Chick-fil-A has confirmed that unauthorized actors gained access to certain Chick-fil-A One loyalty accounts through a credential stuffing attack, exposing customer names, email addresses, phone numbers, membership information, and the last four digits of stored payment cards. The company first detected suspicious login activity on its website and mobile app, leading to an investigation that revealed an automated attack running from June 17 through June 19, 2026. Chick-fil-A determined on July 13 that unauthorized parties may have accessed information stored inside affected accounts.

The attackers obtained email addresses and passwords from a third-party source and then tested those login combinations against Chick-fil-A One accounts. When customers had reused the same password across multiple services, the attackers were able to gain entry. Although Chick-fil-A has not disclosed the total number of affected customers, public filings show that the breach affected 2,182 Texas residents and 39 Massachusetts residents. The company also submitted notifications involving residents of Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island, indicating that the incident likely impacted a broader but still limited number of accounts nationwide.

The exposed data varied by account. According to Chick-fil-A's notification, the information that may have been accessed includes customer names on the account, email addresses, phone numbers, physical addresses if provided, birthday if entered, payment card type and last four digits, membership tier information, and the QR code used for in-store rewards scanning. The company emphasized that full payment card numbers, Social Security numbers, or bank account details were not part of the exposed information. However, the combination of personal details and partial card data could help cybercriminals craft convincing phishing messages that appear legitimate because they include accurate personal information.

This is not the first time Chick-fil-A has faced such an attack. In March 2023, the company confirmed that attackers had accessed more than 71,000 customer accounts in a credential stuffing campaign that ran from December 2022 through February 2023. In that earlier incident, attackers accessed personal information and used stored rewards balances in some accounts. The repeat incident underscores how stolen login credentials from older data leaks remain useful to criminals who continue to test them across popular online services years after the original breach.

In response to the current incident, Chick-fil-A took immediate steps to secure accounts. The company logged affected customers out of their accounts, removed saved payment methods, and added rewards to the compromised accounts as a precaution. A spokesperson for Chick-fil-A, Inc. stated that upon discovering the issue, the company took steps to immediately address, secure, and restore accounts, and is communicating directly with all customers who may have been impacted. The company apologized for any inconvenience or concern and reaffirmed its commitment to maintaining customer trust.

Credential stuffing remains a widespread cybersecurity threat because many people reuse passwords across multiple websites and apps. When one service suffers a breach and usernames and passwords are leaked, automated tools quickly test those credentials on other popular platforms. The attack works without breaching the targeted company's own security systems; instead, it exploits the password reuse habit of users. Cybersecurity experts recommend enabling multifactor authentication whenever available, as it provides an additional layer of protection even if a password is compromised.

Chick-fil-A is advising all customers to create a strong, unique password for their Chick-fil-A One account that is not used on any other service. Customers should also review their stored payment methods and recent rewards activity for any unauthorized use. The company recommends accessing the account only through the official Chick-fil-A app or by typing the company's website directly into a browser, rather than clicking on links in unsolicited messages. Even customers who have not received a notification from Chick-fil-A are urged to take these precautions, as the full scope of affected accounts may not yet be known.

The breach serves as a reminder that loyalty accounts, while often seen as less sensitive than bank or email accounts, can still contain valuable personal information and stored payment details that make them attractive targets for cybercriminals. As companies continue to digitize customer interactions, the risk of credential theft and account takeover remains elevated. Users are encouraged to adopt password managers to generate and store unique passwords for each online service, and to remain vigilant against phishing attempts that may reference the breach.