AI & TechBusinessCybersecurityNewswireTechnology

Chick-fil-A Data Breach Revealed After Credential Stuffing Attacks

▼ Summary

– Chick-fil-A notified customers of a data breach after credential stuffing attacks on its website and mobile app from June 17–19, 2026, using credentials from a third-party source.
– Exposed data includes names, email addresses, membership numbers, QR codes, credit balances, last four digits of payment cards, and possibly birth dates, phone numbers, and addresses.
– The company reported 2,182 affected customers in Texas and 39 in Massachusetts, with notifications also sent to several other states.
– In response, Chick-fil-A logged out affected accounts, removed payment methods, restored balances, and added rewards, advising password changes.
– This follows a similar 2023 incident where over 71,000 customer accounts were breached through credential stuffing.

Chick-fil-A has begun notifying customers about a data breach that resulted from a series of credential stuffing attacks targeting its online platforms. The fast-food giant, which operates more than 3,000 locations across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore, confirmed the incident after detecting suspicious login activity on certain Chick-fil-A One accounts.

According to data breach notification letters sent to affected individuals and filed with multiple state Attorney General offices, the company identified the attacks after noticing unusual login patterns. An investigation revealed that unauthorized parties launched an automated assault on Chick-fil-A’s website and mobile app between June 17 and June 19, 2026. The attackers used account credentials,specifically email addresses and passwords,that were obtained from a third-party source.

“Based on our investigation, we determined on July 13, 2026 that the unauthorized parties may have accessed information in your Chick-fil-A One account,” the company stated in its notification.

The compromised data includes a mix of personal and account-specific details: customers’ names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, the amount of Chick-fil-A credit, and the last four digits of credit or debit card numbers. In some cases, attackers may have also accessed birth dates, phone numbers, and addresses if those were stored in the affected accounts.

Chick-fil-A has not disclosed the total number of customers impacted, but state filings provide a partial picture. The company reported to the Texas Attorney General that 2,182 Texans were affected, while Massachusetts officials were told that 39 residents faced exposure. Notification letters were also sent to customers in Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.

In credential stuffing attacks, cybercriminals use automated tools to test stolen username and password combinations across multiple websites. This method proves especially effective when people reuse login credentials across different services. The ultimate goal is to hijack accounts to steal financial and personal data, which can then be sold on dark web markets or used for identity theft.

In response, Chick-fil-A logged out all impacted accounts, removed stored payment methods, restored Chick-fil-A One account balances, and added rewards as a goodwill gesture. The company also urged affected users to change their passwords immediately, emphasizing that the breach stemmed from stolen credentials rather than a compromise of its own systems.

A Chick-fil-A spokesperson was not immediately available for comment when contacted by BleepingComputer on Tuesday regarding the total number of breached accounts.

This is not the first time Chick-fil-A has faced such an attack. In March 2023, the company confirmed that threat actors accessed the personal information and depleted the rewards balances of over 71,000 customers following a similar wave of credential stuffing attacks between December 2022 and February 2023.

(Source: BleepingComputer)

Topics

data breach 95% credential stuffing 92% customer account security 88% personal information exposure 85% incident response 82% notification letters 78% attack timeline 75% company response 72% cyberattack methods 70% financial information theft 68%