Chick-fil-A Data Breach Impacts Customers Across States
Chick-fil-A disclosed a June 2026 credential-stuffing attack against its website and mobile app, with unauthorized access detected after attackers used login credentials from third-party data breaches. Internal findings show the incident occurred June 17–19, 2026, and an investigation confirmed on July 13, 2026 that some customer accounts were compromised, including Chick-fil-A One accounts. The breach exposed information such as customer names, email addresses, membership numbers, mobile pay numbers, and in some cases the last four digits of card numbers, with additional data like birth dates, phone numbers, and addresses potentially exposed where stored. Texas authorities report at least 2,182 residents affected in that state, and notifications were also sent to residents in Iowa and other jurisdictions; nationwide impact remains unclear. This incident follows a previous widespread credential-stuffing attack on Chick-fil-A from late 2022 to early 2023, underscoring a pattern of password reuse and credential abuse. In its communications, Chick-fil-A emphasized that the breach stemmed from stolen credentials reused across services rather than a flaw in its own systems, highlighting the persistent risk of automated account takeovers via credential stuffing.

