Chick-fil-A Confirms Customer Data Compromised by Credential-Stuffing Attack

Massachusetts’ breach notification to state officials shows 39 affected residents, while Texas filings report 2,182 Texans impacted; Chick-fil-A also notified residents in Iowa and the District of Columbia.
Attackers’ access included QR codes stored in Chick-fil-A One accounts, in addition to names, emails and membership numbers.
Credentials also exposed account balances and mobile pay numbers; in some cases, attackers could see the last four digits of stored cards.
The breach was carried out via an automated credential-stuffing campaign that used login pairs from third-party breaches to bypass basic authentication limits; Chick-fil-A says the compromise came from stolen credentials, not a flaw in its own systems.
Chick-fil-A’s notice includes the line: 'Based on our investigation, we determined on July 13, 2026 that the unauthorized parties may have accessed information in your Chick-fil-A One account.'
Chick-fil-A is warning customers that hackers broke into some Chick-fil-A One loyalty accounts between June 17 and 19, 2026, using stolen passwords from other websites. The company confirmed on July 13, 2026 that the attack succeeded, exposing names, email addresses, membership numbers, and in some cases the last four digits of stored payment cards, according to Yahoo Finance.
Texas officials report at least 2,182 state residents were affected. Massachusetts logged 39 impacted residents. Chick-fil-A also notified customers in Iowa and the District of Columbia, though the total nationwide count remains unclear, KTBS reported.
The attack used a method called credential stuffing. Hackers take usernames and passwords stolen from other data breaches and try them on a different site. Many people reuse the same password across services, which makes this tactic effective. Chick-fil-A says the breach came from those stolen credentials — not a flaw in its own systems, according to WAKA.
Chick-fil-A's notice states: 'Based on our investigation, we determined on July 13, 2026 that the unauthorized parties may have accessed information in your Chick-fil-A One account.' The automated attack ran for just three days, from June 17 to 19, El-Balad reported.
The breach hit several types of stored data. Hackers could see customer names, email addresses, membership numbers, and mobile pay numbers. They could also view QR codes stored inside the Chick-fil-A One app. In some accounts, they saw the last four digits of saved payment cards, Yahoo Finance reported.
Where customers had saved extra details, more data was at risk. That includes birth dates, phone numbers, home addresses, and account balances. Chick-fil-A has prompted affected customers to reset their passwords as a precaution, according to KTBS.
This breach is not a one-time event. Chick-fil-A suffered a similar widespread credential-stuffing attack from late 2022 into early 2023. That earlier incident also compromised Chick-fil-A One accounts. The repeat attack shows the company remains a target for this type of automated account takeover, according to Yahoo Finance.
The pattern points to a broader problem: people reusing passwords across multiple sites. When any one service gets hacked, those credentials can be used to break into unrelated accounts. Security experts say using a unique password for each account is the most reliable defense.
Law firm Shamis & Gentile P.A. has launched an investigation into the breach, according to Claim Depot. The firm, which specializes in data breach class action cases, says the incident may have affected thousands of customers and is reviewing potential legal claims on behalf of those impacted.
Chick-fil-A has sent breach notifications to residents in at least four jurisdictions: Texas, Massachusetts, Iowa, and the District of Columbia. The chain operates more than 3,000 locations across the United States. The full scope of affected customers has not been publicly disclosed.
Publishers
14
Articles
45
Reach
59