Chick-fil-A Warns Customers After Loyalty Account Data Breach

Chick-fil-A has confirmed a customer data breach after credential stuffing attacks compromised an undisclosed number of Chick-fil-A One accounts and exposed personal information.
Chick-fil-A logo on a dark background representing the company’s disclosure of a customer data breach affecting certain Chick-fil-A One loyalty accounts following credential stuffing attacks.

Chick-fil-A is notifying customers after a credential stuffing campaign compromised an undisclosed number of Chick-fil-A One loyalty accounts, potentially exposing personal and payment-related information stored within affected profiles.

According to data breach notification letters filed with multiple U.S. state Attorneys General, the company detected suspicious login activity involving certain customer accounts and determined that unauthorized parties targeted its website and mobile application between June 17 and June 19, 2026. The attackers allegedly used email addresses and passwords obtained from a third-party source to gain access to customer accounts.

Automated attacks targeted loyalty accounts

In its notification letter, Chick-fil-A said the incident resulted from an automated credential stuffing attack rather than a compromise of its own authentication systems. Credential stuffing occurs when attackers use usernames and passwords exposed in previous data breaches to attempt logins across other online services, relying on customers who reuse passwords across multiple platforms.

Following its investigation, Chick-fil-A determined on July 13, 2026 that unauthorized parties may have accessed information stored within certain Chick-fil-A One accounts.

What information may have been accessed

According to the notification letters, the exposed information varies by account but may include:

  • Names
  • Email addresses
  • Chick-fil-A One membership numbers
  • Mobile Pay numbers
  • QR codes
  • Chick-fil-A credit and gift card balances
  • Last 4 digits of stored credit or debit card numbers
  • Birth dates (month and day)
  • Phone numbers
  • Mailing addresses

The company said additional personal information such as birth dates, phone numbers, and addresses would only have been exposed if customers had chosen to store those details in their accounts.

Company has not disclosed total number of affected customers

Chick-fil-A has not publicly disclosed how many customer accounts were impacted by the incident. However, regulatory filings provide a limited view of the breach’s scope.

According to notifications submitted to state regulators, the incident affected 2,182 Texas residents and 39 Massachusetts residents. Customers in Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont also received breach notification letters.

Mitigation steps and customer guidance

As part of its response, Chick-fil-A logged affected users out of their accounts, removed stored payment methods, restored impacted Chick-fil-A One balances, and added rewards to affected accounts as a goodwill gesture.

The company is advising affected customers to reset their passwords immediately, use unique passwords that are not shared across other online services, monitor their account activity and financial statements for suspicious transactions, and remain alert for phishing attempts using their exposed information.

Second credential stuffing incident in recent years

This is not the first time Chick-fil-A has dealt with account takeover attacks. In 2023, the company disclosed that more than 71,000 Chick-fil-A One accounts were compromised during a separate credential stuffing campaign that occurred between December 2022 and February 2023. Attackers in that incident accessed customer information and redeemed stored loyalty rewards before the activity was detected.

The recurrence of credential stuffing attacks highlights the ongoing risks associated with password reuse. While these incidents typically do not indicate that a company’s internal authentication systems were breached, attackers can still successfully access customer accounts when previously exposed credentials are reused across multiple online services.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site