Skip to main content
Emerging ThreatsData Breaches

Chick-fil-A Breach Exposes 13,000 Customers' Data

Chick-fil-A restaurant interior with a tablet login screen in the foreground.

13,322 Chick‑fil‑A customers had their accounts accessed in a credential stuffing campaign that targeted the chain’s website and mobile app over a three‑day span in June, the company disclosed in state filings.

Credential stuffing attacks, June 17–19

Chick‑fil‑A detected the activity between June 17 and June 19 after identifying "suspicious login activity to certain Chick‑fil‑A One accounts," the company told BleepingComputer. The company said the attackers operated automated tools and used credentials "obtained from a third‑party source" to log into affected accounts.

Customer data accessed (what was exposed)

During the incident, threat actors accessed combinations of customer data tied to Chick‑fil‑A One accounts. The company says attackers stole names, email addresses, Chick‑fil‑A One membership numbers, account credit balances, mobile pay numbers, and the last four digits of credit or debit cards. Accounts that stored additional personal details may also have exposed birth dates, phone numbers, and addresses.

Chick‑fil‑A's response and remediation steps

Chick‑fil‑A told BleepingComputer it took immediate steps to secure and restore impacted accounts. The company logged out all impacted accounts, removed payment methods, and restored affected Chick‑fil‑A One account balances. It also added rewards to impacted accounts and advised customers whose credentials were compromised to change their passwords as soon as possible.

In a statement to BleepingComputer, Chick‑fil‑A said: "We recently identified a security incident that may have affected a limited number of Chick‑fil‑A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted."

State notifications and scope: Maine, Texas, Massachusetts, and others

Although the company did not initially publish a single nationwide tally, a filing shared by the Office of the Maine Attorney General with BleepingComputer lists the total number affected as 13,322. In separate state filings, Chick‑fil‑A told the Texas attorney general’s office that the breach impacts 2,182 Texans and informed the Massachusetts attorney general that 39 state residents were affected. Chick‑fil‑A has also sent data breach notification letters to residents of the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.

What this means for Chick‑fil‑A customers and security teams

  • Customers: Those notified should expect that account‑linked details such as membership numbers, balances, mobile pay numbers and partial card details could have been exposed, and Chick‑fil‑A has advised impacted customers to change their passwords.
  • Security teams at Chick‑fil‑A: The company has taken account‑level actions—logging out accounts, removing payment methods, restoring balances, and adding rewards—and is communicating directly with impacted customers per its filings.
  • Regulators and state offices: Multiple state attorney general offices received filings and notification letters that enumerate affected residents and the company’s remediation steps.

Chick‑fil‑A also disclosed a prior, related incident in March 2023: hackers had stolen personal information for over 71,000 customers after a series of credential stuffing attacks between December 2022 and February 2023. The June 2026 disclosure brings the company back before state regulators and affected customers with a smaller, but still consequential, tally of compromised accounts.

The record in the filings is concrete about what was accessed and the immediate, account‑level fixes Chick‑fil‑A implemented. The disclosure leaves open how the credentials obtained from a third‑party source were originally exposed and what additional long‑term measures Chick‑fil‑A will take beyond restoring balances and advising password changes. For now, the company’s notifications and account resets are the steps customers and state offices will use to assess impact and next actions.

Source: BleepingComputer — Chick‑fil‑A data breach affects more than 13,000 customers