What Happened in the Chick-fil-A Data Breach?
Chick-fil-A has begun notifying customers that their Chick-fil-A One accounts were compromised in a wave of credential stuffing attacks. The company filed breach notifications with several state Attorney General offices, confirming that unauthorized parties gained access to customer account information. This Chick-fil-A data breach adds to growing concerns about account takeover attacks across the restaurant industry.
According to the notification, attackers ran an automated attack against Chick-fil-A’s website and mobile app between June 17 and June 19, 2026. The attackers used login credentials, including email addresses and passwords, that they had obtained from an unrelated third-party source. Because many people reuse passwords across different websites, stolen credentials from one breach can unlock accounts on completely unrelated platforms.
Chick-fil-A launched an investigation after noticing suspicious login activity on certain Chick-fil-A One accounts. As a result of that review, the company determined on July 13, 2026 that unauthorized parties may have viewed personal information stored in affected accounts. This is not the first time Chick-fil-A has faced this type of attack. The company disclosed a similar credential stuffing incident in 2023 that affected more than 71,000 customers between December 2022 and February 2023.
Who was affected?
The individuals affected are customers who held Chick-fil-A One loyalty accounts through the company’s website or mobile app. Chick-fil-A has not publicly disclosed the total number of customers impacted nationwide. However, state filings offer a partial picture: the company reported 2,182 affected residents in Texas and 39 in Massachusetts.
Chick-fil-A also sent notification letters to residents of Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island. Because Chick-fil-A operates over 3,000 locations across the United States, Canada, Puerto Rico, the United Kingdom, and Singapore, the true scope of affected customers could be much larger than the state-reported figures suggest. Anyone who used a Chick-fil-A One account between June 17 and June 19, 2026 should consider themselves potentially at risk.
What Information Was Potentially Exposed?
The exposed data varies by account, depending on what information each customer had stored in their Chick-fil-A One profile. In addition, some accounts contained more sensitive personal details than others.
- Full names
- Email addresses
- Chick-fil-A One membership numbers
- Mobile pay numbers and QR codes
- Chick-fil-A credit balances
- Last four digits of credit or debit card numbers
- Birth dates (if stored)
- Phone numbers (if stored)
- Physical addresses (if stored)
This combination of data creates real risk for affected customers. Although only the last four digits of payment cards were exposed, combining that detail with a name, email, and birth date gives scammers enough material to craft convincing phishing messages. For example, a fraudster could impersonate Chick-fil-A support and reference real account details to appear legitimate.
Furthermore, because membership numbers and mobile pay numbers were exposed, criminals could attempt to drain stored reward balances or credit. This kind of account fraud is a direct financial loss even without a full card number. In addition, any customer whose birth date and address were stored faces a heightened risk of broader identity theft attempts down the road.
What is the company doing?
Chick-fil-A responded to the breach by logging out all impacted accounts to stop any active unauthorized access. The company also removed stored payment methods from affected accounts to prevent further misuse. In addition, Chick-fil-A restored account balances that had been affected and added rewards to impacted accounts as a gesture of goodwill.
Beyond these immediate steps, Chick-fil-A advised every affected customer to change their password right away. The company continues to notify state regulators as required by law, filing breach reports with Attorney General offices across multiple states. However, Chick-fil-A has not yet confirmed whether it will offer credit monitoring or identity protection services to affected customers.
What Should Affected Individuals Do?
Change Your Password Immediately
If you have a Chick-fil-A One account, change your password right away, even if you have not received a notification letter. Choose a password you have never used on any other website or app.
This step matters because credential stuffing only works when people reuse passwords. As a result, switching to a strong, unique password for every account you own is one of the most effective ways to prevent future account takeovers.
Monitor Your Accounts and Credit Reports
Check your Chick-fil-A One account activity regularly for unfamiliar orders, missing rewards balances, or unrecognized devices. In addition, review your bank and credit card statements for charges you did not make.
Because some birth dates and addresses may have been exposed, it is also wise to check your credit report for new accounts you did not open. You can request free credit reports from each of the three major credit bureaus once a year, and reviewing them regularly helps catch fraud early.
Watch for Phishing Attempts
Be cautious of emails, texts, or calls claiming to be from Chick-fil-A that ask you to confirm account details or click a link. Scammers often use breach news as cover to launch convincing phishing campaigns.
Instead of clicking links in unexpected messages, go directly to the official Chick-fil-A app or website to check your account. If a message asks for your password, card number, or Social Security number, treat it as suspicious and do not respond.
Consider a Fraud Alert if Sensitive Data Was Involved
If your notification letter confirms that your birth date, phone number, or address was exposed, consider placing a fraud alert on your credit file. This makes it harder for anyone to open new credit accounts in your name.
A fraud alert is free and lasts for one year, though you can renew it. For added protection, you might also consider a credit freeze, which restricts access to your credit report entirely until you lift it.
Consult a Data Breach Attorney
If you received a notification letter from Chick-fil-A, you may want to speak with a data breach attorney about your options. An attorney can review the specifics of your exposure and explain whether you may qualify for compensation.
Many law firms offer free consultations for data breach cases like this one. Because deadlines for legal claims can be strict, it is worth acting sooner rather than later if you plan to explore this option.
More Information
Official data breach notification from California Attorney General
