Chick-fil-A Reports Data Breach of Loyalty Program Accounts
Chick-fil-A notified customers in 10 states and D.C. after a credential-stuffing attack compromised loyalty account data and payment card fragments.
Chick-fil-A Inc. disclosed a data breach affecting its Chick-fil-A One Loyalty accounts resulting from a credential-stuffing attack. Unauthorized actors used email and password combinations obtained from third-party sources to access customer accounts via the company's website and mobile application. The breach occurred between June 17 and June 19, 2026, though the company finalized its investigation on July 13.
Compromised data included names, email addresses, membership numbers, account balances, and the last four digits of payment cards. Some users also had their phone numbers, mailing addresses, and birthdays exposed. The company began notifying affected customers and state Attorney General offices on July 20. While a total national count of affected users was not disclosed, reports to state governments indicate 2,182 affected individuals in Texas and 39 in Massachusetts.
In response to the incident, the company forced account logouts, removed stored payment methods, and restored account balances. Some users were also provided with bonus rewards. Chick-fil-A is notifying customers in 10 states and the District of Columbia, advising them to monitor credit reports and implement fraud alerts.