Drooid Logo
Back to story perspectives

Full Breakdown

Chick-fil-A Loyalty Program Data Breach Affects Customers in Ten States

7/23/2026, 12:56:07 PM

Core Event: Credential-Stuffing Attack Exposes Loyalty Account Data

Between June 17 and June 19 2026, Chick-fil-A’s website and mobile app were targeted in an automated credential-stuffing attack. Attackers used usernames and passwords obtained from a third-party source—lists derived from prior data breaches—to gain access to a limited number of Chick-fil-A One loyalty accounts. The company discovered suspicious login activity, launched an investigation, and on July 13 2026 concluded that unauthorized parties may have accessed personal information stored in the affected accounts.

Affected Regions and Data Types

Letters were sent to customers in the District of Columbia and nine states—Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont—informing them of the potential exposure. A separate notice from Texas indicated that 2,182 Texas residents were also affected. Data that may have been accessed includes:

  • Names and email addresses
  • Chick-fil-A One membership numbers and mobile-pay numbers
  • The last four digits of stored credit or debit card numbers
  • Chick-fil-A gift-card or credit balances
  • Optional fields such as birth-month/day, phone numbers, and physical addresses

Company Response and Remediation Measures

Chick-fil-A took several immediate actions after confirming the breach:

  • Forced log-outs of all affected accounts and removed any stored payment methods.
  • Reset passwords for the compromised accounts.
  • Restored the loyalty balances that may have been altered.
  • Added additional rewards to the impacted accounts as a goodwill gesture.

The company also urged customers to:

  • Reset their Chick-fil-A passwords and use a unique, strong password not reused elsewhere.
  • Enable multi-factor authentication, which is supported via a verified mobile phone number.
  • Monitor bank and credit-card statements, as well as credit reports, for any suspicious activity.

Conflicting Reports & Gaps

  • Date Discrepancy – Most outlets (Fox Business, CBS News, Fox 5 Atlanta, Malwarebytes) report the attack occurred June 17–19 2026. WTVM’s notice describes the intrusion as happening July 17–19 2026. Both date ranges are cited in official letters, creating an unresolved timeline inconsistency.
  • Scope of Financial Loss – WTOP’s notice suggests some customers had money stolen from their Chick-fil-A One accounts, whereas other sources (CBS News, Fox 5 Atlanta) do not mention actual theft, only potential exposure of payment-card information.
  • Number of Affected Customers – No source disclosed the total count of compromised accounts, leaving the scale of the breach unclear.

Verbatim Quotes

  • “We also restored impacted customers’ Chick-fil-A One account balances.” — Android, Chick-fil-A

*Company spokesperson*: “We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted. We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day.”

The breach underscores the risks of credential reuse across services and highlights the importance of robust detection and mitigation controls for automated attacks. Chick-fil-A’s remediation steps aim to protect affected customers while the company continues to enhance its security monitoring and fraud-prevention measures.