Chick-fil-A Confirms Credential Stuffing Attacks Hacked Customer Accounts
Fast-food giant **Chick-fil-A** is notifying an undisclosed number of customers about a data breach stemming from recent credential stuffing attacks. Threat actors leveraged previously compromised credentials to access **Chick-fil-A One** accounts, potentially exposing personal and financial information.
American fast-food restaurant chain **Chick-fil-A** has confirmed that customer accounts were compromised in a series of credential stuffing attacks. The company, operating over 3,000 restaurants across the U.S., Canada, Puerto Rico, the UK, and Singapore, detected suspicious login activity on its website and mobile application.
### Attack Details and Timeline
**Chick-fil-A** revealed in data breach notification letters that unauthorized parties launched an automated attack between June 17 and June 19, 2026. The attackers utilized account credentials (email addresses and passwords) obtained from a third-party source, indicating a credential stuffing operation.
"Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source," the company stated. "Based on our investigation, we determined on July 13, 2026 that the unauthorized parties may have accessed information in your **Chick-fil-A One** account."
### Exposed Customer Data
The investigation concluded that the breach may have exposed a range of customer data, including:
* Names
* Email addresses
* **Chick-fil-A One** membership numbers
* Mobile pay numbers
* QR codes
* **Chick-fil-A** credit balances
* Last four digits of credit/debit card numbers
Additionally, if stored in the compromised accounts, birth dates, phone numbers, and addresses might also have been accessed.
### Scope of the Breach
While **Chick-fil-A** has not disclosed the total number of affected customers, filings with various Attorney General offices provide some insight. The company reported that 2,182 Texans and 39 Massachusetts residents were impacted. Notification letters were also sent to residents in Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
### Understanding Credential Stuffing
Credential stuffing is a common attack vector where cybercriminals use automated tools to test stolen username and password combinations against various online services. This method is particularly effective when users reuse credentials across multiple platforms. The primary objective is to gain unauthorized access to accounts, steal personal and financial information, and potentially sell this data on dark web marketplaces or use it for identity theft.
### Company Response and User Recommendations
In response to the incident, **Chick-fil-A** took several remediation steps:
* Logged out all impacted accounts.
* Removed payment methods from compromised accounts.
* Restored **Chick-fil-A One** account balances.
* Added rewards to affected accounts as a gesture of apology.
The company strongly advised all impacted users to change their passwords immediately, emphasizing the importance of using unique, strong passwords for each online service.
This incident mirrors a similar breach in March 2023, where **Chick-fil-A** confirmed that over 71,000 customer accounts were accessed, and rewards balances were used by threat actors in credential stuffing attacks between December 2022 and February 2023. This recurrence highlights the persistent threat of credential stuffing and the critical need for users to practice robust password hygiene.