Overview
- Chick‑fil‑A says an automated credential‑stuffing attack ran against its website and mobile app from June 17 to June 19, 2026 using username/password lists obtained from a third‑party source.
- Notification letters say attackers may have accessed names, email addresses, Chick‑fil‑A One membership and mobile‑pay numbers, QR codes, reward balances and the last four digits of stored payment cards, and possibly birth dates, phone numbers and addresses if those were saved.
- The company forced impacted accounts to log out, removed stored payment methods, reset credentials and sessions, restored affected Chick‑fil‑A One balances and added rewards, and it has sent breach notices to customers and multiple state attorneys general.
- Chick‑fil‑A reported no sign that its own systems were the original source of the stolen credentials and has not released a nationwide total of affected accounts, although state filings show 2,182 impacted Texas residents.
- The incident mirrors a similar 2022–23 credential‑stuffing wave and highlights that loyalty apps with stored value are attractive targets, so customers should change reused passwords, enable multi‑factor authentication where available, and monitor accounts and statements for fraud.