Chick-fil-A customer accounts hit in June credential-stuffing wave

The chicken chain says attackers used passwords stolen elsewhere to break into Chick-fil-A One accounts over three days in June 2026.

ThreatVectr Newsdesk· 3 min read
Full-frame overhead view of a generic fast-food mobile ordering app open on a smartphone resting on a wooden table, next to a paper cup and a red drink tray, wa
Share

Key points

  • Chick-fil-A says attackers ran an automated login attack against its website and mobile app between June 17 and June 19, 2026.
  • The company confirmed on July 13, 2026 that customer account data may have been accessed.
  • 2,182 Texas residents are affected, with notification letters also sent to customers in ten other US states and territories.
  • Exposed data includes names, emails, membership numbers, QR codes, stored credit balances, and the last four digits of payment cards.
  • This is the second credential-stuffing incident to hit Chick-fil-A One accounts, following a larger attack disclosed in March 2023.

Chick-fil-A is writing to customers to say their accounts were broken into over a three-day stretch in June, after criminals ran passwords stolen from other websites against the chain's login page.

The attack ran from June 17 to June 19, 2026. Chick-fil-A staff spotted odd login activity, investigated, and confirmed on July 13, 2026 that some Chick-fil-A One accounts had been accessed. Chick-fil-A One is the chain's loyalty and mobile ordering programme.

The technique is called credential stuffing. In plain terms, criminals take giant lists of email addresses and passwords leaked from other breaches, then feed them into a login page using automated tools to see which ones still work. It only pays off because so many people reuse the same password across different sites.

What did the hackers actually see?

They saw the sort of details a customer stores in a fast-food loyalty account. That includes names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, the balance of Chick-fil-A credit on the account, and the last four digits of the saved credit or debit card. If a customer had also saved a birth date, phone number, or address, those may have been exposed too.

Full card numbers were not listed among the exposed fields.

The company has not published a total headcount for affected customers. It did tell the Texas Attorney General that 2,182 Texans were hit. Notification letters have also gone to residents of Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island, as first reported by BleepingComputer.

Chick-fil-A operates more than 3,000 restaurants across the United States, Canada, Puerto Rico, the United Kingdom, and Singapore.

What has the company done about it?

Chick-fil-A logged out every affected account, stripped saved payment methods from them, and restored any stolen loyalty balances. It also dropped bonus rewards into affected accounts as an apology. Customers are being told to pick a new password, and to make sure it is not one they use anywhere else.

From a threat intelligence angle, this is not espionage or a nation-state operation. There is no named group, no clever malware, and no zero-day, meaning a previously unknown software flaw. It is opportunistic account takeover, the same low-effort, high-volume tactic that has hit fast-food apps, coffee chains, and airline loyalty programmes for years. The capability required is close to zero. The intent is straightforward theft: drain loyalty balances, resell the accounts, or bundle the fresh data into the next stolen list.

It is also the second time Chick-fil-A has walked customers through this exact story. In March 2023 the chain confirmed a similar wave of credential-stuffing attacks between December 2022 and February 2023 that hit more than 71,000 accounts and drained stored rewards.

What should customers do now?

If you use Chick-fil-A One, change the password on your account, and change it anywhere else you were using the same one. Turn on any extra login checks the app offers. Keep half an eye on your card statement for the next few weeks, especially small unfamiliar charges. And if you get an email or text claiming to be from the chain and asking you to log in via a link, treat it with suspicion, because breached customer lists are exactly what phishing crews shop for next.

© 2026 Threat Vectr