CONTINUE TO SITE »
or wait 15 seconds

Operations

Loyalty programs have become new front line of QSR fraud

Photo: Adobe Stock

August 28, 2026 by Stuart Mann — Head of Industry Product Engagement, Accertify

A recently disclosed data breach at Chick-fil-A made headlines for the type of accounts that were targeted. It was reportedly a credential stuffing attack that went after loyalty program accounts at the restaurant.

According to reports, customers' names, email addresses, membership numbers, credit on file, mobile pay numbers and last 4 digits of the credit/debit card number was accessed by this attack. In addition, birth dates, phone numbers and addresses, if stored, were also compromised.

The incident has sparked renewed discussion about the growing importance of authentication around loyalty programs for QSR brands. In this case, the credentials that were used came from a third-party source — most likely from a data breach from a completely different organization. This means that Chick-fil-A's own security controls were likely functioning as expected. But the attack succeeded anyway.

The reality is that this event represents a growing threat to one of the most valuable assets these organizations have. But why did it happen? It's the balance between security and convenience.

According to the National Restaurant Association, 78% of consumers say they are more likely to visit a restaurant where they can earn points, even if that restaurant is less convenient than other options. The same source notes that 67% of restaurants offer a loyalty program. Digital engagement has only increased their value. Loyalty programs for QSRs are now a core part of how brands drive repeat visits, increase digital engagement, and create more personalized customer experiences.

QSRs will continue investing in digital onboarding and loyalty engagement. However, fraud prevention strategies need to evolve alongside it to ensure their future success. Customers are often the weakest part of an authentication path. Many people use the same combination of email address and password to access multiple accounts. A data breach from one company offers fraudsters an opportunity to try the same credentials against other organizations, often with a worryingly high rate of success.

While having a loyalty program has become more valuable to restaurants, they've also become more attractive targets for fraudsters. Today's loyalty account can contain stored payment credentials, order history, rewards balances, and saved preferences like delivery addresses, giving attackers multiple data points they can exploit to build increasingly sophisticated fraud schemes.

Fraud used to happen primarily at the point of payment. But as fraudsters have become more sophisticated, attacks tend to originate much earlier in the customer journey because hackers can target account creation, credential stuffing, and account takeover (ATO) before a purchase ever occurs.

One of the clearest examples of is ATO, which can damage a customer's trust in the brand, not just the program's bottom line. A fraudster who gains access to a loyalty account, often through credential stuffing, phishing, or passwords reused from other breaches, can drain point balances, redeem stored rewards, or access stored payment methods before the account holder notices anything is wrong.

Because the login itself often looks legitimate, account takeover can slip past controls built for payment fraud. How can QSRs ensure even stronger controls and prevent future credential stuffing attacks? The discussion is well warranted and overdue.

There are stronger authentication paths and clearer warning signs that can be easily adopted. For example, authenticating using passkeys, effectively binding the user to a device, makes it impossible for fraudsters to use email address and password to access an account. Tracking data points such as the device being used to access the account or the behavior interactions between the user and the web/mobile journey (mouse movements, keystroke dynamics, time on page etc.) allows for fraudulent versus trusting patterns to be recognized.

Once these data points are being assessed, it becomes easier to spot unusual user journey activity, such as a login from an unfamiliar device or location, followed quickly by a profile change, and then a fast redemption or points transfer. Individually, each event looks routine, but when viewed as part of the same customer journey, it's one of the strongest available signals of a compromised account, and is usually visible in the minutes before the loss occurs.

As fraudsters are thinking about the broader customer journey, so should security and fraud prevention teams and the strategies they deploy. For example, instead of monitoring only for points redemption events, fraud teams are increasingly monitoring for unusual login activity, device changes, IP reputations, account modifications, and even session behavior to detect and stop fraud attempts before the point of transaction.

That shift is already taking place across the industry. In a recent survey of QSR fraud and security leaders conducted by Accertify and Liminal, 84% said they're expanding fraud controls into account login, while 60% are strengthening protections around account changes.

Rather than treating login, ordering, loyalty and payments as separate systems, QSRs are increasingly putting processes in place to evaluate whether activity makes sense across the entire customer relationship.

Expanding fraud monitoring earlier in the customer journey also requires carefully balancing security with customer experience. Protecting good customers while making abuse more difficult for attackers should remain the goal. Fraudsters thrive on the path of least resistance, so being able to insert that friction can go a long way.

Instead of challenging every customer, the focus should be on introducing friction only where the risk justifies it. That could mean connecting device intelligence, behavioral analytics, and transaction data into a single guest view across login, checkout, and post-purchase so coordinated abuse can be detected without adding unnecessary friction for legitimate customers.

This shift also changes how organizations should think about loyalty programs themselves. Loyalty programs are and will continue to be a significant driver of value for QSR owners and operators. Their value has increased beyond marketing initiatives and into identity platforms. They underpin digital ordering behavior, personalization, payments, and customer retention. This means security and marketing can no longer treat them separately. Ultimately, protecting a loyalty program is protecting customer trust.

The Chick-fil-A incident won't be the last headline about loyalty account abuse in the QSR space, especially as these programs grow in value. The organizations getting ahead of this trend are the ones that view loyalty fraud as part of the broader account security strategy that spans the customer journey.

About Stuart Mann

Stuart Mann is Head of Industry Product Engagement at Accertify, where he leads the outbound communication on Accertify’s product roadmap across fraud prevention, account protection, and payment risk solutions. He has spent over 17 years working across ecommerce fraud, payments and risk—both on the merchant side and within global solution providers—building a deep, pragmatic understanding of how fraud & abuse prevention must balance security, customer experience and revenue growth.

Connect with Stuart:


Related Media




©2026 Connect Media, All rights reserved.
b'S1-NEW'