Chick-fil-A Discloses Data Breach After Credential Stuffing Attacks
Chick-fil-A is notifying customers of a data breach following credential stuffing attacks that compromised customer accounts with stolen credentials.

Fast food giant Chick-fil-A has alerted customers to a data breach that occurred after threat actors utilized stolen credentials from third-party sources to gain unauthorized access to Chick-fil-A One accounts. The attacks, which targeted the company's website and mobile app, took place between June 17 and June 19, 2026. The breach was detected by the company after observing suspicious login activity on its platform.
In a notification to affected individuals and filings with state Attorney General offices, Chick-fil-A detailed that the attackers employed an automated process, leveraging credential pairs obtained from external data breaches. This tactic, known as credential stuffing, is highly effective when users reuse passwords across multiple online services. The investigation confirmed that unauthorized parties accessed information within compromised Chick-fil-A One accounts.
The exposed data includes a combination of customer names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, and QR codes. Additionally, the attackers may have accessed the amount of Chick-fil-A credit, the last four digits of credit/debit card numbers, birth dates, phone numbers, and addresses if these details were stored within the affected accounts.
While Chick-fil-A has not disclosed the total number of affected customers nationwide, the company reported to the Texas Attorney General that 2,182 residents of the state were impacted. Notification letters were also sent to customers in Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
Credential stuffing attacks aim to take over user accounts by systematically trying stolen username and password combinations. Once accounts are compromised, attackers can steal personal and financial information, which may then be sold on the dark web or used for identity theft and other fraudulent activities.
In response to the incident, Chick-fil-A has taken several measures to mitigate the impact on affected customers. This includes logging out all compromised accounts, removing associated payment methods, restoring Chick-fil-A One account balances, and adding rewards as a gesture of apology. The company also strongly advises all impacted users to change their passwords promptly.
This incident is not the first time Chick-fil-A has faced such attacks. In March 2023, the company confirmed a similar breach where threat actors accessed personal information and used stored rewards balances of over 71,000 customers following credential stuffing attacks between December 2022 and February 2023.
The ongoing prevalence of credential stuffing highlights the critical need for robust password management practices, including the use of unique, strong passwords for each online account and enabling multi-factor authentication wherever possible.