What QSR Operators Need to Know About Loyalty Fraud, Part One
5 Min Read
The recent Chick-fil-A loyalty program breach highlights a shift in QSR fraud as these efforts have become valuable targets for account takeover and credential abuse. To learn more about why loyalty fraud prevention should be a focus for QSR operators, Modern Restaurant Management (MRM) magazine connected with Stuart Mann, Director of Fraud & Account Protection at Accertify, an expert in payments and fraud in industries including retail, travel, ticketing, video gaming, and finance He has served on the Merchant Risk Council for over nine years. The first part below details some background on the problem, while the second part will offer best fraud prevention practices for operators.
Beyond the Chick-fil-A breach, what are other indicators signaling that loyalty programs are becoming a target for threat actors?
The Chick-fil-A incident has drawn attention because it happened in the QSR sector, but the warning signs have been visible for some time across other industries. Travel, hospitality and retail loyalty programs have already seen the same pattern: credentials stolen elsewhere are tested at scale, accounts are taken over, and points or stored value are monetized. It’s natural that fraudsters will shift to other industries. The Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC)'s 2025 industry analysis identified credential theft, phishing and fraud as persistent threats across consumer-facing industries, including restaurants and food service organizations.
In some environments, fraudsters are creating entirely new loyalty accounts and linking stolen payment cards to them. They then use the loyalty account as a vehicle to monetize those cards through mobile ordering, stored-value purchases or gift card transactions. In effect, the loyalty account becomes a Trojan horse for broader payment fraud.
Another indicator is that the barrier to entry for attackers continues to fall. Credential stuffing tools, bot frameworks, residential proxy networks and even AI-powered attack services are widely available, allowing fraudsters to automate attacks at scale with far less technical expertise than was required a few years ago. Threat intelligence researchers have also documented how increasingly sophisticated attack tooling is being advertised and sold through underground forums, making these capabilities accessible to a much larger group of threat actors.
What has changed most significantly, however, is the role loyalty programs now play within restaurant apps. Historically, the primary target was the rewards balance itself. Today, many loyalty programs have evolved into digital identity and payment platforms. Customers can store payment credentials, maintain saved addresses, place mobile orders, redeem offers and manage account preferences from within a single account.
As a result, we're seeing fraud extend beyond traditional account takeover. In some environments, fraudsters are creating entirely new loyalty accounts and linking stolen payment cards to them. They then use the loyalty account as a vehicle to monetize those cards through mobile ordering, stored-value purchases or gift card transactions. In effect, the loyalty account becomes a Trojan horse for broader payment fraud.
There is also growing evidence that loyalty accounts themselves are becoming a tradable commodity. Threat intelligence investigations have identified airline and hotel loyalty accounts being advertised and sold on underground marketplaces, alongside discussions around stolen points, rewards balances and compromised customer credentials. When criminal marketplaces begin assigning monetary value to a particular asset, it is often one of the clearest indicators that attackers see a scalable opportunity.
Why are loyalty programs so valuable and vulnerable to fraudsters?
Loyalty programs have become one of the most valuable assets many restaurant operators own because they provide a direct connection to the customer. They drive repeat visits, influence purchasing behavior, support targeted marketing, and help brands create more personalized experiences. For many brands, loyalty membership is now a key measure of long-term customer value and customer engagement.
The challenge is that fraudsters increasingly recognize that value as well. Historically, criminals were primarily interested in the rewards balance itself. Points, credits, vouchers, and free meal redemptions all have monetary value that can be converted into products, gift cards, or other benefits. While that remains a target, today's loyalty account offers far more than just rewards.
Modern loyalty programs have effectively become digital identity platforms. A single account may contain personal information, order history, preferred locations, saved delivery addresses, payment credentials, and a detailed record of customer behavior. From a fraudster's perspective, that information can be just as valuable as the rewards balance because it helps them appear legitimate and better replicate normal customer activity.
The growing convergence of loyalty, ordering, and payments has made these programs even more attractive.
The growing convergence of loyalty, ordering, and payments has made these programs even more attractive. Many restaurant apps now allow customers to browse menus, place orders, earn rewards, and pay from the same account. In some cases, fraudsters are not simply trying to steal points. They are targeting an account that can facilitate broader forms of fraud, including unauthorized purchases, gift card abuse, or the use of stolen payment cards linked to loyalty accounts.
There is also a perception gap within some organizations. Loyalty programs are often viewed as marketing initiatives, while fraud prevention is viewed as a payments or security responsibility. As a result, the controls protecting loyalty accounts do not always evolve at the same pace as the value being stored within them.
Ultimately, loyalty programs have evolved from marketing tools into customer identity ecosystems. They now sit at the intersection of engagement, payments, personal data, and customer trust. As their value to businesses has increased, so has their value to attackers. Fraudsters follow economic opportunity, and loyalty programs increasingly provide exactly that.
In what ways is loyalty fraud evolving and how much of a focus should it be for restaurant operators?
Loyalty fraud is evolving from isolated incidents of points theft into a much broader form of account-centric abuse. What was once considered a niche problem has become part of the wider fraud landscape affecting digital businesses.
Historically, many restaurant operators focused their fraud efforts on payment authorization and chargebacks. Today, attacks often begin much earlier in the customer journey. Fraudsters understand that gaining access to a loyalty account can provide ongoing access to rewards balances, customer data, payment credentials, and account-level trust that has already been established with the brand.
We're increasingly seeing multiple fraud techniques linked together. An attacker may first compromise an account through credential stuffing, change profile details to establish persistence, harvest stored information, and eventually redeem rewards, place fraudulent orders, or abuse stored payment methods. Viewed individually, each action may appear legitimate. Viewed collectively, they reveal a coordinated attack pattern that spans the entire customer journey.
Artificial intelligence and automation are accelerating this trend. Fraudsters can launch attacks at greater scale, automate account testing, generate more convincing communications, and adapt their tactics more quickly than ever before. The result is that loyalty fraud is becoming more organized, more targeted, and harder to detect.
What's also changing is how fraudsters use the information contained within these accounts. A compromised loyalty account may provide visibility into a customer's ordering history, preferred locations, purchasing habits, delivery addresses, and engagement with promotions. That information can be used to create highly convincing phishing and social engineering campaigns that appear to come from the restaurant brand itself. Instead of simply stealing points, attackers can use loyalty data to send realistic order confirmations, payment alerts, refund notifications, or promotional offers that are specifically tailored to the victim's known behavior. In these cases, the loyalty account becomes an intelligence source that can be leveraged to target higher-value assets, such as email accounts, financial accounts, or corporate credentials.
Artificial intelligence and automation are accelerating this trend. Fraudsters can launch attacks at greater scale, automate account testing, generate more convincing communications, and adapt their tactics more quickly than ever before. The result is that loyalty fraud is becoming more organized, more targeted, and harder to detect.
For restaurant operators, this should be a significant strategic priority because customer trust is directly involved. When customers lose rewards, experience account compromise, receive fraudulent communications, or discover unauthorized activity, they rarely distinguish between a loyalty issue and a security issue. They simply view it as the brand failing to protect them.
The financial impact may begin with stolen rewards or fraudulent transactions, but the long-term consequences are often more significant. Lost customer confidence, reduced engagement, lower retention, and reputational damage can be far more costly than the value of the stolen points. As restaurants continue investing in digital ordering, mobile applications, and loyalty engagement, protecting customer accounts should be viewed as a core component of both fraud prevention and customer experience strategy.