
Chick-fil-A Data Breach Hits Customers After Credential Stuffing
.webp)
Chick-fil-A is notifying customers in multiple US states about a data breach affecting Chick-fil-A One loyalty accounts. The fast food chain says attackers ran an automated credential stuffing attack against its website and mobile app. The attack took place between June 17 and June 19, 2026.
The company first noticed suspicious login activity on certain accounts and opened an investigation. That investigation confirmed on July 13 that unauthorized parties had accessed personal information inside affected accounts. Chick-fil-A has since sent breach notification letters to customers and filed reports with several state Attorney General offices.
How the Data Breach Happened
Chick-fil-A says the attackers used email addresses and passwords pulled from a third-party source, not from any breach of its own systems. This is known as credential stuffing. Attackers take large batches of previously leaked username and password pairs and test them against other websites and apps.
Automated tools do the heavy lifting, cycling through thousands of stolen logins in minutes. The tactic succeeds because so many people reuse passwords across different accounts. Once one service leaks credentials, criminals recycle them elsewhere and bet a fraction still work. A short, high-volume attack window like the one Chick-fil-A described fits this pattern well.
What Information Attackers Accessed
The exposed data includes customer names, email addresses, and Chick-fil-A One membership numbers. It also includes mobile pay numbers, QR codes, and stored Chick-fil-A credit balances. Attackers accessed the last four digits of customers' credit or debit card numbers too.
Some accounts stored birth dates, phone numbers, and home addresses. Those may have been exposed as well. Chick-fil-A hasn't released a total victim count, but state filings give a partial picture of the data breach's scope. The company told the Texas Attorney General the breach affects 2,182 residents there.
It also notified residents of Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island. The multi-state notification pattern suggests the true number of affected customers runs well into the tens of thousands nationally.
Chick-fil-A's Response to the Breach
Chick-fil-A logged out every affected account after confirming the incident. The company also removed stored payment methods and restored account balances. It added extra rewards to affected accounts as a gesture of good will.
The breach stemmed from reused credentials rather than a flaw in Chick-fil-A's own systems. Because of that, the company is urging every affected customer to change their password right away. Anyone who reused that password elsewhere should update it there too. The same stolen list may already be circulating against other platforms.
A company spokesperson had not commented publicly on the total number of breached accounts as of this writing.
A Repeat Incident for the Loyalty Program
This is not the first time attackers have targeted Chick-fil-A One accounts this way. In March 2023, the company confirmed a similar credential stuffing campaign. That earlier incident compromised more than 71,000 customer accounts between December 2022 and February 2023. Attackers accessed personal information and drained stored rewards balances.
Two similar breaches within three years point to a pattern, not a one-off event. Loyalty programs make attractive targets. Accounts often hold stored payment methods and cash-equivalent balances that attackers can spend or resell quickly.
What Customers Should Do Now
Anyone with a Chick-fil-A One account should treat this data breach as a reason to review their broader password habits. A unique, strong password on every service removes the main advantage credential stuffing depends on. Reused passwords are the single biggest reason these data breach attempts keep working across so many unrelated companies.
Multi-factor authentication adds a second barrier even if a password leaks elsewhere. Customers should also watch their Chick-fil-A One balance and linked payment methods closely over the coming weeks. Stolen loyalty accounts sometimes get drained or resold before a company finishes notifying victims of a breach.
Lessons for Businesses Running Loyalty Programs
Businesses running their own loyalty or account systems can learn from this recurrence too. Catching credential stuffing early means monitoring for unusual login patterns instead of waiting for complaints. Rate limiting, bot detection, and mandatory multi-factor authentication all limit how far stolen credentials can travel before someone notices, and they cut down how often a data breach like this one repeats.
A data breach caused by recycled passwords is preventable on both sides. Companies can add friction that slows automated login attempts, while also flagging logins from unfamiliar devices or locations before real damage happens. Customers can stop giving attackers working credentials to test in the first place, closing off most of the openings credential stuffing campaigns rely on.
Subscribe to receive the latest blog posts to your inbox every week.