Chick-fil-A Hit by Credential Stuffing Attack, Exposing Customer Data
Chick-fil-A, the third-largest U.S. quick-service restaurant chain, has notified an undisclosed number of customers about a data breach stemming from a credential stuffing attack. The incident targeted the company’s website and mobile app between June 17 and 19, 2026, with unauthorized parties using stolen login credentials from third-party sources to access accounts.
The breach exposed a range of customer data, including names, email addresses, Chick-fil-A One membership numbers, mobile pay details, QR codes, account credit balances, and the last four digits of payment cards. Some accounts also contained birth dates, phone numbers, and addresses, which may have been accessed.
Chick-fil-A detected the attack after identifying suspicious login activity and confirmed on July 13, 2026, that unauthorized access had occurred. While the total number of affected customers remains undisclosed, the company reported that 2,182 Texas residents were impacted, with additional notifications sent to individuals in Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
In response, Chick-fil-A logged out all compromised accounts, removed stored payment methods, restored account balances, and issued rewards as compensation. The company also advised affected users to change their passwords, as the attack leveraged previously leaked credentials.
This is not the first such incident for Chick-fil-A in March 2023, the chain confirmed a similar credential stuffing attack between December 2022 and February 2023, which compromised over 71,000 customer accounts and drained stored rewards balances.
Chick-fil-A Corporate Support Center cybersecurity rating report: https://www.rankiteo.com/company/chick-fil-a-corporate
"id": "CHI1784708820",
"linkid": "chick-fil-a-corporate",
"type": "Breach",
"date": "6/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Undisclosed (2,182 Texas '
'residents confirmed; additional '
'in Iowa, District of Columbia, '
'Maryland, Massachusetts, New '
'Mexico, New York, North '
'Carolina, Oregon, Vermont, '
'Rhode Island)',
'industry': 'Food & Beverage',
'location': 'United States',
'name': 'Chick-fil-A',
'size': 'Third-largest U.S. quick-service restaurant '
'chain',
'type': 'Quick-service restaurant chain'}],
'attack_vector': 'Stolen login credentials from third-party sources',
'customer_advisories': 'Advised to change passwords and monitor accounts for '
'suspicious activity.',
'data_breach': {'number_of_records_exposed': 'Undisclosed (2,182 Texas '
'residents confirmed)',
'personally_identifiable_information': 'Names, email '
'addresses, birth '
'dates, phone numbers, '
'addresses, '
'Chick-fil-A One '
'membership numbers',
'sensitivity_of_data': 'High (PII, partial payment data, '
'account balances)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Payment information (partial)',
'Account credentials']},
'date_detected': '2026-07-13',
'description': 'Chick-fil-A notified an undisclosed number of customers about '
'a data breach stemming from a credential stuffing attack '
'targeting the company’s website and mobile app between June '
'17 and 19, 2026. Unauthorized parties used stolen login '
'credentials from third-party sources to access accounts, '
'exposing customer data.',
'impact': {'brand_reputation_impact': 'Potential negative impact due to '
'repeated incidents',
'data_compromised': 'Names, email addresses, Chick-fil-A One '
'membership numbers, mobile pay details, QR '
'codes, account credit balances, last four '
'digits of payment cards, birth dates, phone '
'numbers, addresses',
'identity_theft_risk': 'High (exposure of PII)',
'operational_impact': 'Account access disruption, removal of '
'stored payment methods, restoration of '
'account balances',
'payment_information_risk': 'Moderate (last four digits of payment '
'cards exposed)',
'systems_affected': 'Website and mobile app'},
'initial_access_broker': {'entry_point': 'Compromised third-party '
'credentials'},
'investigation_status': 'Completed (initial detection and response)',
'lessons_learned': 'Credential stuffing attacks remain a persistent threat '
'due to password reuse; enhanced monitoring and customer '
'education are critical.',
'post_incident_analysis': {'corrective_actions': 'Logged out compromised '
'accounts, removed stored '
'payment methods, restored '
'balances, issued rewards, '
'and advised password '
'changes',
'root_causes': 'Reuse of compromised credentials '
'from third-party breaches; lack of '
'MFA enforcement'},
'recommendations': 'Implement multi-factor authentication (MFA), enforce '
'password complexity requirements, monitor for suspicious '
'login activity, and educate customers on password '
'hygiene.',
'references': [{'source': 'Cyber Incident Description'}],
'regulatory_compliance': {'regulatory_notifications': 'Notifications sent to '
'affected individuals '
'in multiple states '
'(Texas, Iowa, etc.)'},
'response': {'communication_strategy': 'Customer notifications sent to '
'affected individuals',
'containment_measures': 'Logged out all compromised accounts, '
'removed stored payment methods',
'enhanced_monitoring': 'Identified suspicious login activity',
'incident_response_plan_activated': 'Yes',
'recovery_measures': 'Advised affected users to change passwords',
'remediation_measures': 'Restored account balances, issued '
'rewards as compensation'},
'title': 'Chick-fil-A Hit by Credential Stuffing Attack, Exposing Customer '
'Data',
'type': 'Credential Stuffing',
'vulnerability_exploited': 'Reuse of compromised credentials'}