Last Update: 08/01/2026 at 12:00 PM EST

Chick-fil-A Discloses Credential-Stuffing Account Breach

Coverage from Charlotte Observer, The News & Observer, and others

Articles

6

Days Since Update

2

The Story

Chick-fil-A Discloses Credential-Stuffing Account Breach image

Chick-fil-A disclosed that automated credential-stuffing attacks targeted its website and mobile app between June 17 and June 19, 2026, compromising some Chick-fil-A One accounts. Attackers used email-and-password combinations obtained from another source, potentially accessing customer profile details, loyalty balances, QR codes, and limited payment-card information. The company logged out affected users, removed saved payment methods, restored account balances, and advised customers to reset reused passwords and enable multifactor authentication.

First Article: 07/30/26

Latest Article: 07/30/26

Articles

07-30-2026
Charlotte Observer
Chick-fil-A notified customers in North Carolina, eight other states, and Washington, D.C., in July that a June cyberattack accessed limited loyalty accounts using compromised third-party credentials.
07-30-2026
Charlotte Observer
Chick-fil-A notified customers in North Carolina, eight other states, and Washington, D.C., in July that a June cyberattack may have exposed loyalty-account information.
07-30-2026
The News & Observer
Chick-fil-A notified customers in nine states and Washington, D.C., on July 20 that a June cyberattack may have exposed loyalty-account information.
07-29-2026
Fox News / Kurt Knutsson
Chick-fil-A warned customers in the United States on July 13, 2026, that credential-stuffing attacks may have accessed Chick-fil-A One loyalty accounts targeted through the company website and mobile app.
07-27-2026
CPO Magazine / Alicia Hope
Chick-fil-A reported credential stuffing attacks on its website and mobile apps between June 17 and June 19, 2026, leading to customer data exposure and state breach notifications.
07-24-2026
Unpwned
Chick-fil-A notified customers of a credential-stuffing breach affecting loyalty and ordering accounts after automated login attempts succeeded.