Description

Chick-fil-A has confirmed a data security incident affecting an undisclosed number of Chick-fil-A One loyalty accounts after detecting suspicious login activity targeting its website and mobile application. According to the company’s customer notification dated July 20, 2026, unauthorized actors conducted automated credential-stuffing attacks between June 17 and June 19, 2026, using usernames and passwords obtained from unrelated third-party breaches instead of compromising Chick-fil-A’s own systems. On July 13, 2026, the company determined that attackers may have accessed customer account information. Potentially exposed data includes names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers, account QR codes, remaining gift card or account credit balances, the last four digits of linked payment cards, and, for some users, birth month and day, phone numbers, and residential addresses. Although full payment card details were not exposed, the compromised information could support identity fraud and account abuse. The attack relied on credential stuffing, where automated bots tested large volumes of previously leaked username and password combinations against Chick-fil-A’s login portals. The valid credentials enabled unauthorized access without exploiting software vulnerabilities. Once inside affected accounts, attackers could view loyalty balances, stored payment information, QR codes, and customer profile data, increasing the risk of fraudulent reward redemption, account takeover, phishing campaigns, and social engineering attacks. The incident highlights the importance of implementing rate limiting, bot detection, breached-password screening, behavioral analytics, anomalous login monitoring, device fingerprinting, and phishing-resistant MFA to reduce automated authentication abuse. Chick-fil-A responded by forcing logouts for affected accounts, resetting passwords, removing saved payment methods, restoring compromised balances, and notifying impacted customers. Regulatory filings indicate that at least 2,182 Texas residents and 39 Massachusetts residents were affected, with notifications also issued in several other U.S. states and the District of Columbia. Customers are advised to create unique passwords, replace reused credentials on other services, review account activity, and remain alert for phishing attempts.