Thousands of Chick-fil-A One loyalty members are receiving breach notifications after criminals broke into their accounts using passwords stolen from unrelated websites. The company says the intrusion took place between June 17 and June 19, 2026, and that it confirmed unauthorized access to customer data on July 13. State filings so far put the number of affected Texas residents at 2,182, with notifications also sent to customers in Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont and the District of Columbia.
How the attack unfolded
According to Chick-fil-A's notice, the breach was not the result of a hack against its own systems. Instead, attackers used login credentials - email addresses and passwords - obtained from a third-party source, almost certainly a previous, unrelated data breach, and ran them against the Chick-fil-A website and mobile app in an automated fashion. This method, known as credential stuffing, relies entirely on the fact that many people reuse the same password across multiple services. When one of those services is breached, the stolen credentials become a key that may unlock accounts elsewhere. buy vpn
Once inside a compromised account, attackers could potentially view names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, rewards balances and Chick-fil-A credit, and the last four digits of any linked payment card. In accounts where the information was stored, phone numbers, birth dates and mailing addresses may also have been exposed. Chick-fil-A has been clear that full payment card numbers and passwords from its own systems were not compromised, since credential stuffing depends on data already stolen elsewhere.
Why loyalty accounts are attractive targets
Restaurant and retail loyalty programs are often treated as low-priority accounts by users, yet they frequently hold saved payment methods, contact details and reward balances that can be converted into real value. Attackers can drain reward points, place fraudulent orders through stored mobile pay credentials, or harvest personal details to sharpen future phishing attempts. Combined with data from other breaches, this information helps build fuller identity profiles that can be resold or used for further fraud. This is not a new problem for the chain: in 2023, Chick-fil-A disclosed a similar credential stuffing incident affecting more than 71,000 accounts, in which attackers accessed personal data and spent stored rewards balances.
In response to the latest incident, Chick-fil-A says it has logged out affected users, removed stored payment methods, restored compromised rewards balances, issued bonus rewards to affected customers, and advised them to reset their passwords.
Reducing the risk of account takeover
Credential stuffing succeeds because password reuse remains widespread, and its effects are rarely limited to the platform named in a breach notice. Anyone who has ever reused a password is potentially exposed, regardless of whether they use Chick-fil-A's app. Practical steps can meaningfully reduce that risk:
- Change your Chick-fil-A account password immediately, even without a notification, and update it anywhere else it was reused.
- Use a unique, strong password for every account, generated and stored through a password manager rather than memorized.
- Enable multi-factor authentication wherever it is offered, since it blocks most automated login attempts even when a password is known.
- Review your Chick-fil-A account for unfamiliar orders, altered profile details, or missing rewards.
- Check bank and card statements for unrecognized charges, and monitor credit reports if personal details were stored in the account.
- Treat unsolicited emails, texts or calls referencing the breach with suspicion, since these incidents often trigger follow-up phishing attempts.
Stolen credentials rarely surface immediately after a breach; they often circulate quietly for months before being tested against other platforms. Monitoring services that alert users when their email addresses or passwords appear in known breaches can provide an early warning, giving people a chance to change exposed passwords before criminals use them elsewhere. Paired with unique passwords and multi-factor authentication, that kind of visibility remains one of the more effective defenses against an old breach quietly enabling a new one.