Story perspectives
Chick-fil-A Alerts Credential-Stuffing Breach, Resets Loyalty Accounts
7/23/2026
1 of 2
Story summary
- Chick-fil-A warned customers in 10 states and Washington, D.C. that a credential-stuffing attack using third-party usernames and passwords from June 17-19, 2026 may have accessed data in loyalty accounts.
- On July 13, 2026 the company forced accounts to log out, removed stored payment methods and reset passwords.
- Chick-fil-A sent letters on July 20, 2026, added rewards, urged strong unique passwords and said it is enhancing security.
1 / 2
