Overview
- Chick‑fil‑A says unauthorized actors used stolen username/password lists to run an automated credential‑stuffing attack against its website and app on June 17–19, 2026.
- The company notified customers in Washington, D.C., and at least 10 states and state filings show 2,182 Texans were affected while no national total has been released.
- Information that may have been accessed includes names, email addresses, Chick‑fil‑A One membership and mobile pay numbers, reward balances and the last four digits of payment cards, plus birth dates, phone numbers or addresses if saved.
- To secure accounts Chick‑fil‑A forced logouts, removed stored payment methods, reset passwords, restored impacted Chick‑fil‑A One balances and added rewards, and it is urging customers to create unique passwords and monitor financial activity.
- The company says its systems do not appear to be the source of the stolen credentials, highlighting the risk of password reuse and repeating a pattern after a similar 2023 credential‑stuffing incident that affected over 71,000 accounts.