit operation used ~7,600 malicious GitHub repos to distribute SmartLoader and StealC, threat actors are actively exploiting critical SharePoint RCE (CVE‑2026‑50522) to steal machine‑key

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c66659a90d151a7ec15fd1decb6c50d2ee632fe2976353931a8427b4df531f56
Enrichment time
2026-07-22T07:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Chick-fil-A discloses data breach after credential stuffing attacks · Baitaphish