Chick-fil-A disclosed a data breach after attackers used credential stuffing to access customer Chick-fil-A One loyalty accounts through the company’s website and mobile app. The automated login activity occurred between June 17 and June 19, with the company later determining that account information may have been accessed after usernames, email addresses, and passwords obtained from third-party sources were used to take over some accounts. The incident was described as account takeover through reused credentials rather than a direct compromise of Chick-fil-A’s internal systems.
Potentially exposed data included names, email addresses, membership numbers, mobile pay numbers, QR codes, stored credit or balance amounts, and the last four digits of payment cards; some accounts may also have exposed birth dates, phone numbers, and physical addresses. Chick-fil-A said it logged out affected users, reset passwords, removed stored payment methods, restored balances, and terminated active sessions during the investigation, while also notifying impacted individuals across multiple jurisdictions, including 2,182 Texas residents.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Chick-fil-A said it detected suspicious login activity in June 2026 while investigating the account takeover activity. The company identified that the attacks involved automated login attempts against customer accounts.
In response to the incident, Chick-fil-A logged out impacted accounts, reset passwords or terminated active sessions, removed stored payment methods, and restored balances where needed. The company also advised affected users to change their passwords.
On July 20, 2026, Chick-fil-A began notifying affected customers about the credential stuffing incident and started filing breach notices with state authorities. This followed the company's investigation into unauthorized access to a limited number of customer accounts.
On July 13, 2026, Chick-fil-A determined that information in affected customer accounts may have been accessed during the credential stuffing attacks. Potentially exposed data included names, email addresses, membership numbers, QR codes, balances, limited payment card details, and for some users birth dates, phone numbers, and addresses.
Automated credential stuffing attacks targeted Chick-fil-A's website and mobile app using email addresses and passwords obtained from third-party sources. The activity occurred between June 17 and June 19, 2026 and led to unauthorized access to some Chick-fil-A One customer accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
9 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourceteiss.co.uk
Open sourcetechrepublic.com
Open sourcesecurityweek.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcebleepingcomputer.com
Open sourcefoxbusiness.com
Open sourcemass.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.