Chick-fil-A Security Incident Exposes Customer Account Data
Chick-fil-A has disclosed a security incident that may have exposed personal information from a limited number of Chick-fil-A One customer loyalty accounts following a credential stuffing attack in June 2026. The fast-food chain confirmed that unauthorized parties gained access to accounts between June 17 and June 19, using stolen username and password combinations obtained from third-party data breaches rather than compromising Chick-fil-A’s own systems.
According to Fox Business, the company detected suspicious login activity, launched an investigation, and concluded on July 13 that customer data had been accessed. Affected customers received breach notification letters dated July 20, and the company made a public disclosure on July 22.
What Information Was Exposed
The data accessible to attackers varied depending on what each customer had stored in their Chick-fil-A One profile. Potentially exposed information includes full names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, account QR codes, stored credit balances, and the last four digits of linked credit or debit cards, as USA TODAY reported.
For customers who had filled in optional profile fields, additional information was accessible, including month and day of birth, phone numbers, and mailing addresses. Chick-fil-A confirmed that its own password database was not compromised and that full credit or debit card numbers were not exposed.
A Recurring Vulnerability
This marks the second major credential stuffing attack on Chick-fil-A’s loyalty program. Between December 2022 and February 2023, a nearly identical attack compromised 71,473 customer accounts, leading to a class action lawsuit — Stephens et al. v. Chick-fil-A Inc. — which alleged the company committed an “utter failure to implement basic cybersecurity policies.” A settlement was reached in October 2023, though financial terms were not publicly disclosed.
Credential stuffing is a type of cyberattack where automated bots use large lists of stolen username and password combinations — obtained from prior breaches at other companies — to attempt logins across different platforms. According to cybersecurity researchers, roughly 0.1% of credential pairs tested in a typical campaign result in successful logins, meaning a million stolen credentials can yield up to 1,000 compromised accounts.
The MFA Question
Chick-fil-A offers multi-factor authentication for Chick-fil-A One accounts through a verified mobile phone number, but it does not require MFA enrollment. This is the same vulnerability that enabled the 2023 breach. The Cybersecurity and Infrastructure Security Agency has stated that enabling MFA makes an account approximately 99% less likely to be compromised in an account-takeover attack.
TechTimes reported that the recurrence of the same attack vector raises significant questions about the company’s cybersecurity posture. Industry precedent is unfavorable: Dunkin’ Brands paid $650,000 to New York’s attorney general in 2020 for credential stuffing attacks on its loyalty accounts, and a 42-state coalition extracted $18 million from 23andMe’s bankrupt estate in July 2026 for a nearly identical failure.
Affected States and Scope
Chick-fil-A has disclosed that affected customers are located in at least 11 states plus Washington, D.C.: Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont, and Texas. The company reported 2,182 affected customers to the Texas Attorney General and 39 to Massachusetts authorities, but has not disclosed a total national count of compromised accounts.
Company Response
Upon discovering the attack, Chick-fil-A forced affected accounts to log out of all active sessions, removed stored payment methods from compromised profiles, restored impacted account balances, and added bonus rewards as a goodwill measure. The company reset passwords for affected customers and advised all users to create strong, unique passwords.
“We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts,” a company spokesperson told Fox Business. “Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted.”
What Customers Should Do
Chick-fil-A is advising all Chick-fil-A One users — not only those who received notification letters — to change their passwords immediately and enable multi-factor authentication through a verified phone number. Customers should also monitor their financial accounts for suspicious activity and avoid reusing passwords across multiple services.
Law firms including Cole & Van Note have begun investigating the 2026 breach for potential new class-action claims, suggesting that Chick-fil-A may face renewed legal scrutiny over its failure to mandate MFA despite being on notice after the 2023 incident.
Looking Ahead
The company has stated it continues to enhance its “security, monitoring and fraud controls” but has not specified whether mandatory MFA enrollment is among those enhancements. With cybersecurity researchers discovering a 24-billion-record credential database on an unsecured server in June 2026 — the same month this attack occurred — the broader threat landscape for credential stuffing attacks continues to expand, making proactive security measures increasingly critical for companies holding customer data.