CSIDB logo
Incident

Chick-fil-A

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-21 00:50

Linked entities

Victim
Chick-fil-A
Threat actors
0 actors
Sources
9 sources

Timeline

Occurred
Jun 2026
Discovered
Jul 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

Chick-fil-A disclosed that attackers used email and password pairs obtained from a third‑party source to conduct a credential stuffing attack against its website and mobile app, gaining unauthorized access to certain One loyalty accounts over a three‑day period. The compromised data may have included names, email addresses, membership numbers, mobile pay numbers, QR codes, the last four digits of stored credit or debit cards, account credit balances, and, when saved, birthdays, phone numbers and mailing addresses. In response, the company forced affected users to log out, removed stored payment methods, reset passwords, restored account balances and added bonus rewards. While the total number of impacted customers has not been made public, notifications were sent to residents of Texas, Massachusetts and several other states, and the firm noted that a similar credential stuffing incident had occurred previously.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Chick-fil-A first noticed suspicious login activity involving certain Chick-fil‑A One accounts and launched an investigation that revealed an automated credential‑stuffing attack against its website and mobile application. The attack occurred between June 17 and June 19 2026, using email addresses and passwords obtained from a third‑party source. After reviewing the evidence, the company determined on July 13 2026 that unauthorized parties may have accessed information stored in the affected loyalty accounts. Notification letters were sent to impacted individuals on July 20 2026 and copies were filed with the attorneys general of Texas, Massachusetts and several other states.

The data that may have been exposed varied by account but could include customers’ names, email addresses, Chick‑fil‑A One membership numbers, mobile pay numbers, account QR codes, the last four digits of linked credit or debit cards, the amount of Chick‑fil‑A credit stored in an account, and, where saved, the month and day of birthdays, phone numbers and mailing addresses. According to state filings, 2,182 Texas residents and 39 Massachusetts residents were affected, and breach notices were also sent to residents of Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont and Rhode Island. The total number of affected customers nationwide has not been publicly disclosed. This incident follows a similar credential‑stuffing event in March 2023 in which more than 71,000 Chick‑fil‑A One accounts were compromised.

In response, Chick‑fil‑A forced all impacted accounts to log out, removed stored payment methods from those accounts, reset passwords for the affected users, restored any Chick‑fil‑A One balances that had been altered, and added bonus rewards to the accounts as a goodwill gesture. The company sent direct notifications to potentially affected customers, provided a toll‑free telephone line for inquiries, and stated that it continued to enhance its security monitoring and fraud controls to reduce the risk of similar incidents. No further details about the attackers or the exact number of compromised accounts were made public.

Sources

Sources available to members: 9 sources.

CSIDB