Thousands of Chick-fil-A One loyalty accounts were accessed by cybercriminals last month in an automated attack that reused passwords stolen from unrelated data breaches. The company began notifying affected customers this week, confirming that names, membership numbers, mobile pay details, and partial payment card information may have been exposed. Filings with state regulators show at least 2,182 residents of Texas alone were affected, with notification letters also sent to customers in Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont and the District of Columbia.
What Happened, According to Chick-fil-A
According to the notice filed with regulators, unauthorized parties launched automated login attempts against Chick-fil-A's website and mobile app between June 17 and June 19, 2026, using email addresses and passwords obtained from a third party. Chick-fil-A says it detected the suspicious activity, cut off further attempts, and opened an investigation. On July 13, the company concluded that some accounts had in fact been accessed. Depending on what a customer had saved, exposed data could include email addresses, membership numbers, QR codes, rewards balances, Chick-fil-A credit, the last four digits of linked cards, and in some cases phone numbers, birth dates, and mailing addresses. Chick-fil-A has stressed that passwords were not stolen from its own systems. buy vpn
Why Credential Stuffing Keeps Working
Credential stuffing does not rely on breaking into a company's servers. Instead, attackers take large lists of usernames and passwords leaked from previous, often unrelated breaches, and run them automatically against other websites, betting that people reuse the same login across multiple platforms. Because password reuse remains widespread, even a handful of successful matches out of thousands of attempts can be profitable. Loyalty programs are attractive targets precisely because they are often treated as low-value accounts, even though they frequently store real names, saved payment methods, and stored monetary balances that can be spent or transferred before anyone notices.
A Repeat Incident
This is not the first time Chick-fil-A has dealt with this exact problem. In 2023, the company disclosed a similar credential stuffing campaign that compromised more than 71,000 accounts and allowed attackers to drain stored rewards. Following this latest incident, Chick-fil-A says it has logged out affected users, removed stored payment methods, restored compromised reward balances, added bonus rewards to affected accounts, and urged customers to reset their passwords. The recurrence highlights a structural weakness common across loyalty and rewards platforms: authentication systems that rely solely on email-and-password logins remain vulnerable no matter how well a company secures its own internal data.
What Customers Should Do Now
- Change your Chick-fil-A account password immediately, even without a notification.
- Update that same password anywhere else it has been reused.
- Use a unique password for every account, ideally generated and stored with a password manager.
- Turn on multi-factor authentication wherever it is offered.
- Review your Chick-fil-A account for unfamiliar orders or missing rewards.
- Check bank and card statements for unrecognized charges.
- Watch for phishing messages posing as Chick-fil-A or offering breach compensation.
Incidents like this rarely start with the company that ends up making headlines. The stolen credentials usually originate from breaches disclosed months or years earlier, sitting unused until criminals decide to test them elsewhere. Services that monitor whether your email addresses and passwords have surfaced in known breaches can offer early warning, giving people a chance to change vulnerable passwords before they are weaponized against yet another account.