Credential-Stuffing Attack

Chick-fil-A Reports Data Breach Affecting Customer Accounts

Data Breach, credential stuffing, Chick-fil-A data breach, Chick-fil-A data breach 2026, Chick-fil-A One account data breach, Chick-fil-A. Cyberattack,
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Ken Wolter/Shutterstock.com

Chick-fil-A is notifying customers about a data security incident following credential-stuffing attacks in June. Personal information and account balances may have been exposed.

US fast-food chain Chick-fil-A has notified several state attorneys general and affected customers about a security incident. Between June 17 and June 19, 2026, unauthorized actors carried out automated credential-stuffing attacks against the company’s website and mobile app. The attackers used combinations of email addresses and passwords obtained from third-party data breaches. The company described its findings in notification letters as follows:

Ad

“After a careful investigation, we determined that between June 17 and June 19, 2026, unauthorized parties launched an automated attack against our website and mobile application using account credentials (e.g., email addresses and passwords) obtained from a third-party source. Based on our investigation, on July 13, 2026, we determined that the unauthorized parties may have accessed information in your Chick-fil-A One account.”

Chick-fil-A

Ad

Affected Customer Data and Account Information

As a result of the unauthorized access to Chick-fil-A One accounts, the attackers may have gained access to various types of customer data. This included names, email addresses, membership numbers, mobile payment numbers, QR codes, account balances, and the last four digits of stored credit or debit cards.

Where this information was included in customer profiles, birth dates, phone numbers, and home addresses may also have been accessible. The company did not disclose the total number of affected users. In a filing with the Texas Attorney General’s Office, Chick-fil-A said that 2,182 residents of the state were affected.

Company Response and Recommendations for Customers

In response to the incident, the company logged all affected accounts out, removed stored payment methods, and restored loyalty program balances that had been withdrawn. Customers affected by the incident were advised to change their passwords.

Chick-fil-A was previously targeted in a similar wave of credential-stuffing attacks between December 2022 and February 2023. At the time, accounts belonging to more than 71,000 customers were affected.

(ll)

Ad

Artikel zu diesem Thema

Weitere Artikel