Particle.news

Chick‑fil‑A Confirms Credential‑Stuffing Attack Exposed Some Chick‑fil‑A One Accounts

Company says attackers used reused credentials from a third‑party source to access account data, prompting forced logouts, password resets and state breach notifications.

Overview

  • Chick‑fil‑A says an automated credential‑stuffing attack ran against its website and mobile app from June 17 to June 19, 2026 using username/password lists obtained from a third‑party source.
  • Notification letters say attackers may have accessed names, email addresses, Chick‑fil‑A One membership and mobile‑pay numbers, QR codes, reward balances and the last four digits of stored payment cards, and possibly birth dates, phone numbers and addresses if those were saved.
  • The company forced impacted accounts to log out, removed stored payment methods, reset credentials and sessions, restored affected Chick‑fil‑A One balances and added rewards, and it has sent breach notices to customers and multiple state attorneys general.
  • Chick‑fil‑A reported no sign that its own systems were the original source of the stolen credentials and has not released a nationwide total of affected accounts, although state filings show 2,182 impacted Texas residents.
  • The incident mirrors a similar 2022–23 credential‑stuffing wave and highlights that loyalty apps with stored value are attractive targets, so customers should change reused passwords, enable multi‑factor authentication where available, and monitor accounts and statements for fraud.