Menu
Browse

Cyber Incident Victim: Chick-fil-A

Date:

Jun 2026

Location:

United States of America

Summary

Chick-fil-A disclosed a credential‑stuffing attack in which attackers used login credentials obtained from a third‑party source to gain unauthorized access to customer accounts, prompting the company to force logouts, remove stored payment methods, restore account balances and reset passwords. The compromised data included names, email addresses, membership numbers, mobile pay numbers, QR codes, account credit balances and the last four digits of credit or debit cards, with additional details such as birthdays, phone numbers and mailing addresses potentially exposed for some users. State breach filings showed 39 affected individuals in Massachusetts and 2,182 in Texas, while the total nationwide impact has not been publicly disclosed. The incident follows a similar credential‑stuffing event previously reported by the company.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Chick-fil-A reported a data breach to the Commonwealth of Massachusetts on July 20 2026 after identifying suspicious login activity to certain Chick-fil‑A One accounts and launching an immediate investigation. The company determined on July 13 that unauthorized parties may have accessed information in customer accounts following an automated attack against its website and mobile application that occurred between June 17 and June 19. The attack used credentials obtained from a third‑party source, a method described as credential stuffing, in which attackers attempt to log into accounts using usernames and passwords harvested from other breaches. Notification letters were sent to affected customers and multiple state Attorney General offices were informed of the suspicious activity. The breach was first publicized by the technology publication Bleeping Computer, which also referenced a similar incident in 2023.

Cyber Incident Image

The information potentially accessed included customers’ names, email addresses, Chick-fil‑A One membership numbers, mobile pay numbers, QR codes, account credit balances, and the last four digits of credit or debit card numbers; if customers had stored additional details, birthdays, phone numbers, and mailing addresses could also have been exposed. According to the Massachusetts breach report, 39 residents of that state were affected, while a Texas filing indicated 2,182 customers were impacted; Chick-fil‑A has not disclosed a nationwide total. In the prior 2023 credential‑stuffing incident, 71,473 customer accounts were compromised during an automated attack that lasted from December 2022 through February 2023, exposing similar data elements including names, email addresses, membership numbers, QR codes, account balances, and in some cases birthdays, phone numbers, and addresses.

In response to the 2026 breach, Chick-fil‑A forced logouts of the affected accounts, removed stored payment methods, restored impacted Chick-fil‑A One account balances, and reset passwords for those accounts. The company stated it continued to enhance its security monitoring and fraud controls following the incident. In its customer notice, Chick-fil‑A urged users to update their passwords immediately, create a strong password unique to their Chick-fil‑A account, and monitor credit reports, bank accounts, and account statements for suspicious activity. These actions were communicated directly to the individuals whose data may have been accessed.

Sources
Sources available to members
1 source