Chick‑fil‑A says unauthorized actors used credentials obtained from a third‑party source to access Chick‑fil‑A One accounts in a credential‑stuffing attack from June 17–19, 2026, with the company concluding on July 13 that some account data may have been exposed. Potentially viewed information includes names, emails, membership and mobile pay numbers, QR codes, stored balances and the last four digits of payment cards; optional fields such as birth dates, phone numbers and addresses could also be affected. Chick‑fil‑A signed affected users out, removed saved payments, forced password resets, restored balances and credited rewards while saying it will strengthen security controls.
Chick‑fil‑A Confirms June Credential‑Stuffing Attack Exposed Chick‑fil‑A One Accounts

Chick‑fil‑A has notified customers that unauthorized actors accessed Chick‑fil‑A One loyalty accounts in a credential‑stuffing attack that targeted the company’s website and mobile app from June 17–19, 2026. The company said it determined on July 13 that some customer account information may have been exposed.
In credential‑stuffing incidents, attackers use automated tools to test username/password pairs—often harvested from previous breaches—across unrelated services to find accounts that use the same credentials. Chick‑fil‑A said the intruders relied on login credentials obtained from a third‑party source to gain access to accounts.
What Data May Have Been Exposed
Chick‑fil‑A said the information that may have been viewed includes:
- Names and email addresses
- Chick‑fil‑A One membership numbers and mobile pay numbers
- QR codes tied to accounts, stored credit balances and the last four digits of stored payment cards
- Optional profile fields — where provided — such as dates of birth, phone numbers and home addresses
Scope And Notifications
The company has not released a nationwide total of affected customers. State breach filings show at least 2,182 impacted customers in Texas and 39 in Massachusetts, according to BleepingComputer. Chick‑fil‑A also sent notifications to residents of Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont and Rhode Island.
"We recently identified a security incident that may have affected a limited number of Chick‑fil‑A One Loyalty accounts," a company spokesperson told Newsweek. "We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day."
Company Response And Customer Actions
To contain the incident and protect customers, Chick‑fil‑A has taken several steps:
- Signed affected users out of their accounts and forced password resets
- Removed saved payment methods and restored any drained account balances
- Credited rewards to impacted accounts and said it is enhancing security and monitoring controls
Chick‑fil‑A is urging customers to set new, unique passwords for their Chick‑fil‑A accounts. Security experts also recommend enabling multi‑factor authentication (if available), monitoring financial statements for suspicious charges, watching for phishing messages that reference the incident, and reviewing account activity.
Background
This is not the first credential‑stuffing incident involving Chick‑fil‑A. In 2023, attackers accessed more than 71,000 Chick‑fil‑A accounts in a campaign that ran from December 2022 into February 2023, exposing similar categories of personal information and prompting comparable security measures by the company, according to BleepingComputer.
Chick‑fil‑A and outside investigators continue to review the incident. Customers with concerns should consult the company’s breach notification and follow guidance in any notices they received.
Help us improve.


































