
Chick-fil-A has notified customers that attackers accessed some Chick-fil-A One loyalty accounts after launching a credential stuffing attack against the company's website and mobile application.
The incident, which occurred in June, allowed unauthorized parties to view personal information stored in affected accounts after they successfully logged in using credentials obtained from a third-party source.
According to a customer notification dated July 20, 2026, Chick-fil-A discovered suspicious login activity affecting certain Chick-fil-A One accounts and immediately launched an investigation while taking steps to block further unauthorized access. The company determined that attackers carried out an automated attack between June 17 and June 19, 2026, attempting to log in to customer accounts using email address and password combinations that had been compromised elsewhere.
The investigation concluded on July 13, 2026, when Chick-fil-A determined that the attackers may have accessed information stored in affected loyalty accounts. The company has not disclosed how many customers were impacted.
Founded in 1967, Chick-fil-A is one of the largest fast-food restaurant chains in the United States, operating more than 3,000 restaurants across North America. Its Chick-fil-A One loyalty program allows customers to earn rewards, redeem points, store payment methods, and manage digital gift card balances through the company's website and mobile application.
According to the notification, the information exposed varied depending on what customers had stored in their accounts. Potentially accessed data includes:
- Customer names
- Email addresses
- Phone numbers
- Physical addresses
- Chick-fil-A One membership numbers
- Mobile pay numbers
- QR codes
- Dates of birth
- Last four digits of linked credit or debit cards
- Balance of any Chick-fil-A credit or electronic gift cards
The company emphasized that the attack was not the result of a direct compromise of Chick-fil-A's systems or password database. Instead, it described the incident as an automated credential-stuffing attack, in which cybercriminals reuse username-password combinations stolen during previous breaches of unrelated online services.
Following discovery of the attack, Chick-fil-A forced affected users to log out of their accounts, removed stored payment methods, reset passwords, and restored impacted Chick-fil-A One account balances. The company also stated that it added loyalty rewards to affected accounts as a gesture of appreciation for customers' continued support.
Customers whose accounts may have been affected are being instructed to reset their Chick-fil-A passwords immediately and choose a unique password that is not used on any other online service. The company is also encouraging users to monitor account statements and credit reports for suspicious activity, and promptly report any unauthorized financial activity to their bank or payment card provider.







Leave a Reply