Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
A huge debate is brewing in Silicon Valley over the proliferation of Chinese-made artificial intelligence tools, particularly “open-weight” AI systems that, by some measures, can compete with or even outperform some of the best US models. My WIRED colleague Hugo Lowell has written about the Trump administration’s internal debate on how to handle these Chinese models. Among AI companies in the Valley, the issue is proving even more divisive.
A top concern in both DC and the Valley relates to distillation, in which a less capable AI model is trained on the outputs of a more powerful one. In June, Anthropic accused the Chinese tech giant Alibaba of illicitly stealing its IP through distillation attacks. Then, earlier this week, the White House said that it believes the Beijing-based Moonshot AI had developed its Kimi K3 model by distilling Anthropic’s Fable 5 model.
Another big concern is how quickly China’s models are appearing and spreading. An open-weight AI model has its core components made public, so that it can be fine-tuned to suit a user’s needs. But they don’t have the kinds of guardrails on which Anthropic has been building its reputation. Yasir Atalan, deputy director and data fellow at the Center for International and Strategic Studies, points out that the main benefit of open-weight AI models is their speed of diffusion. They can spread especially easily “through Hugging Face, GitHub, cloud providers, local deployments, and third-party inference platforms,” he writes. If you’re Anthropic, and you’ve built a cult around safety and charge for access to your big expensive proprietary models, you have every reason to want to regulate this.
But some Silicon Valley startups—not the trillion-dollar ones like OpenAI and Anthropic—really don’t want the US government to put restrictions on these AI models. On Wednesday a group of over 200 startups called the Little Tech Association sent a letter to Michael Kratsios, science adviser to President Donald Trump, and US Commerce Secretary Howard Lutnick lobbying against an outright ban of open-weight AI models. The group, which includes famed startup incubator YCombinator, has argued in favor of certain safeguards but says that denying Americans access to AI models abroad would weaken US startups and create a monopoly among the AI giants.
Bill Gurley, the legendary tech investor and longtime partner at Benchmark Capital, has publicly argued in favor of letting “the free market work.” In a lengthy blog that offers a nice little history of open-source software, Gurley writes that open-weight models avoid lock-in, encourage true academic research, and are critical for capital-constrained startups.
“Every AI startup, every solo developer, every two-person team building a product on top of AI infrastructure depends on having access to good models at affordable prices,” Gurley says.
Chamath Palihapitiya, one of the All-In podcast hosts, wrote on X that “tricking the US Government to protect frontier labs’ business model by using a China boogeyman is a mistake…It is protecting the equity of 5,000 people who are investors in OAI and Ant at the sale of everyone else. This would be a terribly stupid decision.” His cohost and fellow VC Jason Calacanis piled on. “Daddy Trump protect us!!!!” he wrote on X, with an alarming number of crying-laughing emoji.
This stance from some of Silicon Valley’s most ruthless capitalists might at first seem counterintuitive. Why let a foreign adversary’s technology flourish in the US? It’s as if the US is up just 1-0 in the AI World Cup, a slightly uncomfortable lead, and the crowd is chanting for the opposing team to get a free kick.
Microsoft says a bug in its automated network maintenance request system caused Thursday’s massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services.
The outage began at 10:44 AM ET on Thursday, July 23, and mostly affected customers accessing Microsoft 365 services through network infrastructure connected to Microsoft’s West US Azure region.
At 11:11 AM ET, Downdetector had recorded 2,403 outage reports, sharply above its normal baseline of 29. SharePoint accounted for 78% of the complaints, followed by Excel at 11% and the Microsoft 365 Admin Center at 6%.
Microsoft tracked the Microsoft 365 outage under incident ID MO1437424 and confirmed that multiple Microsoft 365 services were impacted:
Other affected services included Fabric and Power BI, Power Apps, Copilot Studio, Windows 365, and Microsoft Defender.
Some Defender customers experienced delays receiving responses from Microsoft Defender Experts, while investigations, workflows, and remediation actions triggered through Threat Explorer and Advanced Hunting could fail.
Microsoft initially attempted to mitigate the outage by rerouting traffic through alternate network paths, which helped customers, but many services continued to be affected.
Before determining what caused the outage, Microsoft warned customers that they might need to review their business continuity and disaster recovery plans and take actions appropriate for their environments.
The company later identified a recent networking change as the cause and began reverting it.
Microsoft completed the reversion at 2:26 PM ET and confirmed through service telemetry and customer reports that the Microsoft 365 incident had been resolved.
In a preliminary Post Incident Review for the Azure incident, Microsoft said the outage was triggered during routine device maintenance in its West US Azure region, where specific network paths were being isolated.
Microsoft says its maintenance process converts these types of requests into system-readable instructions and checks that at least one of two redundant paths remains healthy before the work begins.
However, a bug in the request conversion system incorrectly marked additional network devices as part of the maintenance event.
As a result, IP routes were removed from more devices than intended between Microsoft’s West US datacenter and its wide-area network.
The removed routes disrupted network traffic entering or leaving the West US region. However, Microsoft said traffic remaining entirely within the region was not affected.
The Azure incident caused connectivity failures, increased latency, and problems accessing numerous cloud services, including Azure App Service, Application Gateway, Azure AD B2C, Azure AI Search, Azure API Management, Azure Cosmos DB, Azure Databricks, Azure Firewall, Azure Kubernetes Service, Azure Monitor, Azure Virtual Desktop, ExpressRoute, Log Analytics, Microsoft Graph, Microsoft Sentinel, Power BI Embedded, Virtual WAN, and VPN Gateway.
Microsoft said its engineers began investigating the issues immediately after the outage began at 10:44 AM ET.
The problem initially presented itself as large-scale route churn in Microsoft’s WAN. Engineers later traced the route removals to a datacenter in the West US region and linked them with the recent maintenance activity.
Microsoft initiated a rollback of the maintenance change at 1:45 PM ET, which was completed at 2:26 PM ET.
The rollback restored the affected network infrastructure and allowed Microsoft 365 services to recover. Some Azure services continued recovering after the fix was put in place, with Microsoft reporting that all affected services had fully recovered by 3:41 PM ET.
Microsoft is now conducting a full internal review focused on the safety checks and automated processes used to execute maintenance requests.
“We will be preforming a full analysis focusing on safety checks, automated maintenance request change process, and more as we progress through our post mitigation internal retrospective,” explained Microsoft.
The company said it will publish a final Post Incident Review after completing its investigation, which is usually within 14 days.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Players may be unable to log into their account, play online or purchase games from the PlayStation Store.
PlayStation Network (PSN) is going through an outage that’s affecting all of Sony’s video game services, according to the PlayStation Service Status page. Players may be unable to access their PlayStation account or use the PlayStation Store, and the outage has had at least one real world impact by delaying the EA Sports FC 26 championship at the Esports World Cup.
Sony’s status page notes that “all services are experiencing issues,” including account management features, game streaming, the PlayStation Store and even PlayStation Direct, Sony’s website for selling PlayStation hardware. The issues also extend to older platforms the company is still maintaining in one way or another, like the PS Vita, PS4 and PS3.
Engadget has asked Sony to comment on the outage and the work it’s doing to fix it. We’ll update this article if we hear back.
Sony has yet to publicly acknowledge the PSN outage on its public-facing PlayStation Support account, but the timing is awkward, to say the least. The company recently announced plans to retire physical game disc production by 2028 and make all PlayStation games available digitally. While digital games offer certain conveniences, one way their weaknesses show is when a network outage makes them completely unavailable to purchase or play.
If you remember Jibo, you’ll probably also remember its emotional farewell. The social robot, once named one of TIME’s Best Inventions, shut down in 2019 with a message asking owners to “say hello” to future robots. Singapore-based AI hardware startup Lingverse, the team behind the original visoon, has announced $29 million in Pre-A funding to develop iKairos, a wearable AI companion that the company describes as the spiritual successor to Jibo. Unlike existing AI wearables, iKairos is designed to understand both its user and their surroundings, allowing it to offer proactive assistance instead of simply responding to prompts.

AI wearables have gained momentum over the past year, but most products still rely on a single camera or microphone to interpret the world from the wearer’s perspective. Lingverse believes that’s only half the picture. The company says iKairos is the first dual-perspective AI wearable, featuring a modular design that can be worn on the body or used as a desktop device. Users can switch its field of view between themselves and their surroundings, allowing the AI to build context about both the person wearing it and the environment around them.
The goal is to make the device less reactive and more proactive. Instead of waiting for voice commands, iKairos is designed to recognize situations where reminders, suggestions, or questions might be useful based on what it observes over time.
Beyond that, the company says iKairos includes a physical camera shutter that completely blocks visual recording whenever users want additional privacy. It also claims that personal data is either processed locally on the device or encrypted during transmission, and that user data won’t be used to train its AI models.
Speaking on the matter, Jiawei Gu, Founder and CEO of Lingverse, said:
Today, with iKairos, we can finally pick up where the Jibo team left off and deliver on the promise. iKairos continuously observes both you and your surroundings, creating the context that today’s AI lacks. Once the AI understands your life instead of just your prompts, iKairos can begin to act as a personal AI guardian, which is capable of unlocking entirely new experiences and proactively adapts to and works around your lifestyle.”
Dynaudio’s decision to close its U.S. subsidiary raised the question every owner wanted answered first: would the warranty still mean anything once the company packed up and left? The answer is yes, but the repair network, service contacts and future North American distribution plan are still being worked out.
A warranty promise is good news. A warranty promise without a named repair center, service contact or explanation of where your loudspeaker goes when something fails is still only half an answer.
Dynaudio has now addressed the most important consumer question following its decision to close its U.S. subsidiary and end direct commercial operations across North America this fall: existing warranties will remain valid.
In an email interview published by Stereophile, Dynaudio Chief Commercial Officer Julien Bergere stated: “All warranties of existing products in the US market will be honored.” He also confirmed that products purchased through official Dynaudio dealerships during the transition will retain warranty coverage.
That should provide some reassurance to current owners and anyone considering remaining dealer inventory. What Dynaudio has not provided is the support structure required to turn that promise into an actual repair.

Dynaudio’s confirmation applies to products already sold in the United States and to new purchases made through authorized dealers while the company winds down its North American operation. Buying from an official dealer remains important; a deeply discounted grey market speaker with no authorized sales record is unlikely to become more appealing because the U.S. office is closing.
Dynaudio’s published warranty policy currently provides up to 96 months of coverage for registered passive loudspeakers, provided registration occurs within 12 months of purchase. Registered active products receive up to 96 months on passive components and 36 months on electronics, while OEM drivers and automotive aftermarket products carry 24 months of coverage. Terms vary by product and local warranty law.
Owners should register qualifying products now, retain the original receipt and document the authorized dealer. This is not the moment to discover that the invoice disappeared with an email account from 2021.
Bergere acknowledged that Dynaudio is still studying how warranty service will be delivered after the subsidiary closes. The company has not named replacement service centers, explained whether repairs will remain inside the United States or confirmed how parts and technical support will reach dealers.
Dynaudio’s current contact page still lists Dynaudio North America and its existing U.S. sales contact, but that does not explain who takes over once the Northbrook, Illinois, operation shuts down.
For a small bookshelf speaker, uncertain shipping logistics are irritating. For a large floorstander, active loudspeaker or professional monitor, they become expensive very quickly. Owners need to know who authorizes the repair, where the product is shipped, who pays the freight and how long replacement drivers or electronics will remain available.
“We will honor it” is welcome. “Here is how” is the part still missing.
Dynaudio has offered U.S. and Canadian dealers the opportunity to place final orders before the transition is completed. Bergere said remaining inventory will be returned and “shipped back to be sold elsewhere.”
That could make some models harder to find once existing dealer stock is depleted. It could also produce discounts, although buyers should not let a sale price distract them from asking who will provide support after the local subsidiary disappears.
The company has also left open the possibility of returning through an independent distributor or selling more directly to retailers. Dynaudio says it would consider either arrangement if it could maintain the required level of brand representation and customer service. No agreement has been announced, and nobody should confuse willingness to consider a distributor with actually having one.
Dynaudio says the U.S. importer, rather than Dynaudio A/S in Denmark, pays tariffs at the border. Those costs are then absorbed through lower margins, higher retail prices or some combination of both. The company deliberately used the broader phrase “economic challenges and market uncertainty” in its original announcement rather than turning the release into a seminar on customs policy.
Bergere also rejected online speculation that tensions between the United States and Denmark over Greenland played a role in the decision.
Greenland did not drive Dynaudio from North America. The spreadsheet appears to have been sufficiently persuasive on its own.
Dynaudio maintains that the move is strategic, allowing it to concentrate on Europe, Asia and new premium products including the Legend loudspeaker, Confidence i range and Symphony Opus One system. That makes the timing no less strange after prominent appearances at AXPONA and High End Vienna, but it provides a clearer explanation than geopolitical revenge involving an island with fewer people than Hoboken.

Dynaudio’s warranty confirmation is genuinely good news. Existing owners are not being abandoned, and authorized purchases made during the transition will remain covered.
The unresolved issue is execution. Dynaudio still needs to identify the repair network, publish the service process and explain how parts, freight and customer communication will work after its U.S. subsidiary closes.
A warranty is a promise. A functioning service network is how that promise gets kept.
Consumers do not need to panic, and the loudspeakers did not suddenly become worse because the company changed its regional strategy. But anyone buying Dynaudio inventory in the coming months should register the product immediately, keep every document and ask the dealer for a clear explanation of who will handle future service.
Despite their small size, mosquitoes are one of the deadliest creatures on Earth, and keeping them away from you is one of the best ways to stay safe. DEET has been the mainstay of insect repellents for decades, but what if there was a repellent you could grow yourself?
Researchers at Cardiff University found that the essential oil from catnip plants (Nepeta cataria) could be as effective as DEET at repelling mosquitoes when applied as a 6% lotion. The oil has been shown to be effective against many species of mosquitoes, ticks, and mites in previous research. You can look at the paper for details, but the catnip oil was obtained through steam distillation followed by some processing with hexane. The essential oil was then mixed with “water, glycerin, emulsifying wax, cetyl alcohol, cetyl stearyl alcohol, shea butter, glycerol monostearate, olive oil, coconut oil, sunflower oil, methyl paraben, propyl paraben and silicone oil.” We suspect that list will look familiar to anyone who’s read an ingredient label of most any store bought lotion, unless it was paraben free.
The Guardian’s coverage quotes one of the researchers, [Dr. Simon Scofield]: “We did not conduct any experiments to see if it is attractive to cats, but given that the active ingredient [nepetalactone] has well-known cat-attractive properties, I would expect they would quite like it,” he said. Depending on how your cats react, you may want to consider applying the lotion shortly before departing home.
If you want some more options in your mosquito defense, how about becoming a bug zapper, using drones and sonar, or genetically modifying mosquitoes to curb their numbers.
On July 23, President Donald Trump stood in the White House and promised that electricity bills for American families would “actually come down,” even as power-hungry AI data centres spread across the grid. T
he vehicle was an expanded version of the Ratepayer Protection Pledge, a voluntary scheme first unveiled in March. What energy analysts noticed was mostly what it left out.
The pledge asks the companies building data centres, among them Amazon, Google, Meta, Microsoft, OpenAI, Oracle, and xAI, to fund or build the power infrastructure their facilities demand rather than passing the cost to existing ratepayers.
The administration had already signalled it would widen the scheme to the utilities, and the new version reaches, by the White House’s own count, nearly 200 additional signatories, including NextEra Energy, Duke Energy, rural cooperatives, and a group of Republican governors.
Trump claimed the commitment now covers roughly 80% of the power delivered to US homes and businesses, and that companies given the right to build their own plants could sell surplus energy back to the grid, nudging rates down. He offered no capacity targets, no timelines, and no measurable milestones.
That silence matters, because the strain on household bills is already well documented. AI data centres have pushed up power bills across parts of the industrial Midwest, and in the PJM Interconnection, the largest US grid operator, data centres accounted for $6.3bn of the $16.4bn in charges from the most recent capacity auction, roughly 38%, according to the grid’s independent market monitor.
“PJM is continuing to act like it’s business as usual,” Joseph Bowring, the monitor’s president, said of the shift. “You have to open your eyes and recognise that it is really a paradigm shift, and failing to do that imposes costs on other customers.”
The pledge is not binding, and that is the central objection. It carries no penalties and no compliance oversight, and a quirk of federal rules may stop signatories honouring it even where they want to.
Current interconnection tariffs socialise grid-upgrade costs across all customers, and as FirstEnergy argued in a 2026 filing to regulators, existing rules can prevent a company from covering its own infrastructure costs even if it chooses to.
Consumer advocates were blunt. Jesse Lee of the campaign group Climate Power called the pledge a “pinky promise,” and a Consumer Reports survey found that 75% of American adults lacked confidence that large developers would truly cover all their costs.
Researchers at the Brookings Institution added that federal statutes “cannot readily override” the state public utility commissions that actually set residential rates.
There is a further wrinkle. Some of the same companies signing the pledge have fought state-level rules that would force them to deliver on it, consumer groups say, which makes the voluntary version look less like generosity than like the softer of two options.
The White House has cast the plan as proof that the AI build-out can proceed without punishing households.
The forecasts are not reassuring either. The consultancy ICF has estimated that data centres could lift US electricity demand by 25% by 2030 and add as much as 40% to monthly bills over five years, and utilities are planning some $1.4 trillion in capital spending by the end of the decade to keep up.
Louisiana, for its part, projects $2.6bn in ratepayer savings over 15 years from its deal with Meta, a reminder that the local arithmetic can cut both ways.
Congress has taken its own run at the problem, with the House advancing a bill on data centre energy costs, though nothing on the books yet compels the hyperscalers to pay.
The one body that could give the pledge teeth is the Federal Energy Regulatory Commission, which has already begun to fast-track grid connections for large loads. In June, it ordered six regional grid operators to justify or reform how they charge those users, with a deadline in August.
Until those rules change, the pledge remains what its critics say it is: a promise made in a room, with no one obliged to keep it.
GitHub has confirmed plans to evolve its bug bounty program into a two-tier system, which will come into force for reports submitted on or after July 27, 2026.
Under the new scheme, the Microsoft-owned coding platform will add a lower-paying public program that’s available to the wider research community, under a higher-paying invitation-only program.
Product Security Engineer Catherine Cassell explained that the change comes in response to a growing backlog of low-effort, low-quality and AI-generated reports.
Latest Videos FromTechRadar
For the new public program, GitHub will replace payout ranges with a single payment for each severity, spanning $250, $2,000, $5,000 and $10,000 for low, medium, high and critical. Cassell said this would help researchers know in advance what a valid finding could be worth, and it would also give insiders less of a headache having to decide where a report sits within a range.
Notably, the payouts are much lower than before, with the previous ranges paying out $500-$1,000, $2,000-$5,000, $5,000-$20,000 and $10,000-$30,000.
Invited VIP researchers under the second plan will earn around 3-4x more than researchers under the other scheme, depending on bug severity.
GitHub is also adding a HackerOne signal requirement for new researchers, giving them four opportunities to “establish a track record” – likely another response to rising AI-generated reports, which are typically of lower value.
“We want to build a program that attracts the research we value, creates an experience that reflects how seriously we take this work, and upholds the trust researchers place in us every time they submit a report,” Cassell concluded.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
A lawsuit over Apple’s failure to deliver Apple Intelligence and Siri features is moving closer to a conclusion as a judge has provisionally approved the company’s settlement offer.
The class action suit filed in 2025 alleged that people had bought new iPhones expressly because of Apple’s promoting of Apple Intelligence features that it then did not deliver. Apple admitted in March 2025 that the new Siri features were delayed, but then in May 2025 offered a settlement.
Apple and the parties to the class action suit agreed to a $250 million settlement, but it had to be approved. Now in a filing in the US District Court, Northern District of California, judge Noel Wise has provisionally given approval.
The final approval and so the start of any pay out to buyers, though, is dependent on a final hearing which has now been announced for September 29, 2027. While Judge Wise has given overall approval, he ruled that the court will not decide on any amounts until that hearing.
It may be a quick final hearing, though, as the parties have already agreed to a payment of at least $25 per eligible device. It is possible, however, that this amount could rise to $95 per device if the number of claims filed is low.
There will be a way for users to formally apply to be part of the claim. But as MacRumors said on Friday yet the details of this have not been announced.
Earlier this year FCC boss Brendan Carr launched a series of fake investigations into ABC because the network (1) hosted Democratic Texas Senate hopeful James Talarico on The View, (2) aired comedians who made fun of the president and his wife, and (3) occasionally engaged in journalism critical of Trump corruption.
The details of these investigations really don’t matter at this point. We’ve discussed how they’re legally incoherent, clearly violate the First Amendment, and involve Carr actively manufacturing false claims that ABC violated FCC rules it was long-exempt from. At other points it just involves Carr being incoherently racist on Trump’s behalf; such as claims that ABC didn’t eliminate its “DEI” requirements quickly enough.
Carr’s now dumping additional empty threats into the mix, claiming that his ongoing review of ABC’s local broadcast licenses will take into consideration the network’s refusal to air Trump’s recent prime time speech, which mostly just involved Trump spewing more false election fraud conspiracy theories surrounding his 2020 loss.
ABC and NBC wisely refused to air the speech live, knowing that helping to spread distrust in election integrity in real time would be the opposite of useful journalism. That made Trump mad, so he’s clearly urged Brendan Carr to levy some additional empty threats against ABC:
“I think when you have the President of the United States standing inside the White House delivering an important speech, I think that’s something that broadcasters should be carrying. And so, obviously, this is an issue,” Carr told reporters Wednesday. “There have been lots of concerns raised, including by members of Congress, about whether broadcasters and their decisions there comply with the public interest.”
Carr is somewhat vague here because he knows this is a bunch of bullshit.
Obviously it’s ABC’s First Amendment right to determine what it broadcasts and when. Carr has absolutely zero legal role in determining the scheduling lineup of a private company. Carr’s once again pretending that networks that refuse to pander to our mad idiot king will be subjected to FCC review of their public interest obligations affixed to ownership of public airwaves.
As we’ve mentioned countless times already, Carr doesn’t want any of this to actually head to court because he knows it’s an absolute loser on First Amendment grounds. The real goal remains to threaten U.S. media companies with costly and annoying legal headaches if they challenge Republicans or the unpopular president. It’s typical lazy autocrat stuff by weak men who are afraid of words.
When it comes to ABC, that’s still been embarrassingly effective. The company agreed to pay Trump a $16 million bribe in 2024 to settle a baseless lawsuit the company easily could have won. And more recently, ABC shows like The View have shied away from hosting any political candidates at all for risk of upsetting Trump.
Brendan Carr has openly stated in interviews he fancies himself a tough, pit bull enforcer; but as Trump’s health and political power wane, the threats will hold less and less weight. As a result you’ve already seen ABC execs start to show a backbone in their fight with Carr, openly pointing out how he colluded with local right wing broadcast affiliates to manufacture evidence suggesting ABC broke FCC rules (something I’m sure will play great in court).
Carr’s threats will become weaker and weaker until he’s ultimately booted from office by subsequent administrations, at which point he’ll fail upward to some mid-six figure job at a telecom or media think tank, where he’ll spend the rest of his life helping corporate America dismantle whatever’s left of competition, labor, and consumer protection standards.
One of the ironic things, for Carr, is that his authoritarian censorship and saber rattling often draws press and public attention away from all the other terrible things he’s doing, whether it’s destroying media consolidation limits, making life easier on robocallers, dismantling broadband consumer protection standards, or making it easier for giant shitty companies to run amok.
You’d like to think Carr ultimately faces some sort of meaningful accountability for being one of the most censorial, petty, captured, and authoritarian regulators in U.S. history, but I wouldn’t hold your breath.
Filed Under: brendan carr, censorship, fcc, first amendment, james talarico, media
Companies: abc, disney
American fast food restaurant chain Chick-fil-A has confirmed that over 13,000 customers had their data stolen in a recent wave of credential stuffing attacks.
As BleepingComputer first reported, the company revealed in data breach notification letters filed with multiple attorney general’s offices that it detected attacks targeting its website and mobile app between June 17 and June 19 after identifying suspicious login activity to certain Chick-fil-A One accounts.
Chick-fil-A says the attackers used automated tools and credentials “obtained from a third-party source” to hack into Chick-fil-A One accounts and steal customer data.
“We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted,” the company told BleepingComputer.
During the attacks, the threat actors accessed a combination of customers’ names, email addresses, Chick-fil-A One membership numbers, the amount of Chick-fil-A credit, the mobile pay numbers, and the last four digits of the credit/debit card number. Additionally, they may have also gained access to birth dates, phone numbers, and addresses if stored in the compromised accounts.
While the company didn’t say how many individuals had their data exposed, Chick-fil-A notes in a filing shared by the Office of the Maine Attorney General with BleepingComputer on Wednesday that the resulting data breach affected 13,322 people in total.
In separate filings, it also told the Texas attorney general’s office the data breach impacts 2182 Texans and the Massachusetts AG that it affects 39 residents. Chick-fil-A has also sent data breach notification letters to residents of the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
In response to the incident, Chick-fil-A says it logged out all impacted accounts, removed payment methods, restored all affected Chick-fil-A One account balances, and has also added rewards to affected accounts as a way of apologizing. Since the accounts were compromised because they were using credentials stolen from third-party services, Chick-fil-A also advised impacted customers to change their passwords as soon as possible.
Chick-fil-A also disclosed in March 2023 that hackers stole the personal information of over 71,000 customers after hacking their accounts in another series of credential stuffing attacks between December 2022 and February 2023.
As one of the largest fast food companies in the United States, Chick-fil-A operates a network of over 3,000 restaurants across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Weekend Open Thread – Corporette.com
The House | The City of London can help the new chancellor deliver growth in every postcode
Ripple Payments Joins MiCA With 14 Firms, Does It Mean Anything For XRP?
Democrats look to World Cup watch parties to register thousands of voters
Ripple wins EU-wide access as ESMA adds it to MiCA register
Grayscale Files For Worldcoin ETF, WLD Registers Sharp Rise
Sail Virtually Aboard The “Itanic” With IA-64 Emulator
Unregistered fitter used Gas Safe logo on business flyers
Turtle Beach Command Series KB7 review: a nifty screen-equipped gaming keyboard
Big Money Is Entering XRP
New Jersey voter registration controversy explained: How 6,600 noncitizens got on the rolls, and what happens next
Kaspersky exposes OkoBot’s 20-module crypto wallet attack
Airlines warn Sunshine Protection Act could disrupt flight scheduling
Johnny Depp’s R-Rated Gothic Cult Classic Gets New Release Ahead of Sydney Sweeney Remake
Durham County Council to send out electoral registration emails
MiCA Licensing Faces Delays as ESMA Adds 14 CASPs to Register
Ethics, other provisions in crypto Clarity Act to be further discussed
Shanghai science forum photos show China’s AI and robotics advances in rivalry with US
Chip Stocks Enter Bear Market After Moonshot Ai Unveils Kimi K3 Model
Watch Flock Safety CEO Garrett Langley discuss the future of surveillance at TechCrunch Disrupt 2026
You must be logged in to post a comment Login