Chick-fil-A has disclosed a data breach affecting an unspecified number of customers, attributing the incident to a series of credential stuffing attacks that targeted its website and mobile application in June. The fast-food chain, which operates over 3,000 restaurants across multiple countries, began notifying affected individuals through data breach letters filed with various Attorney General offices.
The company's investigation determined that unauthorized parties launched automated attacks between June 17 and June 19, 2026. These attackers utilized email addresses and passwords previously obtained from a third-party source, indicating a credential stuffing methodology where stolen credentials from one service are tried on others. Chick-fil-A confirmed on July 13, 2026, that information within affected Chick-fil-A One accounts may have been accessed.
The compromised data includes customers' names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, and QR codes. Additionally, the amount of Chick-fil-A credit and the last four digits of credit/debit card numbers were exposed. For accounts where the information was stored, attackers may also have gained access to birth dates, phone numbers, and addresses.
While the total number of affected customers remains undisclosed, Chick-fil-A informed the Texas Attorney General that 2,182 Texans were impacted. Notification letters were also sent to residents in Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
In response to the breach, Chick-fil-A took several steps: all impacted accounts were logged out, payment methods were removed, and Chick-fil-A One account balances were restored. The company also added rewards to affected accounts as a gesture of apology. Customers whose accounts were compromised have been advised to change their passwords immediately.
This incident marks a recurring challenge for Chick-fil-A. In March 2023, the company confirmed a similar credential stuffing attack between December 2022 and February 2023, which resulted in unauthorized access to personal information and the use of stored rewards balances for over 71,000 customers.






