Last Update: 08/01/2026 at 12:00 PM EST

Chick-fil-A Credential-Stuffing Breach

Coverage from BleepingComputer, CBS News, and others

Articles

58

Active Days

8

The Topic

Chick-fil-A Credential-Stuffing Breach topic image

Chick-fil-A is notifying customers and state regulators after credential-stuffing attacks on Chick-fil-A One accounts exposed personal, loyalty, and partial payment data. The incident is being reported across multiple states, with remediation focused on forced logouts, password resets, and payment-method removal.

First Article: 07/20/26

Latest Article: 07/27/26

Summary

  • The dominant signal is a consumer account breach affecting Chick-fil-A One loyalty users, not a broad platform privacy policy shift.
  • Attackers used credentials obtained from another source, showing password reuse and third-party compromise as the main access vector.
  • Exposed data consistently includes names, email addresses, membership numbers, loyalty/payment identifiers, and last four digits of payment cards; some reports also mention addresses, phone numbers, birth dates, and gift card balances.
  • Chick-fil-A's response has been consistent across reports: force logouts, reset passwords, remove stored payment methods, restore balances, and notify customers and state authorities.
  • State breach filings make the scale clearer, but the total affected population remains somewhat fragmented across reports, with figures cited in Texas, Massachusetts, and Maine.
  • The topic is operationally stable and high-cohesion: multiple outlets are describing the same incident from slightly different regulatory and consumer-notice angles.
  • A prior similar Chick-fil-A credential-stuffing incident is mentioned in one report, but the current cluster signal is overwhelmingly about the July 2026 breach.

History

07/26/2026

The story has broadened from a multi-state Chick-fil-A loyalty breach into a more clearly documented state-regulatory incident, with Maine now joining Texas and Massachusetts in the reporting trail. The current version also sharpens the exposure description by emphasizing loyalty/payment identifiers and the credential-reuse access path.

07/24/2026

The story has shifted from a general account-takeover breach report to a more regulator-backed picture, with Texas and Massachusetts filings adding clearer confirmation of the incident and its scope. The core facts remain the same, but the current version strengthens the case that this was a credential-stuffing event affecting loyalty accounts and partial payment data.

Featured

Timeline: 8 Days

Jul 20Jul 21Jul 23Jul 24Jul 26Jul 27

Additional Articles

⭐⭐⭐⭐⭐

NBC Connecticut / Max Molski07-22-2026
Chick-fil-A notified customers in 10 states and Washington, D.C. after unauthorized access to the Chick-fil-A One website and mobile app between June 17 and June 19.
WTOP News / Tracy Johnke07-22-2026
Chick-fil-A notified Chick-fil-A One members in Washington, D.C., Maryland, and other states after a June 2026 attack used third-party credentials to access accounts.
Yahoo07-22-2026
Chick-fil-A notified customers after a June 17 to June 19, 2026 automated cyberattack potentially exposed personal details and Chick-fil-A One account data.
Yahoo07-22-2026
Chick-fil-A notified customers July 20 after a June 17-19 incident potentially exposed Chick-fil-A One loyalty data across multiple U.S. states.
Yahoo07-22-2026
Chick-fil-A notified customers in multiple states on July 20 after an automated cyberattack targeted Chick-fil-A One accounts and exposed personal data between June 17 and June 19, 2026.
Yahoo07-23-2026
Chick-fil-A notified customers in June about a website and mobile app cyberattack that exposed Chick-fil-A One loyalty data in Georgia, Massachusetts, and Texas.
Yahoo07-24-2026
Chick-fil-A notified Chick-fil-A One members on July 20 about suspicious logins from third-party credentials, potentially exposing personal and payment-related data.
Atlanta Journal-Constitution / Mirtha Donastorg and Amy Wenk07-22-2026
Chick-fil-A disclosed a June 17-19 breach of Chick-fil-A One accounts to the Massachusetts attorney general after unauthorized access to customer identity and last-four payment data.
Newsday / Maureen Mullarkey07-23-2026
Chick-fil-A disclosed a June 17 to 19 cyberattack on its Chick-fil-A One site and app, potentially exposing loyalty data across New York and other states.
NJ.com / Khadrice Rollins07-22-2026
Massachusetts posted July 20 notice after Chick-fil-A reported unauthorized access to Chick-fil-A One accounts between June 17-19, potentially exposing customer data across multiple states.
People / Chiara Kim07-24-2026
Chick-fil-A notified customers on security incident remediation steps in Washington, D.C. and nine states after a June 17-19 automated attack used third-party-obtained credentials.
The Baltimore Banner / Darreonna Davis07-22-2026
Chick-fil-A reported a June 17-19 attack potentially exposed Chick-fil-A One personal data and partial card details in Maryland and nine other jurisdictions.
WNBJ 3907-23-2026
Chick-fil-A reported June 17-19 unauthorized access to Chick-fil-A One accounts via third-party credentials affecting customers across multiple U.S. states.
MySanAntonio / Polly Anna Rocha07-23-2026
Chick-fil-A notified customers in multiple states and Washington, D.C. on July 20, 2026, after an automated attack on Chick-fil-A One accounts may have exposed personal data.
WataugaOnline.com / Kenneth Reece07-24-2026
Chick-fil-A notified customers on July 20, 2026 that a credential-stuffing incident may have exposed Chick-fil-A One account data from June 17 to June 19.
AOL07-22-2026
Chick-fil-A notified customers in July 2026 that a June 17 to June 19 automated attack may have accessed Chick-fil-A One account data nationwide.
Fox 10 News / Dorothy Sedovic07-22-2026
Chick-fil-A notified customers on July 20, 2026 of a limited Chick-fil-A One loyalty account breach tied to third-party credential misuse.
Western Massachusetts News / Dorothy Sedovic07-22-2026
Chick-fil-A notified customers on July 20, 2026 to reset passwords after third-party obtained credentials led to a Chick-fil-A One Loyalty account breach.
The News & Observer / Tanasia Kenney07-23-2026
Chick-fil-A disclosed a June 17 to June 19 cyberattack using third-party credentials that potentially exposed loyalty account data across multiple U.S. states.
WISN / Jocelyn Brumbaugh07-23-2026
Chick-fil-A notified Chick-fil-A One members in multiple U.S. states in 2026 after a cyberattack between June 17 and June 19 may have exposed account data.
McAfee / Brooke Seipel07-24-2026
Chick-fil-A notified customers in 10 states after credential stuffing using leaked credentials potentially accessed a limited set of Chick-fil-A One loyalty accounts.
WCVB / Jocelyn Brumbaugh07-23-2026
Chick-fil-A notified customers in multiple US states in 2026 after an automated attack on Chick-fil-A One may have exposed account and payment-related data.
Safestate07-22-2026
Chick-fil-A notified customers in multiple U.S. states in 2026 after a credential-stuffing attack accessed Chick-fil-A One loyalty-account data from leaked credentials.
Fox 5 Atlanta07-22-2026
Chick-fil-A reported suspicious logins on Chick-fil-A One Loyalty accounts, disclosing potential customer data exposure in Washington, D.C., and several US states.
WAVY07-22-2026
Chick-fil-A confirmed July 13, 2026 potential access to names, emails, and credit card last four digits for some Chick-fil-A One accounts after a credential-based attack in June 2026.
CPO Magazine / Alicia Hope07-27-2026
Chick-fil-A reported credential stuffing attacks on its website and mobile apps between June 17 and June 19, 2026, leading to customer data exposure and state breach notifications.
WESH / Jocelyn Brumbaugh07-23-2026
Chick-fil-A informed Chick-fil-A One loyalty members in multiple states in July 2026 that an automated cyberattack may have exposed account data.
The Dallas Morning News / Trevor Bach07-22-2026
Chick-fil-A disclosed a June 17 to June 19 breach impacting about 2,200 Texas loyalty customers after an automated attack used third-party-obtained credentials.
NBC Boston / Max Molski07-22-2026
Chick-fil-A notified customers in 10 states and Washington, D.C. after a June 17-19 cyberattack potentially exposed loyalty account and partial payment details.
Cleveland.com / Khadrice Rollins07-22-2026
Chick-fil-A issued breach notifications in multiple U.S. states in July 2026 after unauthorized access to Chick-fil-A One data from a June website and app hack.
Charlotte Observer / Tanasia Kenney07-23-2026
Chick-fil-A notified customers after a June 17-19, 2026 cyberattack potentially exposed loyalty account information in multiple states including North Carolina.
Star-Telegram / Lillie Davidson07-23-2026
Chick-fil-A disclosed a cyberattack between June 17 and 19 that potentially exposed loyalty account data for over 2,000 customers in Texas and other states.
PIX1107-22-2026
Chick-fil-A reported a June 17-19, 2026 Chick-fil-A One attack that may have exposed customer emails, passwords, and card-adjacent identifiers in New York and other states.
WLKY / Jocelyn Brumbaugh07-23-2026
Chick-fil-A notified Chick-fil-A One members in multiple U.S. states after a June 2026 account-takeover attack possibly exposed loyalty and payment-adjacent data.
Syracuse.com / Khadrice Rollins07-22-2026
Chick-fil-A notified customers in multiple US states in July after June 17-19 hacking of Chick-fil-A One may have exposed account data and last-four card digits.
MLive / Khadrice Rollins07-22-2026
Chick-fil-A notified customers in multiple U.S. states in July 2026 after a Chick-fil-A One website and app hack exposed names, emails, and card last four digits.
AL.com / Khadrice Rollins07-22-2026
Massachusetts and multiple states issued notices after a June 17-19 Chick-fil-A website and app hack exposed Chick-fil-A One member account data.
KOAT / Jocelyn Brumbaugh07-23-2026
Chick-fil-A notified customers in multiple U.S. states in July 2026 after unauthorized parties may have accessed Chick-fil-A One account data via third-party credentials.
OregonLive / Khadrice Rollins07-22-2026
Chick-fil-A notified customers in Massachusetts and other states in July 20 guidance about unauthorized access to Chick-fil-A One accounts from June 17-19.
LiveNOW from FOX07-22-2026
Chick-fil-A notified customers in Massachusetts after unauthorized access to some Chick-fil-A One loyalty accounts occurred between June 17 and June 19, 2026.
WYFF4 / Jocelyn Brumbaugh07-23-2026
Chick-fil-A notified Chick-fil-A One customers in the U.S. after an attack from June 17 to June 19, 2026 may have exposed loyalty account data.
WBAL-TV / Jocelyn Brumbaugh07-23-2026
Chick-fil-A notified customers in multiple states in 2026 after a June 17-19 cyberattack may have accessed Chick-fil-A One account data, including login credentials and partial payment details.
KCRA / Jocelyn Brumbaugh07-23-2026
Chick-fil-A notified loyalty customers across multiple states and Washington, D.C. in July 2026 after a cyberattack may have accessed Chick-fil-A One account data.
WMUR / Jocelyn Brumbaugh07-23-2026
Chick-fil-A notified Chick-fil-A One members in multiple US states in 2026 after an automated website and app attack may have accessed account data using third-party credentials.
PCWorld / Alaina Yee07-23-2026
Chick-fil-A disclosed a June 17-19 credential-stuffing incident affecting customer accounts in 10 states and Washington, D.C., with notifications issued in July.
MassLive / Khadrice Rollins07-22-2026
Chick-fil-A notified customers in multiple US states after a June 17-19 hack of the website and app exposed Chick-fil-A One account data.
OAN / Katherine Mosack07-23-2026
Chick-fil-A notified customers in multiple US states after an automated June 17-19 2026 attack using acquired Chick-fil-A One credentials potentially exposed rewards account data.
Woman's World07-23-2026
Chick-fil-A reported potentially compromised Chick-fil-A One accounts after credential-stuffing logins between June 17 and June 19 affected customers in multiple states.

⭐⭐⭐

Forbes07-22-2026
Chick-fil-A notified customers on July 20 after suspicious login activity and an automated credential-based attack on Chick-fil-A One accounts occurred June 17-19, 2026.
Yahoo07-22-2026
Chick-fil-A notified certain Chick-fil-A One loyalty members after suspicious logins linked to a June 17-19 credential-based attack affected accounts in multiple states and Washington, D.C.
Newsweek / Toby Meyjes07-22-2026
Chick-fil-A reported a data breach on July 20, with Massachusetts filings listing 39 affected customers and Texas filings listing 2,182.
WDTN / Trey Brown07-22-2026
Chick-fil-A disclosed a security breach affecting Chick-fil-A One Loyalty accounts, with potentially limited account impact, and began customer communication and account restoration.
Atlanta News First07-22-2026
Chick-fil-A disclosed unauthorized access to Chick-fil-A One accounts between June 17 and June 19 from leaked credentials, starting in Atlanta.
NBC Washington / Max Molski07-22-2026
Chick-fil-A warned customers in multiple states and Washington, D.C. on a July 2026 breach tied to unauthorized access of Chick-fil-A One account data from June 17-19.
Unpwned07-24-2026
Chick-fil-A notified customers of a credential-stuffing breach affecting loyalty and ordering accounts after automated login attempts succeeded.