Chick-fil-A Data Breach Exposes Personal Information and Stored Account Credit

Chick-fil-A has notified customers of a data security incident in which unauthorized parties gained access to Chick-fil-A One loyalty accounts through a credential stuffing attack, exposing personal information and stored account credit for affected users.

Chick-fil-A identified suspicious login activity on certain Chick-fil-A One accounts and launched an investigation, ultimately determining that attackers ran an automated credential stuffing campaign against its website and mobile application between June 17 and June 19, 2026.

The attackers used account credentials, including email addresses and passwords, that had been obtained from a third-party source rather than through a direct compromise of Chick-fil-A’s own systems.

Chick-fil-A Data Breach

On July 13, 2026, the company confirmed that unauthorized parties may have accessed information stored within affected Chick-fil-A One accounts.

Credential stuffing relies on previously leaked username-password combinations from unrelated breaches, exploiting password reuse across services rather than any Chick-fil-A-specific vulnerability.

This is not the first time the loyalty program has been targeted; a similar wave of attacks in early 2023 compromised more than 71,000 accounts and affected fewer than 2% of Chick-fil-A One members at the time.

Data Exposed

The breach notification letter, filed with the Massachusetts Attorney General, details a broad set of potentially compromised data points tied to Chick-fil-A One accounts.

  • Names and email addresses
  • Chick-fil-A One membership numbers and mobile pay numbers
  • QR codes used for in-app transactions
  • Last four digits of linked credit or debit card numbers
  • Chick-fil-A credit, including e-gift card balances
  • Phone numbers, birth month and day, and mailing addresses, if saved to the account

While Chick-fil-A has not disclosed the total number of affected customers nationwide, regulatory filings offer a partial picture of the breach’s reach.

Texas alone reported 2,182 affected residents, and notification letters were sent to customers in Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont, and Washington, D.C.

Upon discovering the intrusion, Chick-fil-A forced logouts on affected accounts, removed stored payment methods, and restored any drained Chick-fil-A One balances to their pre-incident state.

The company also reset passwords for impacted users and proactively added reward credits as a goodwill gesture. Chick-fil-A stated it “continues to enhance its security, monitoring, and fraud controls” to reduce the likelihood of similar incidents going forward.

Mitigation

The notification letter urges affected users to take several precautionary steps beyond the automatic remediation Chick-fil-A has already performed.

Reset Chick-fil-A One passwords immediately using a strong, unique credential not reused on other sites, enable multi-factor authentication where available on the account, monitor linked payment cards and financial statements for unauthorized transactions

Place a fraud alert with major credit bureaus if identity theft is suspected, report any suspicious account activity to Chick-fil-A’s support line or local law enforcement

This incident underscores a persistent trend among quick-service restaurant loyalty platforms, where stored payment credit and points make accounts attractive targets for credential stuffing operations that exploit reused passwords rather than platform-level vulnerabilities.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories