Chick-fil-A is notifying customers across the United States about a data breach that hit its Chick-fil-A One loyalty program. The fast-food giant confirmed that unauthorized parties broke into customer accounts using a technique called credential stuffing, exposing personal and payment-related information. Here is everything known so far, based on the company’s own notification letters and state regulatory filings.
What Happened in the Chick-fil-A Data Breach
Chick-fil-A discovered suspicious login activity on certain Chick-fil-A One accounts and launched an investigation. The company determined that unauthorized parties ran an automated attack against its website and mobile application between June 17, 2026, and June 19, 2026. The attackers did not breach Chick-fil-A’s internal systems directly. Instead, they used usernames and passwords stolen from earlier, unrelated data breaches at other companies and tested them against Chick-fil-A’s login pages, a method known as credential stuffing.
Chick-fil-A completed its internal investigation on July 13, 2026, concluding that the attackers had indeed accessed personal information tied to certain accounts. Breach notification letters were dated July 20, 2026, and were mailed to affected customers as well as filed with multiple state Attorneys General offices.
What Information Was Exposed
According to the notification letters, the information accessed may have included:
- Full names
- Email addresses
- Chick-fil-A One membership numbers
- Mobile pay numbers and QR codes
- Last four digits of stored credit or debit card numbers
- Account balances
- Dates of birth (month and day)
- Phone numbers
- Home addresses, where saved to the account
Chick-fil-A has said the breach affected “a limited number” of Chick-fil-A One accounts but has not released a total nationwide figure.
How Many Customers Were Affected
Chick-fil-A has not disclosed an exact nationwide total, but regulatory filings give a partial picture:
- Texas: 2,182 residents affected
- Massachusetts: 39 residents affected, reported to the state on July 20, 2026
- Vermont: 2 residents affected
The company also sent notification letters to residents of Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, and Rhode Island, though exact per-state numbers for those areas have not been made public.
Chick-fil-A’s Response and Remediation Steps
Once the suspicious activity was confirmed, Chick-fil-A said it took the following steps to secure affected accounts:
- Forced logouts on all compromised accounts
- Removed saved payment methods from affected accounts
- Reset passwords on impacted accounts
- Restored any account balances that had been drained
- Added rewards to affected customer accounts as a goodwill gesture
- Said it is enhancing ongoing security and monitoring controls
A company spokesperson said: “We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted.” The spokesperson added an apology for the inconvenience and reaffirmed the company’s commitment to customer trust.
Not Chick-fil-A’s First Credential Stuffing Incident
This is the second time Chick-fil-A has dealt with a credential stuffing attack of this scale. A prior incident, disclosed in 2023, revealed that attackers broke into more than 71,000 Chick-fil-A accounts during a months-long campaign that ran from December 2022 into February 2023. Cybersecurity commentators have pointed out that Chick-fil-A offers multi-factor authentication on its loyalty app but does not require customers to use it, which may have left the door open for a repeat attack.
Industry data adds context to why these attacks keep happening. Verizon’s 2025 Data Breach Investigations Report found that stolen credentials were behind 22 percent of all confirmed data breaches that year. Separately, in June 2026 — the same month the Chick-fil-A attack occurred — researchers discovered a massive 24-billion-record credential database sitting exposed and unsecured online, made up largely of information stolen through infostealer malware. Databases like this are exactly what fuels credential stuffing attacks against major consumer brands.
What Chick-fil-A One Customers Should Do Now
If you have a Chick-fil-A One account, security experts recommend the following steps regardless of whether you received a breach notification letter:
- Reset your password immediately, even if you have not been notified
- Use a unique password for your Chick-fil-A account that you don’t reuse anywhere else
- Enable multi-factor authentication if the app offers it
- Consider a password manager to generate and store strong, unique passwords
- Monitor your bank and card statements for any unfamiliar charges
- Watch for phishing emails that may impersonate Chick-fil-A following the breach announcement
Frequently Asked Questions
When did the Chick-fil-A data breach happen? The attack took place between June 17, 2026, and June 19, 2026. Chick-fil-A confirmed on July 13, 2026, that customer data had been accessed, and notification letters went out on July 20, 2026.
How did hackers get into Chick-fil-A accounts? Attackers used a method called credential stuffing. They took usernames and passwords stolen from earlier breaches at other, unrelated companies and used automated tools to try them on Chick-fil-A’s website and app. Chick-fil-A’s own systems were not directly hacked.
Was my credit card number stolen? Only the last four digits of stored credit or debit card numbers were exposed, along with mobile pay numbers and QR codes tied to the Chick-fil-A One account. Full card numbers were not disclosed in the notification letters.
How many people were affected in total? Chick-fil-A has not released a nationwide total. State filings show at least 2,182 affected in Texas, 39 in Massachusetts, and 2 in Vermont, with additional notifications sent to several other states.
Has this happened to Chick-fil-A before? Yes. A similar credential stuffing attack was disclosed in 2023, affecting more than 71,000 accounts between December 2022 and February 2023.
What is Chick-fil-A doing to fix this? The company forced logouts on affected accounts, removed saved payment methods, reset passwords, restored drained balances, added rewards to impacted accounts, and says it is strengthening its security monitoring going forward.
Stay tuned as more details emerge about the full scope of the Chick-fil-A data breach — and don’t forget to reset your Chick-fil-A One password today if you haven’t already!