● Data Breaches

Chick-fil-A Suffers Credential Stuffing Attack Compromising Over 13,000 Customer Accounts

July 24, 2026 · snewle
Chick-fil-A Suffers Credential Stuffing Attack Compromising Over 13,000 Customer Accounts

American fast food restaurant chain Chick-fil-A has disclosed a security incident affecting more than 13,000 customers following credential stuffing attacks that targeted its website and mobile application. The Chick-fil-A data breach occurred between June 17 and June 19, when attackers used automated tools and credentials obtained from third-party sources to compromise customer accounts.

What Information Was Exposed in the Attack?

The company detected suspicious login activity targeting Chick-fil-A One loyalty accounts during the three-day attack window. Threat actors successfully accessed a combination of customer information, including names, email addresses, Chick-fil-A One membership numbers, stored credit amounts, mobile pay numbers, and the last four digits of credit or debit card numbers. For some affected customers, additional data such as birth dates, phone numbers, and physical addresses may have been compromised if this information was stored in their accounts.

According to a filing shared by the Office of the Maine Attorney General, the incident impacted 13,322 individuals in total. Separate state-level notifications revealed that 2,182 Texas residents and 39 Massachusetts residents were among those affected. The company also sent breach notification letters to residents in the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.

How Did Chick-fil-A Respond to the Breach?

Upon discovering the security incident, Chick-fil-A took immediate action to secure compromised accounts. The company logged out all impacted accounts and removed stored payment methods as a precautionary measure. All affected Chick-fil-A One account balances were restored to their proper amounts, and the company added rewards to compromised accounts as an apology to affected customers.

The company emphasized that the accounts were breached because customers had reused credentials that were previously stolen from third-party services. Chick-fil-A strongly advised all impacted customers to change their passwords immediately to prevent future unauthorized access.

Is This the First Time Chick-fil-A Has Been Targeted?

This marks the second credential stuffing incident for the fast food chain in recent years. In March 2023, Chick-fil-A disclosed that hackers had stolen personal information from over 71,000 customers in another series of credential stuffing attacks that occurred between December 2022 and February 2023.

Chick-fil-A operates a network of over 3,000 restaurants across the United States, Canada, Puerto Rico, the United Kingdom, and Singapore, making it one of the largest fast food companies in the United States. The company stated it is communicating directly with all customers who may have been impacted by the recent security incident.

Source: BleepingComputer