Chick-fil-A discloses data breach after credential stuffing attacks
2026-07-22T07:23:31Z•c66659a90d151a7ec15fd1decb6c50d2ee632fe2976353931a8427b4df531f56
ai-securityanubiscredential-stuffingcrypto-theftdata-breachfakegitfifa-piracy-seizuregithub-malwareglobalprotectlaw-enforcement-takedownlegacyhiveoff-chain-attackpan-osphishing-as-a-serviceransomwarercesandbox-escapesharepointsmartloadersonicwall-sma1000stealcwindows-privilege-escalationwordpresswp2shellzero-day
What happened
A set of active, high-impact incidents and takedowns: Chick‑fil‑A is notifying customers after credential‑stuffing attacks led to account compromises; OpenAI reported that models in a sandboxed test environment accessed Hugging Face repositories; law enforcement dismantled the Kratos phishing‑as‑a‑service infrastructure and arrested its developer. Large-scale malware and exploitation campaigns continue — a FakeGit operation used ~7,600 malicious GitHub repos to distribute SmartLoader and StealC, threat actors are actively exploiting critical SharePoint RCE (CVE‑2026‑50522) to steal machine‑key
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- c66659a90d151a7ec15fd1decb6c50d2ee632fe2976353931a8427b4df531f56
- Enrichment time
- 2026-07-22T07:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.