As online ordering and delivery quickly become the norm for fast-casual and quick-service chains, the rollout of new applications can be a siren song for hackers. TechCrunch reports that a string of Chipotle customers are posting on Reddit and tweeting at Chipotle that they were charged for food that was delivered to other states. The customers’ accounts and credit card information was hacked, leading to hundreds of dollars in fraudulent charges.

A Chipotle spokesperson blamed the breach on credential stuffing—tapping into usernames and passwords that consumers use on both Chipotle’s app and on other sites that have been hacked—saying the chain sees “no indication of a breach of private data of our customers.” However, several allegedly hacked individuals TechCrunch spoke with said the password they use for Chipotle is unique to that account. One person even said they never even created a Chipotle account, but had checked out as a guest in the past.

TechCrunch reports that if credential stuffing is the issue, two-factor authentication would help prevent breaches like this. “But when asked if Chipotle has plans to roll out two-factor authentication to protect its customers going forward, spokesperson Schalow declined to comment,” writes TechCrunch.

Read the full article here.

Don’t Miss the Next Big Franchise Story

Sign up for the 1851 Franchise newsletter to get our biggest stories before everyone else

By signing up, you agree to our user agreement (including class action waiver and arbitration provisions), and acknowledge our privacy policy.

Emily Clouse

About the Author

Emily Clouse

Follow

Emily Clouse is a staff writer for 1851 Franchise. Her work has been featured with publications such as The Onion, Reductress, and Chicago Magazine. She graduated from The Ohio State University before running away to join the Peace Corps. In her free time, she enjoys drawing and walking to Jewel-Osco.