Chick-fil-A Loyalty Program Hit by Cyberattack, Customer Data Exposed
Chick-fil-A has disclosed a data breach affecting some users of its Chick-fil-A One loyalty program. The fast-food chain revealed that hackers accessed accounts last month using email addresses and passwords obtained from a third-party source, likely through credential-stuffing attacks.
Exposed data may include:
- Names and email addresses
- Membership numbers
- The last four digits of some stored payment cards
- Gift card balances
In response, Chick-fil-A logged out affected users, removed stored payment methods, and advised customers to reset passwords and use unique credentials for their accounts. The incident highlights the risks of reused passwords and third-party data leaks in targeted cyberattacks.
The breach was reported in early June 2025, with no indication of how many accounts were compromised. Chick-fil-A has not disclosed further details on the third-party source or the attackers’ motives.
Source: https://www.waka.com/2026/07/22/chick-fil-a-warns-of-data-breach-on-some-accounts/
Chick-fil-A Corporate Support Center cybersecurity rating report: https://www.rankiteo.com/company/chick-fil-a-corporate
"id": "CHI1784738131",
"linkid": "chick-fil-a-corporate",
"type": "Breach",
"date": "6/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Fast Food/Restaurant',
'location': 'United States',
'name': 'Chick-fil-A',
'type': 'Corporation'}],
'attack_vector': 'Credential Stuffing',
'customer_advisories': 'Reset passwords, use unique credentials, and remove '
'stored payment methods.',
'data_breach': {'personally_identifiable_information': 'Names, Email '
'addresses, Membership '
'numbers, Partial '
'payment card details',
'sensitivity_of_data': 'Moderate',
'type_of_data_compromised': ['Names',
'Email addresses',
'Membership numbers',
'Last four digits of payment '
'cards',
'Gift card balances']},
'date_publicly_disclosed': '2025-06',
'description': 'Chick-fil-A has disclosed a data breach affecting some users '
'of its Chick-fil-A One loyalty program. The fast-food chain '
'revealed that hackers accessed accounts last month using '
'email addresses and passwords obtained from a third-party '
'source, likely through credential-stuffing attacks. Exposed '
'data may include names, email addresses, membership numbers, '
'the last four digits of some stored payment cards, and gift '
'card balances.',
'impact': {'data_compromised': 'Names, email addresses, membership numbers, '
'last four digits of stored payment cards, '
'gift card balances',
'identity_theft_risk': 'High',
'payment_information_risk': 'Moderate',
'systems_affected': 'Chick-fil-A One loyalty program'},
'initial_access_broker': {'entry_point': 'Third-party data leak (email '
'addresses and passwords)'},
'lessons_learned': 'Highlights the risks of reused passwords and third-party '
'data leaks in targeted cyberattacks.',
'post_incident_analysis': {'corrective_actions': 'Logged out affected users, '
'removed stored payment '
'methods, advised password '
'resets.',
'root_causes': 'Credential stuffing using reused '
'passwords from third-party data '
'leaks'},
'recommendations': 'Use unique credentials for accounts, enable multi-factor '
'authentication, and monitor for suspicious activity.',
'references': [{'source': 'Cyber Incident Description'}],
'response': {'communication_strategy': 'Public disclosure and customer '
'advisories',
'containment_measures': 'Logged out affected users, removed '
'stored payment methods',
'remediation_measures': 'Advised customers to reset passwords '
'and use unique credentials'},
'title': 'Chick-fil-A Loyalty Program Hit by Cyberattack, Customer Data '
'Exposed',
'type': 'Data Breach',
'vulnerability_exploited': 'Reused passwords from third-party data leaks'}