"Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third‑party source," Chick‑fil‑A said in notification letters.
The company is notifying customers after a wave of credential stuffing attacks allowed unknown actors to access Chick‑fil‑A One accounts. The restaurant chain — self‑described as the third‑largest quick‑service restaurant company in the United States and operating more than 3,000 restaurants worldwide — identified suspicious login activity tied to its website and mobile app in June and concluded on July 13, 2026 that some accounts may have been accessed.
The attack timeline: June 17–19 activity, July 13 determination
Chick‑fil‑A’s investigation found the automated attacks occurred between June 17 and June 19, 2026. The company says it used account credentials "obtained from a third‑party source" to carry out the campaign against both the website and mobile application. Chick‑fil‑A determined on July 13, 2026 that the unauthorized parties may have accessed information in affected Chick‑fil‑A One accounts.
What information was exposed from Chick‑fil‑A One accounts
According to breach notification letters and filings with multiple Attorney General offices, the breach exposed a combination of customer data stored in Chick‑fil‑A One accounts. The information that may have been accessed includes:
- Names and email addresses;
- Chick‑fil‑A One membership numbers and mobile pay numbers;
- QR codes associated with accounts and the amount of Chick‑fil‑A credit;
- The last four digits of credit or debit card numbers;
- Additionally, birth dates, phone numbers, and addresses may have been accessed if they were stored in the compromised accounts.
Credential stuffing: method and end goals
The company described the incident as a credential stuffing campaign. The source material explains credential stuffing as an automated use of stolen username/password pairs to breach user accounts — a technique that succeeds particularly when people reuse credentials across multiple services. The stated end goals are account takeover followed by theft of personal and financial information, which can then be sold to other cybercriminals or used for identity theft and other malicious purposes.
State notifications and scale: 2,182 Texans and other jurisdictions
Chick‑fil‑A did not disclose a total number of impacted customer accounts in the public filings cited, but told the Texas Attorney General that 2,182 Texans were affected. The company also sent breach notification letters to residents of Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island. The company previously disclosed a similar credential stuffing incident in March 2023 in which threat actors accessed personal information and used stored rewards balances of over 71,000 customers after account takeovers between December 2022 and February 2023.
Chick‑fil‑A’s remediation steps and customer guidance
In response to the June attacks, Chick‑fil‑A logged out all impacted accounts, removed payment methods from those accounts, restored Chick‑fil‑A One account balances, and added rewards to affected accounts as an apology. Because the company says the intrusions used stolen credentials, it advised impacted users to change their passwords as soon as possible. When contacted by BleepingComputer, a Chick‑fil‑A spokesperson was not immediately available for comment about the number of breached accounts.
What this means for security teams, customers, and malicious actors
- Security teams and technologists: Automated login activity and credential‑based attacks are front‑of‑mind in this incident. The source material notes a Picus whitepaper stat that security teams log 54% of successful attacks and alert on just 14%, and that breach‑and‑attack simulation can be used to test SIEM and EDR rules so threats stop slipping by detection.
- End users and customers: The company’s remediation emphasizes immediate password changes and monitoring of account payment methods and stored personal data; users with credentials reused on other sites should assume elevated risk where those credentials may be known to attackers.
- Adversaries and data buyers: The stated outcome for attackers is account takeover for immediate use of rewards and stored balances or for subsequent sale of harvested personal and financial information to other cybercriminals.
This episode leaves two concrete takeaways in the record: Chick‑fil‑A has acknowledged repeated exposure to credential stuffing campaigns — a June 2026 event now tied to thousands of Texans and a prior, larger incident disclosed in March 2023 — and the company has taken immediate account‑level mitigations while declining to state a total affected‑customer count publicly. Whether that count will be disclosed and whether similar campaigns will recur remain open questions anchored to facts in the company’s notifications.
Original reporting: BleepingComputer — Chick‑fil‑A discloses data breach after credential stuffing attacks



