Chick-fil-A disclosed that credential stuffing attacks exposed customer loyalty account data across at least 10 states, including New York, Massachusetts, and Maryland. The fast-food chain confirmed the breach in a notice to affected customers on July 22, 2026.
The attacks exploited reused passwords from other sites. Hackers used automated tools to log into Chick-fil-A One accounts with credentials stolen from unrelated data breaches. Chick-fil-A said the attacks occurred between June 15 and July 10, 2026.
Exposed data includes names, email addresses, phone numbers, and loyalty account details. The company stated that payment card information was not compromised. Chick-fil-A reset passwords for all affected accounts and urged users to create unique credentials.
Signs your account may be compromised include unexpected reward redemptions, changed login details, or login locations you don’t recognize. Check your Chick-fil-A One app history for unusual activity. The company recommends reviewing account settings immediately.
To secure your account: change your password to a strong, unique one. Enable two-factor authentication if available. Remove any unknown devices linked to your account. Update security questions. Never reuse passwords across multiple sites.
Long-term, monitor bank statements and credit reports. Consider placing a free credit freeze with major bureaus. Be wary of phishing emails referencing the breach—attackers often use such events to steal more data.
Chick-fil-A said it notified affected customers and is cooperating with authorities. The company warned customers in 10 states via direct emails and is implementing additional security measures. It did not disclose the exact number of impacted accounts.
Credential stuffing remains a systemic risk. Use a password manager. Enable multi-factor authentication wherever supported. Stay informed via official Chick-fil-A security resources.
💡 Frequently Asked Questions (FAQ)
- Q: What happened in the Chick-fil-A loyalty account breach?
- A: Credential stuffing attacks between June 15 and July 10, 2026, exposed names, emails, phone numbers, and loyalty details for accounts in at least 10 states. Payment card data was not compromised.
- Q: How can I tell if my Chick-fil-A One account was affected?
- A: Signs include unexpected reward redemptions, changed login details, or unfamiliar login locations. Check your account history in the Chick-fil-A One app for unusual activity.
- Q: What steps should I take to secure my Chick-fil-A account?
- A: Change your password to a strong, unique one. Enable two-factor authentication if available. Remove unknown linked devices and update security questions. Never reuse passwords across multiple sites.
Extended Reading
For further details, refer to Chick-fil-A’s official breach notice and reports from BleepingComputer, CBS News, and AZFamily.