Skip to content

davidweaver.codes ↗

Chick-fil-A confirms a new data breach hitting loyalty accounts in a June credential-stuffing attack

Chick-fil-A says attackers used passwords stolen elsewhere to break into some Chick-fil-A One loyalty accounts between June 17 and 19, exposing names, emails, membership numbers and the last four digits of saved cards. It is a new incident, separate from the company's 2023 breach.

Monogram avatar for David Weaver, publisher of DWC News

By David Weaver

Publisher & Editor

Published July 22, 2026, 10:00 AM ET

Case-file graphic on the Chick-fil-A data breach: a June 17 to 19, 2026 credential-stuffing attack on Chick-fil-A One loyalty accounts exposed names, emails and the last four digits of saved cards; confirmed by Chick-fil-A and a Massachusetts breach notice; steps for customers listed.
Case-file graphic on the Chick-fil-A data breach: a June 17 to 19, 2026 credential-stuffing attack on Chick-fil-A One loyalty accounts exposed names, emails and the last four digits of saved cards; confirmed by Chick-fil-A and a Massachusetts breach notice; steps for customers listed.Graphic: DWC News

Chick-fil-A has confirmed a data breach affecting some Chick-fil-A One loyalty accounts, after unauthorized parties used passwords stolen in other companies' breaches to log in through the chain's website and app.

The company began mailing notification letters to affected customers on July 20, 2026. In a statement quoted by Newsweek and Forbes, Chick-fil-A said: "We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted."

To be clear up front: this is a real, confirmed breach, not a rumor or a resurfacing of old news. It is also a new incident — separate from the credential-stuffing breach Chick-fil-A disclosed in 2023 — even though the method of attack is nearly identical.

What happened, in plain terms

Between June 17 and 19, 2026, attackers ran what security researchers call a credential-stuffing attack against Chick-fil-A's website and mobile app. That means they did not "hack in" by breaking Chick-fil-A's defenses. Instead, they took huge lists of usernames and passwords that leaked from other companies' breaches and tried them, automatically and at scale, against Chick-fil-A logins. Wherever a customer had reused the same password, the login worked.

Chick-fil-A has been explicit on this point: it says the passwords were not stolen from its own systems. According to the breach notice filed with Massachusetts, the company determined on July 13 that accounts may have been accessed, and it began notifying customers a week later, per the Commonwealth of Massachusetts breach filing and reporting by BleepingComputer.

What data was exposed

Per the notification and multiple outlets, the information that may have been accessed in an affected account includes:

  • Your name and email address
  • Your Chick-fil-A One membership number and mobile pay number
  • Your account QR code and the amount of Chick-fil-A credit on the account
  • The last four digits of a saved credit or debit card
  • If you saved them to your account: your month and day of birth, phone number, and address

What was not exposed, according to the reporting: full card numbers and CVV security codes. Only the last four digits of a card were involved, so the payment data on its own cannot be used to make a new card. That is genuinely reassuring — but the name, email, birthday, phone and address details are still useful to scammers for targeted phishing, which is why the steps below matter.

How many people, and where

Chick-fil-A has not disclosed a nationwide total. What is on the record comes from breach notices filed with state regulators: at least 2,182 people in Texas and 39 in Massachusetts, with a small number (two) in Vermont. The company sent notices to residents of roughly 10 states plus the District of Columbia — Texas, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont — according to CBS News Atlanta and the Atlanta Journal-Constitution. State totals only capture states with mandatory reporting thresholds, so the true number is almost certainly higher than the figures published so far. We are not going to print a nationwide estimate, because Chick-fil-A has not released one.

Secure Your Chick-fil-A Account

Chick-fil-A data breach: steps to take if you use Chick-fil-A One

A step-by-step guide for Chick-fil-A One customers after the June 2026 credential-stuffing breach: check whether you're affected, reset and de-duplicate your password, review points and the card on file, and protect against phishing and identity theft.

This is general account-security information, not security, legal, or financial advice, and it is not affiliated with or endorsed by Chick-fil-A. Verify all details against Chick-fil-A's official breach notification and the FTC before acting. If you see fraudulent charges, contact your bank or card issuer directly.

0 of 13 done

1. Check whether you're affected
2. Lock down your account now
3. Check your points and the card on file
4. Guard against phishing and identity theft

How this is calculated

The steps mirror Chick-fil-A's own customer guidance and the notification it filed with state regulators, plus standard consumer-protection guidance from the U.S. Federal Trade Commission for credential-stuffing breaches: reset the account password to a unique one, change that password anywhere it was reused, review saved payment methods and rewards, watch for phishing, and — because names, emails and (if stored) birthdays and addresses were exposed — optionally place a fraud alert or credit freeze. No scoring and no model output; these are the official instructions, ordered by urgency.

Data as of July 21, 2026 · verified July 21, 2026 · v1

Assumptions, limitations & sources

Assumptions

  • · Breach details (dates, data elements, affected-state list) are current as of the data date shown; Chick-fil-A's notice and state filings are the authority.
  • · The reader has, or had, a Chick-fil-A One loyalty account accessed via the website or mobile app.

Limitations

  • · This is general account-security information, not legal, financial, or identity-theft advice, and not affiliated with Chick-fil-A.
  • · Chick-fil-A has not disclosed a nationwide total; state figures capture only some states, so not being notified does not guarantee your account was untouched.
  • · Whether Chick-fil-A One offers two-factor authentication may change; verify the current login-security options in the app.
  • · Verify every detail against Chick-fil-A's official notification and the FTC before acting.

Sources

This is what modern SEO looks like: not just an article, but a useful resource people can return to, cite, and share. See how this newsroom is growing · See DavidWeaver's SEO packages

Is this the same as the 2023 Chick-fil-A breach?

No — and this is the most common point of confusion, so it is worth being precise. Chick-fil-A had a separate credential-stuffing breach that ran from December 8, 2022 to February 12, 2023 and affected more than 71,000 accounts, draining rewards balances in some cases and prompting class-action litigation that is still winding through the courts.

The breach announced this week is a different, later event (June 2026) with its own notification letters and its own state filings. What the two share is the technique: both were credential-stuffing attacks that exploited reused passwords rather than a direct hack of Chick-fil-A. A company being hit the same way twice is itself part of the story, and a reason to take your own password hygiene seriously rather than assume the company will catch it every time.

What Chick-fil-A did about it

The company says it responded by signing affected users out of their accounts, removing saved payment methods, restoring any Chick-fil-A One balances that were spent by intruders, and in some cases adding rewards for the inconvenience. It is also prompting affected customers to reset their passwords, per Malwarebytes Labs.

The questions readers are asking

Is my account affected? Chick-fil-A says it is contacting affected customers directly, with letters that started going out July 20, 2026. If you got one, treat your account as affected. If you did not, you are probably not on the notified list — but if you reused your Chick-fil-A password on another site that has ever been breached, you should still change it, because that is exactly the weakness this attack exploited.

Were my card or my points stolen? Only the last four digits of a saved card were involved — not the full number or the CVV — so your card itself is not directly usable from this breach. Rewards are a different matter: intruders did spend some account balances, and Chick-fil-A says it restored those balances. Check that your points and any Chick-fil-A credit look right, and contact support if they do not.

What should I do right now? Reset your Chick-fil-A One password to something strong and unique, change that password anywhere else you reused it (starting with your email and bank), review your saved payment methods, and watch for phishing messages that pretend to be Chick-fil-A. The checklist above walks through each step with official links.

Has Chick-fil-A actually confirmed this? Yes. The company issued a statement, filed breach notices with multiple state regulators, and is mailing individual notification letters. This is confirmed by Chick-fil-A itself and by a government filing, not just by third-party reports.

Should I worry about identity theft? For most people this is a lower-severity breach than one that leaks Social Security numbers or full card details. The realistic near-term risk is targeted phishing using your name and email. If your birthday, phone and address were saved to the account, consider a free fraud alert or credit freeze as a precaution — both are covered in the checklist.

Why it matters and what happens next

Credential stuffing works only because people reuse passwords across sites. The single most effective thing any Chick-fil-A One user can do — today, and for every account — is use a unique password per site, ideally generated and stored by a password manager. That one habit neutralizes this entire class of attack.

The story is still developing. Chick-fil-A has not released a nationwide count, additional state filings may follow, and plaintiffs' law firms have already begun publicizing investigations, as happens after most large breaches. We will update this article as the company or regulators release more.

Sources

More from DWC News