Technology

Chick-fil-A Discloses Data Breach After Credential Stuffing Attacks

Chick-fil-A is notifying customers of a data breach after credential stuffing attacks in June exposed names, email addresses, and payment details.

Chick-fil-A is notifying customers of a data breach caused by credential stuffing attacks in June 2026 that exposed names, email addresses, and last four digits of payment cards for over 71,000 accounts. The company has reset passwords and removed payment methods for impacted accounts, offering identity protection services.

American fast food restaurant chain Chick-fil-A is notifying an undisclosed number of customers about a data breach resulting from a wave of credential stuffing attacks. The company detected suspicious login activity to certain Chick-fil-A One accounts between June 17 and June 19, 2026, and determined on July 13 that attackers may have accessed account information.

According to data breach notification letters filed with various Attorney General offices, the information exposed includes a combination of customers' names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, and the last four digits of credit/debit card numbers. Additionally, attackers may have also accessed birth dates, phone numbers, and addresses if stored in the compromised accounts.

Chick-fil-A has not disclosed the total number of customers affected, but told the Texas Attorney General that the breach impacted 71,044 individuals. This mirrors a similar incident in March 2023, where attackers accessed the accounts of over 71,000 customers.

Response and Mitigation

In credential stuffing attacks, attackers use automated tools to breach accounts with stolen username/password pairs, a tactic that is especially effective when users reuse credentials across multiple platforms. In response to the incident, Chick-fil-A logged out all impacted accounts, removed payment methods, and restored account balances. The company has advised all users to change their passwords as a precaution.

"Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application using account credentials obtained from a third-party source," the company stated. Chick-fil-A is offering identity protection services to affected individuals. The company has not yet responded to requests for comment regarding the full scope of the breach.