TL;DR for CISOs: Chick-fil-A confirmed a credential stuffing breach of loyalty accounts, Swiss manufacturer Stadler Rail refused a $12.3 million ransom after a supplier platform was compromised, and South Korea disclosed that a diplomat training system sat in an attacker's hands for nearly ten months. The common thread is identity and access: reused passwords, supplier credentials, and a foothold no one watched.
- Credential stuffing keeps working because most consumer and workforce accounts still allow password-only logins. Optional MFA protects almost no one at scale. Treat MFA enforcement, bot mitigation, and breached-credential screening as a single program, not three projects.
- Your suppliers' shared platforms are part of your attack surface. Stadler's own systems were clean, yet a partner's stolen login exposed technical data and triggered an eight-figure extortion demand. Map every third-party data exchange and the credentials that reach it.
- Dwell time is still the quiet killer. A ten-month intrusion found by an outside agency, not the victim, is a detection and telemetry failure more than a patching failure. Assume a zero-day will land and invest in seeing what happens after the first login.
Lead story: Chick-fil-A confirms credential stuffing breach of loyalty accounts
- Automated credential stuffing ran against Chick-fil-A's website and mobile app between June 17 and June 19, 2026, using username and password pairs sourced from earlier third-party breaches.
- The company determined on July 13, 2026 that attackers may have accessed information in affected Chick-fil-A One accounts.
- Exposed fields can include name, email, membership and mobile pay numbers, account QR codes, stored Chick-fil-A credit balance, and the last four digits of a saved card. Birth date, phone number, and address were exposed where a customer had saved them.
- A Texas Attorney General filing lists 2,182 affected residents. Notifications also went to Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island. No national total has been disclosed.
- Multi-factor authentication is available for Chick-fil-A One accounts through a verified mobile number, but it is not required.
What happened
Chick-fil-A, which operates more than 3,000 restaurants across the United States, Canada, Puerto Rico, the United Kingdom, and Singapore, began notifying customers after spotting unusual sign-in activity on some Chick-fil-A One accounts. The investigation traced the activity to a three-day burst of automated logins in mid-June that relied on credentials stolen from other services. This is account takeover through password reuse rather than a direct intrusion into Chick-fil-A's back-end systems.
The chain says it signed affected users out, cleared stored payment methods, restored loyalty balances, and added rewards to the affected accounts. It has not stated how many accounts were taken over nationwide. For context, a similar wave against Chick-fil-A in late 2022 and early 2023 reached more than 71,000 accounts, so the current per-state filings are likely a floor rather than the full picture.
Evidence
Verified against two independent sources:
- BleepingComputer: Chick-fil-A discloses data breach after credential stuffing attacks
- Malwarebytes: Chick-fil-A loyalty accounts hijacked using stolen passwords
What this means for your team
A loyalty program looks low-stakes until you notice what sits inside the account: partial card data, stored value, and enough personal detail to power convincing follow-on phishing. Attackers monetize takeovers by draining balances and reselling working credentials, and every reused password in your customer base is a standing liability you did not create but still own. The lesson translates directly to workforce identity. If your own single sign-on, VPN, or remote access still permits password-only authentication for any population, you are running the same exposure Chick-fil-A just disclosed, only against systems that matter more.
- Find every login surface that still accepts a password alone, customer-facing and internal, and set a date to make MFA or passkeys the default rather than an option.
- Put bot mitigation and rate limiting in front of authentication endpoints so a credential stuffing run trips a control before it succeeds, not after account takeover.
- Screen new and changed passwords against known-breached credential lists, and alert on login patterns that show many accounts hit from few sources.
- Rehearse the customer response: forced logout, payment method removal, balance restoration, and clear notification language you can send within hours.
Supporting story: Stadler Rail rejects $12.3 million ransom after a supplier platform breach
- The Everest extortion group demanded roughly $12.3 million, quoted as 10 million Swiss francs, from Stadler Rail.
- Access was gained through compromised login credentials for a data exchange platform shared with one of Stadler's suppliers. The incident occurred in mid-July.
- Stadler says only non-security-relevant technical information was taken from the supplier and that no relevant personal data was involved.
- The company's own IT systems and global production were not affected and continue to operate normally.
- Stadler states it will not pay under any circumstances and has filed a criminal complaint with the Thurgau cantonal police. Everest has not publicly claimed the attack.
What happened
Stadler Rail is a large Swiss manufacturer of trains, trams, and signaling systems, with about 18,000 employees and annual revenue above $4.9 billion. The company reports that attackers used valid credentials for a shared supplier platform to reach technical data, then sent an extortion letter demanding a multi-million-franc payment. Everest is a group that dropped file encryption in 2020 and now runs pure data-theft extortion, at times buying access or stolen data from other actors to fuel its campaigns.
Notably, Stadler drew a firm public line by refusing to negotiate and reporting the matter to police. This mirrors the pattern in our earlier Breach Watch coverage of the Accenture intrusion, where the initial compromise and the extortion narrative moved on separate tracks.
Evidence
Verified against two independent sources:
- BleepingComputer: Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
- SWI swissinfo.ch: Cyberattackers demand CHF10m from Swiss train maker Stadler
What this means for your team
Stadler did almost everything right on its own perimeter, and it still ended up in an extortion negotiation because a partner's credential was the way in. Shared data exchange platforms are convenient and easy to forget, and they rarely carry the same identity controls as your core systems. When a supplier's login is the key, the blast radius is defined by whatever that platform can reach, not by how strong your internal defenses are. The refusal to pay is a defensible stance, but it only holds up when the data at risk is genuinely low-value and you can prove your own environment stayed clean.
- Inventory every third-party file exchange, portal, and collaboration platform that holds or moves your data, and record which accounts can reach it.
- Require phishing-resistant authentication on those shared platforms and confirm your supplier contracts allow you to mandate it.
- Classify what actually sits on each shared platform so that, if it is stolen, you can state the sensitivity quickly and set your negotiation stance from evidence.
- Pre-agree your ransom position with legal and executives now, so a refusal is a prepared policy rather than a decision made under pressure.
Supporting story: South Korea diplomat training system was breached for nearly ten months
- The Korea National Diplomatic Academy's online training system was compromised from April 2025 through February 2026, close to ten months.
- Roughly 10,000 records of current and retired diplomats are believed to have been affected.
- The attacker exploited a zero-day flaw in the server software plus weak security settings to seize control in April or May 2025, then continued access using legitimate software privileges.
- The system stored training videos along with names and usernames. According to Yonhap, identification numbers, mobile numbers, and home addresses did not appear to be affected.
- The foreign ministry was alerted by an outside government agency in early February, not by its own monitoring. The system remains offline and North Korean involvement has not been ruled out.
What happened
A training platform used to educate South Korean diplomats and senior officials was under an attacker's control for the better part of a year. The intrusion started with a zero-day the software vendor did not know about, which meant no patch existed at the time. After the initial break-in, the attacker blended in by using legitimate access privileges, which made the activity hard to separate from normal use. The breach came to light only when a separate government body flagged abnormal access, and five months later the system is still down while the investigation continues.
Evidence
Verified against two independent sources:
- Korea JoongAng Daily: Diplomatic academy training platform hacked for nearly 10 months
- The Star (Bloomberg): Hacker breaches South Korean database of nearly all diplomats
What this means for your team
Two details deserve a CISO's attention. First, the attacker converted a zero-day into a long stay by pivoting to legitimate credentials, so the detection problem became a behavior problem rather than a signature problem. Second, an outside party found it. When someone else spots your intrusion, it usually means your own logging, retention, or analytics did not cover the systems that were hit. Training and education platforms are easy to treat as low-risk, yet this one held the personal data of a nation's diplomatic corps. The value of a system is set by the data inside it, not by how central it looks on the org chart.
- Extend detailed authentication and access logging to secondary systems such as training, HR, and vendor portals, and keep the logs long enough to reconstruct a months-long intrusion.
- Build detections for valid credentials behaving abnormally, such as unusual times, volumes, or source locations, since post-exploitation often looks like normal use.
- Assume a zero-day will eventually hit an internet-facing service and rehearse how you would contain and investigate before a patch exists.
- Review which second- and third-tier applications hold sensitive personal data and pull them into the same monitoring tier as crown-jewel systems.
Also notable
Ranked but lighter items from the same reporting window. Threat-actor claims are labeled as claims.
- A critical ServiceNow AI Platform pre-authentication flaw (CVE-2026-6875, CVSS 9.5) is under active exploitation. Cloud instances were patched automatically; self-hosted deployments must update. Source
- OpenAI reported that its AI models broke into the Hugging Face repository during sandboxed internal testing, a controlled red-team result rather than a live breach. Source
- A reported breach at microtask platform Paidwork is said to expose personal and financial data of more than 23 million users. Source
- Accenture has confirmed an isolated breach; a threat actor claims to be selling roughly 35GB of source code and secrets, a figure the company has not verified. Source
FAQ
What is credential stuffing?
Credential stuffing is an attack where criminals take username and password pairs stolen from one service and use automated tools to try them on many other sites and apps. It succeeds when people reuse the same password across accounts, so attackers gain access without breaking into the target's own systems.
Was Chick-fil-A itself hacked?
Not in the traditional sense. The attackers used credentials stolen elsewhere to log into Chick-fil-A One accounts, so the failure was account takeover through password reuse and optional MFA rather than a direct intrusion into Chick-fil-A's back-end infrastructure.
Why does the Stadler Rail incident matter if its own systems were fine?
Because the entry point was a supplier's compromised login to a shared platform. It shows that third-party data exchanges are part of your attack surface, and that a partner's weak credential can trigger an extortion event even when your internal defenses hold.
How did the South Korea breach go undetected for ten months?
The attacker exploited a zero-day for initial access, then used legitimate access privileges to blend in with normal activity. The breach was found only after an outside agency reported abnormal access, which points to gaps in the ministry's own detection and logging.
What is the single most useful action from today's edition?
Make strong, phishing-resistant authentication the default across every login surface, customer-facing and internal, and pair it with monitoring for valid credentials behaving abnormally. Identity was the weak link in all three stories.
Curated by Pritha Aash, Community Head, CISO Platform.
Explore more in the Breach Intelligence hub and our earlier edition on the WordPress wp2shell RCE and Craneware data theft.
Join a vendor-neutral community of senior security leaders who share what actually works.
Join the CISO Platform community (free)
Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Comments