Attackers used stolen credentials to access Chick-fil-A One accounts between June 17 and June 19, exposing names, partial card numbers, and rewards balances