Overview
- Chick‑fil‑A reported that unauthorized actors used credential‑stuffing tools to access Chick‑fil‑A One accounts between June 17 and June 19, 2026.
- The company warned that attackers may have viewed names, email addresses, Chick‑fil‑A One membership and mobile pay numbers, QR codes, Chick‑fil‑A credit balances and the last four digits of payment cards, with stored birthdates, phone numbers and addresses possibly exposed.
- As of its July investigation the chain logged out impacted accounts, reset passwords, removed stored payment methods, restored account balances, added rewards and sent breach notices to customers and multiple state attorney general offices.
- Chick‑fil‑A told the Texas attorney general the incident affects 2,182 Texas residents but it has not disclosed the total number of impacted accounts and a company spokesperson was not available for comment.
- The attack repeats a pattern seen in late 2022–early 2023 that hit roughly 71,000 customers and raises risks of fraud and phishing if account data or credentials are sold, so customers should change reused passwords and enable multi‑factor authentication.