Overview
- Chick‑fil‑A says unauthorized parties ran an automated credential‑stuffing attack against its website and app between June 17 and June 19, 2026 and determined on July 13 that some Chick‑fil‑A One accounts may have been accessed.
- The company’s notification letters say accessed data may include names, email addresses, Chick‑fil‑A One membership and mobile pay numbers, QR codes, stored Chick‑fil‑A credit and the last four digits of payment cards, with birth dates, phone numbers and addresses exposed if they were saved.
- Chick‑fil‑A has notified customers and state regulators in multiple jurisdictions and told the Texas attorney general the incident affected 2,182 Texas residents while declining to provide a nationwide total.
- To secure accounts the company forced logouts, removed stored payment methods, reset affected passwords, restored loyalty balances and added rewards, and it is urging customers to change passwords and monitor bank and credit statements.
- Security experts warn credential stuffing exploits reused passwords from other breaches and point to a similar 2022–2023 wave that compromised more than 71,000 Chick‑fil‑A accounts, making loyalty programs a repeated target for fraud and resale of harvested data.