Full Breakdown
Chick-fil-A Data Breach Overview
7/22/2026, 8:37:46 PM
Core Event
In late June 2026, Chick-fil-A’s website and mobile app were hit by a credential-stuffing attack. Attackers used usernames and passwords from a third-party source to log into a limited number of Chick-fil-A One loyalty accounts. The company’s investigation concluded on July 13 2026 that attackers may have accessed personal information stored in the affected accounts. Notification letters were sent to customers on July 20 2026.
Background & Context
Credential-stuffing attacks reuse stolen login credentials across services. The National Security Agency notes such attacks succeed when users recycle passwords, giving attackers access to accounts that store payment data and rewards. Security experts say fast-food and retail apps are attractive targets because they often hold stored payment information and loyalty balances.
Timeline
- June 17-19 2026: Attackers attempted logins using compromised credentials.
- July 13 2026: Chick-fil-A determined that attackers may have accessed data in the compromised accounts.
- July 20 2026: The company mailed breach notification letters to customers in ten states and the District of Columbia and filed similar notices with state attorneys general.
Data & Statistics
- States notified: District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont.
- Potentially exposed data: customer name, email address, Chick-fil-A One membership number, Mobile Pay number, QR code, last four digits of linked cards, gift-card balances, and, if stored, birth month and day, phone number, and mailing address.
- State-specific impact: filings indicate 2,182 Texas residents, 39 Massachusetts residents, and two Vermont residents were affected. The total number of affected customers nationwide has not been disclosed.
Official Statements & Responses
Chick-fil-A said the breach affected “a limited number” of loyalty accounts. The company forced logouts of the compromised accounts, removed stored payment methods, and reset passwords. It restored account balances and added additional rewards as a goodwill gesture, emphasizing that the incident resulted from credential reuse rather than a direct compromise of its own systems.
Conflicting Reports & Gaps
- Attack dates: Most sources identify the attack window as June 17-19 2026, while a few cite July 17-19 2026, creating uncertainty about the precise timing.
- Number of affected accounts: The company has not released a nationwide total; state filings provide specific counts for Texas, Massachusetts, and Vermont, but the overall scope remains unknown.
- Scope of data exposure: Notification letters list a set of data elements, but some sources mention additional details such as home addresses and phone numbers, indicating possible variation in what individual users stored.
Why It Matters
The breach highlights the risk of credential-stuffing attacks on consumer-facing apps that store payment information and underscores the importance of unique passwords and multifactor authentication, as recommended by federal agencies. For a chain with over 3,000 locations, the incident could affect consumer trust in digital loyalty programs and prompt industry reviews of authentication practices.
What’s Next
Chick-fil-A has indicated ongoing enhancements to its security infrastructure but has not announced specific future actions beyond the immediate remediation steps. Customers are advised to follow the company’s guidance on password updates and remain vigilant for signs of identity theft.
