Chick-fil-A Discloses Data Breach After Credential Stuffing Attacks
Chick-fil-A is notifying customers of a data breach following credential stuffing attacks that compromised customer accounts with stolen credentials.

Fast food giant Chick-fil-A has alerted customers to a data breach that occurred after threat actors utilized stolen credentials from third-party sources to gain unauthorized access to Chick-fil-A One accounts. The attacks, which targeted the company's website and mobile app, took place between June 17 and June 19, 2026. The breach was detected by the company after observing suspicious login activity on its platform.
In a notification to affected individuals and filings with state Attorney General offices, Chick-fil-A detailed that the attackers employed an automated process, leveraging credential pairs obtained from external data breaches. This tactic, known as credential stuffing, is highly effective when users reuse passwords across multiple online services. The investigation confirmed that unauthorized parties accessed information within compromised Chick-fil-A One accounts.
The exposed data includes a combination of customer names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, and QR codes. Additionally, the attackers may have accessed the amount of Chick-fil-A credit, the last four digits of credit/debit card numbers, birth dates, phone numbers, and addresses if these details were stored within the affected accounts.
While Chick-fil-A has not disclosed the total number of affected customers nationwide, the company reported to the Texas Attorney General that 2,182 residents of the state were impacted. Notification letters were also sent to customers in Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
Credential stuffing attacks aim to take over user accounts by systematically trying stolen username and password combinations. Once accounts are compromised, attackers can steal personal and financial information, which may then be sold on the dark web or used for identity theft and other fraudulent activities.
In response to the incident, Chick-fil-A has taken several measures to mitigate the impact on affected customers. This includes logging out all compromised accounts, removing associated payment methods, restoring Chick-fil-A One account balances, and adding rewards as a gesture of apology. The company also strongly advises all impacted users to change their passwords promptly.
This incident is not the first time Chick-fil-A has faced such attacks. In March 2023, the company confirmed a similar breach where threat actors accessed personal information and used stored rewards balances of over 71,000 customers following credential stuffing attacks between December 2022 and February 2023.
The ongoing prevalence of credential stuffing highlights the critical need for robust password management practices, including the use of unique, strong passwords for each online account and enabling multi-factor authentication wherever possible.
The Malwarebytes Labs article provides additional detail on the mechanics of credential stuffing attacks, explaining how attackers leverage breached credentials from other sources to gain access. It also elaborates on the specific types of data potentially accessed, including names, email addresses, membership numbers, QR codes, gift card balances, and partial payment card details, and offers advice to customers on securing their accounts, such as resetting passwords and enabling multi-factor authentication.
The latest report indicates that the credential stuffing attack against Chick-fil-A One accounts occurred between June 17 and June 19, 2026, and affected customers in ten U.S. states. While the company has reset affected passwords and removed stored payment methods, it is now urging all users to proactively change their passwords due to the potential exposure of names, emails, mobile payment numbers, and partial payment card details. This incident is the second such attack on Chick-fil-A One accounts, following a previous campaign that impacted over 70,000 accounts between 2022 and 2023.
The latest disclosure from Chick-fil-A provides more granular detail on the types of data compromised, including names, email addresses, membership and mobile pay numbers, partial payment card details, and account balances. For affected accounts where funds were drained, the company has restored balances and added additional rewards. Chick-fil-A has also implemented security measures such as forced logouts, password resets, and removal of stored payment methods for compromised accounts.
The latest disclosure reveals that the credential stuffing attacks against Chick-fil-A's website and mobile app, which occurred between June 17 and June 19, resulted in the unauthorized access of 13,322 customer accounts. The compromised data includes names, email addresses, membership numbers, credit amounts, mobile pay numbers, and the last four digits of payment cards, with potential access to birth dates, phone numbers, and addresses. In response, Chick-fil-A has logged out affected accounts, removed payment methods, restored account balances, and added rewards to affected accounts.