Chick-fil-A has begun notifying customers that attackers broke into an unknown number of Chick-fil-A One loyalty accounts using recycled passwords, in a credential-stuffing campaign that ran between June 17 and June 19, 2026. The fast-food chain confirmed the intrusion in breach notification letters filed this week with state attorneys general, disclosing the incident publicly on July 22. It is the company’s second credential-stuffing breach in roughly three years.
The attackers did not break Chick-fil-A’s defenses so much as walk through an unlocked door with keys the company never issued. Using automated tools and email-and-password combinations obtained from a third-party source — almost certainly a prior breach elsewhere — they logged into accounts belonging to customers who had reused the same credentials on Chick-fil-A’s site and app. The company was careful to frame this precisely: the incident was “not the result of a direct compromise of Chick-fil-A’s systems or password database.”
What was exposed
For accounts that were successfully accessed, the exposed data depended on what each customer had stored, but could include a substantial profile:
- Names and email addresses
- Phone numbers and physical addresses
- Dates of birth
- Chick-fil-A One membership numbers and mobile pay numbers
- QR codes used for in-store scanning
- Account credit balances and gift card balances
- The last four digits of linked credit or debit cards
No full payment card numbers or account passwords were exposed, according to the company. But the combination that was taken — loyalty credit, mobile-pay identifiers, and scannable QR codes — is exactly what a fraudster needs to drain rewards value or resell working accounts on underground markets.
The numbers Chick-fil-A won’t total
Chick-fil-A has not disclosed a nationwide total of affected customers. What’s public comes from the piecemeal reality of US breach-notification law, which forces disclosure state by state. In its filing with the Texas Attorney General, the company reported 2,182 Texans affected. Its filing under the Massachusetts 2026 Data Breach Notification Report listed just 39 residents.
Notification letters also went to residents of Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island — meaning the true figure is spread across at least eleven jurisdictions and is certainly larger than any single state number suggests. The absence of a headline total is itself telling: companies that face a small, contained incident tend to say so plainly.
Timeline
- June 17–19, 2026 — Automated credential-stuffing attack runs against Chick-fil-A’s website and mobile app.
- July 13, 2026 — Chick-fil-A determines that unauthorized parties may have accessed customer account information.
- July 20–22, 2026 — Breach notifications filed with state attorneys general and sent to affected customers; the incident becomes public.
The roughly four-week gap between the attack and the determination of impact reflects how credential stuffing hides in plain sight: individually, each malicious login looks like a legitimate customer signing in from a new device. It’s only the aggregate pattern — millions of automated attempts, a spike of successes from unusual infrastructure — that gives it away.
How Chick-fil-A responded
To its credit, the company’s remediation was concrete rather than the usual boilerplate. Chick-fil-A said it:
- Logged out all impacted accounts and forced password resets
- Removed stored payment methods from affected accounts
- Restored rewards and account balances that had been drained
- Added bonus rewards as compensation for the disruption
It also urged customers to reset passwords immediately, adopt unique credentials for every site, monitor financial statements, and report any suspicious activity to their banks.
A repeat, not a first
This is the part Chick-fil-A’s carefully worded statement doesn’t dwell on: the company has been here before. Between December 2022 and February 2023, Chick-fil-A suffered a nearly identical credential-stuffing campaign that compromised more than 71,000 customer accounts, exposing similar loyalty and mobile-pay data and triggering class-action litigation.
The recurrence matters. Credential stuffing is not a novel or sophisticated threat — it is one of the most well-understood attack patterns in consumer security, and the standard defenses are equally well understood: mandatory multi-factor authentication, bot-detection and rate-limiting on login endpoints, monitoring for impossible-travel and password-spray patterns, and proactive resets against known-breached credential lists. That a high-profile brand with a prior incident of the same type was hit again by the same technique suggests those controls were either not fully deployed or not tuned aggressively enough at the login layer.
The uncomfortable shared responsibility
Chick-fil-A’s framing — that its systems weren’t breached — is technically accurate and strategically incomplete. Credential stuffing only works because customers reuse passwords, so in one sense the root cause lives outside the company’s walls. But the industry has long since concluded that “our users picked bad passwords” is not a defense. When reused credentials are a known, ubiquitous risk, blocking the attack that exploits them is the platform’s job.
For customers, the practical takeaway is unchanged and unglamorous: use a unique password for Chick-fil-A One, turn on any available multi-factor option, and treat any loyalty or mobile-pay account that touches stored payment data as worth protecting like a bank login — because to a fraudster, that’s exactly what it is.



