Chick-fil-A: Chick-fil-A says some customers’ information exposed in data breach

Chick-fil-A: Chick-fil-A says some customers’ information exposed in data breach

Chick-fil-A Data Breach Exposes Customer Loyalty Account Information

Chick-fil-A has notified customers of a data breach affecting its Chick-fil-A One loyalty program after detecting suspicious login activity. The company sent letters to impacted individuals on July 20, 2026, revealing that unauthorized parties accessed accounts between July 17 and July 19 using credentials obtained from a third party.

The breach exposed customers’ names, email addresses, membership numbers, and the last four digits of saved payment cards. Additional stored details, such as birthdays and addresses, may have also been compromised. Chick-fil-A stated that only a limited number of accounts were affected and that it took immediate action to secure them, including forced logouts, removal of saved payment methods, and restoration of account balances.

In response, the company has urged affected customers to reset their passwords and monitor financial statements for unusual activity. No evidence suggests broader system vulnerabilities, but the incident highlights the risks of credential-based attacks on loyalty programs.

Source: https://www.wsfa.com/2026/07/22/chick-fil-a-says-some-customers-information-exposed-data-breach/

Chick-fil-A Corporate Support Center cybersecurity rating report: https://www.rankiteo.com/company/chick-fil-a-corporate

"id": "CHI1784737860",
"linkid": "chick-fil-a-corporate",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Limited number of accounts',
                        'industry': 'Fast Food/Restaurant',
                        'location': 'United States',
                        'name': 'Chick-fil-A',
                        'type': 'Corporation'}],
 'attack_vector': 'Credential Stuffing',
 'customer_advisories': 'Reset passwords, monitor financial statements for '
                        'unusual activity',
 'data_breach': {'personally_identifiable_information': 'Names, email '
                                                        'addresses, birthdays, '
                                                        'addresses, membership '
                                                        'numbers',
                 'sensitivity_of_data': 'Moderate to High',
                 'type_of_data_compromised': 'Customer loyalty account '
                                             'information, payment card '
                                             'details (last four digits), '
                                             'personally identifiable '
                                             'information'},
 'date_detected': '2026-07-17',
 'date_publicly_disclosed': '2026-07-20',
 'description': 'Chick-fil-A has notified customers of a data breach affecting '
                'its Chick-fil-A One loyalty program after detecting '
                'suspicious login activity. Unauthorized parties accessed '
                'accounts using credentials obtained from a third party, '
                'exposing customer names, email addresses, membership numbers, '
                'and the last four digits of saved payment cards, along with '
                'potential birthdays and addresses.',
 'impact': {'data_compromised': 'Names, email addresses, membership numbers, '
                                'last four digits of saved payment cards, '
                                'birthdays, addresses',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'Moderate',
            'systems_affected': 'Chick-fil-A One loyalty program'},
 'initial_access_broker': {'entry_point': 'Third-party credentials'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Risks of credential-based attacks on loyalty programs, '
                    'importance of monitoring for suspicious login activity',
 'post_incident_analysis': {'corrective_actions': 'Forced logouts, removal of '
                                                  'saved payment methods, '
                                                  'account balance '
                                                  'restoration, password '
                                                  'resets',
                            'root_causes': 'Use of third-party credentials for '
                                           'unauthorized access'},
 'recommendations': 'Customers should reset passwords, monitor financial '
                    'statements for unusual activity, and enable multi-factor '
                    'authentication where possible',
 'references': [{'source': 'Chick-fil-A Customer Notification'}],
 'response': {'communication_strategy': 'Customer notifications via letter',
              'containment_measures': 'Forced logouts, removal of saved '
                                      'payment methods, account balance '
                                      'restoration',
              'incident_response_plan_activated': 'Yes',
              'remediation_measures': 'Password resets, monitoring for unusual '
                                      'activity'},
 'title': 'Chick-fil-A Data Breach Exposes Customer Loyalty Account '
          'Information',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Third-party credentials'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.