BusinessCybersecurityNewswireTechnology

Chick-fil-A Data Breach Hits Over 13,000 Customers

Originally published on: July 26, 2026
▼ Summary

– Chick-fil-A confirmed that over 13,000 customers had their data stolen in credential stuffing attacks between June 17 and June 19, 2024.
– The attackers used automated tools and credentials obtained from a third-party source to compromise Chick-fil-A One accounts.
– Stolen data included names, email addresses, membership numbers, credit balances, and the last four digits of payment card numbers, with possible access to birth dates, phone numbers, and addresses.
– In response, Chick-fil-A logged out all impacted accounts, removed payment methods, restored account balances, and added rewards as an apology.
– This incident follows a similar credential stuffing attack in 2023 that affected over 71,000 customers.

A significant security incident at Chick-fil-A has exposed the personal data of more than 13,000 customers. The fast food giant confirmed the breach resulted from a wave of credential stuffing attacks targeting its digital platforms.

As reported initially by BleepingComputer, the company disclosed in data breach notifications filed with multiple state attorney general offices that suspicious login activity was detected on certain Chick-fil-A One accounts between June 17 and June 19. The attackers employed automated tools and credentials “obtained from a third-party source” to gain unauthorized access and steal customer information.

“We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted,” the company stated to BleepingComputer.

The compromised data varied by account but included combinations of customer names, email addresses, Chick-fil-A One membership numbers, the amount of Chick-fil-A credit, mobile pay numbers, and the last four digits of credit or debit cards. In some cases, attackers also accessed birth dates, phone numbers, and stored addresses.

A filing shared with BleepingComputer by the Office of the Maine Attorney General on Wednesday revealed that 13,322 individuals were affected in total. Separate notifications to the Texas attorney general’s office indicated 2,182 residents were impacted, while Massachusetts reported 39 affected residents. Chick-fil-A also sent breach letters to customers in the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.

In response, Chick-fil-A immediately logged out all impacted accounts, removed stored payment methods, and restored any lost account balances. The company also added rewards to affected accounts as a goodwill gesture. Because the breaches relied on credentials stolen from other services, Chick-fil-A strongly advised affected customers to change their passwords promptly.

This is not the first such incident for the chain. In March 2023, Chick-fil-A disclosed that hackers had stolen personal information from over 71,000 customers during a similar series of credential stuffing attacks between December 2022 and February 2023. The company operates more than 3,000 restaurants across the U. S., Canada, Puerto Rico, the United Kingdom, and Singapore.

(Source: BleepingComputer)

Topics

credential stuffing attacks 95% data breach notification 92% customer data theft 90% chick-fil-a one accounts 88% security incident response 85% third-party credential compromise 83% automated attack tools 80% affected states reporting 78% customer compensation 75% password change advisory 73%