Chick-fil-A notified customers on July 22, 2026 that unauthorized parties broke into Chick-fil-A One loyalty accounts in June using stolen passwords — the exact same type of attack that compromised 71,473 accounts at the same company in 2022 and 2023. The company offers multi-factor authentication for its loyalty app but does not require it. The attack worked anyway.
The breach ran from June 17 through June 19, 2026. Chick-fil-A's own systems were not the source of the stolen credentials — attackers used username-and-password combinations harvested from prior, unrelated data breaches elsewhere and fired them at the Chick-fil-A website and mobile app in a high-speed automated barrage. The company detected suspicious login activity, launched an investigation and disclosure, and concluded on July 13 that customer data had been accessed. Customers received breach notification letters dated July 20.
Chick-fil-A One Accounts Exposed: What Attackers Could See
The data accessible to attackers varied by how much each customer had stored in their Chick-fil-A One account. According to the company's breach notification filed with state attorneys general, potentially exposed information included full names, email addresses, Chick-fil-A One membership numbers and mobile pay numbers, account QR codes, stored Chick-fil-A credit balances, and the last four digits of linked credit or debit cards.
Customers who had filled in optional profile fields faced additional exposure: dates of birth, phone numbers, and home addresses were also accessible in affected accounts. Chick-fil-A confirmed that its own password database was not compromised in the attack — the credentials used came from external sources — and that only partial card numbers were reachable, not full payment card data.
How Credential Stuffing Works — and Why Loyalty Apps Are Targets
Credential stuffing is not guessing. Attackers do not try random password combinations against a locked door. They show up with a working key — a list of real username-and-password pairs extracted from prior breaches at other companies — and try each one. According to Imperva security research, roughly 0.1 percent of credential pairs tested in a typical stuffing campaign result in successful logins. At scale, that fraction is enough: feed a million stolen credentials into an automated bot, and up to a thousand accounts fall.
Fast-food and retail loyalty apps are among the most frequently targeted platforms for this type of attack, according to a 2026 industry analysis by Nexustek. The reason is straightforward: loyalty accounts hold stored payment method references, spendable credit balances, redeemable QR codes, and personal information including dates of birth and home addresses — all inside a system that historically has required less authentication friction than a bank. Verizon's 2025 Data Breach Investigations Report found that stolen credentials drove 22 percent of all confirmed data breaches that year.
In June 2026 — the same month this attack took place — cybersecurity researchers discovered a 24-billion-record credential database sitting exposed on an unsecured server, stocked primarily with infostealer malware logs. That reservoir represented the ammunition supply from which attacks like this one draw.
How Many Customers Were Affected?
Chick-fil-A has not disclosed a total national count of compromised accounts. Regulatory filings offer a partial picture: the company reported 2,182 affected customers to the Texas Attorney General's office and 39 to Massachusetts authorities via the state's 2026 Data Breach Notification Report. Beyond those two states, Chick-fil-A sent notifications to customers in Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont — 11 states plus DC in total.
A Chick-fil-A spokesperson confirmed the incident to Newsweek, calling it a matter affecting "a limited number of Chick-fil-A One Loyalty accounts." The company declined to provide a total figure to BleepingComputer. That absence matters: in 2023, when Chick-fil-A disclosed 71,473 affected accounts, the company had allowed a months-long attack to run before detecting it. The June 2026 attack ran for two days before being stopped — a faster containment, but the total national scope of damage remains unknown to the public.
Why the Same Attack Worked Again
Chick-fil-A does offer multi-factor authentication for Chick-fil-A One accounts. Malwarebytes confirmed in its July 22 reporting that MFA is available through a verified mobile phone number. However, MFA has not been made mandatory. The credential stuffing attack succeeded because automated bots could attempt logins without triggering an MFA challenge on accounts where the feature was not activated.
The Cybersecurity and Infrastructure Security Agency has stated that enabling MFA makes an account approximately 99 percent less likely to be compromised in an account-takeover attack. The Federal Trade Commission has similarly advised consumers to enable MFA and avoid reusing passwords across multiple services. Neither federal agency requires consumer-facing loyalty apps to mandate MFA — and Chick-fil-A has not chosen to do so voluntarily.
The 2023 class action lawsuit filed against Chick-fil-A after that breach — Stephens et al. v. Chick-fil-A Inc., Case No. 1:23-cv-00964-LMM, in the US District Court for the Northern District of Georgia — alleged the company had committed an "utter failure to implement basic cybersecurity policies." The parties reached a settlement in principle in October 2023; its financial terms were not disclosed. Law firms including Cole & Van Note began investigating the 2026 breach for potential new class-action claims on the same day the disclosure was published.
The industry precedent is not encouraging for Chick-fil-A. Dunkin' Brands paid $650,000 to New York's attorney general in 2020 to settle charges arising from credential stuffing attacks on its DD Perks loyalty accounts that ran from 2015 through 2018. A 42-state coalition extracted $18 million from the bankrupt estate of 23andMe this month for a nearly identical failure: credential stuffing succeeded on 14,000 accounts, MFA was not required, and the resulting damage cascaded to 6.9 million users.
Chick-fil-A's Response
Following detection of the attack, Chick-fil-A forced affected accounts to log out of all active sessions, removed stored payment methods from compromised profiles, restored Chick-fil-A One account balances that had been exposed, and added bonus rewards to affected accounts as a goodwill measure. The company advised customers to reset their passwords.
In its statement to Newsweek, Chick-fil-A said it has continued to enhance its "security, monitoring and fraud controls" following the incident. The company has not specified whether mandatory MFA enrollment is among those enhancements.
What Chick-fil-A One Customers Should Do Now
Security researchers and federal agencies are aligned on the protective steps, and the urgency applies to all Chick-fil-A One users — not only those who received a notification letter, since the total national affected count has not been disclosed.
Change your Chick-fil-A One password immediately, even if you have not received a notification. If you used the same password on any other service — email, banking, streaming, other food or retail apps — change it on those accounts as well, because attackers routinely run the same stolen credentials across dozens of platforms simultaneously.
Enable MFA on your Chick-fil-A One account. The app supports it via verified mobile phone number, and it will block the specific attack type used in both the 2023 and 2026 breaches from working against your account in the future. The step takes under two minutes.
Use a dedicated password manager to generate and store unique passwords for each online account. The structural problem that makes credential stuffing possible — password reuse across multiple services — is one that consumers can address individually even when platforms do not mandate it.
Monitor your bank and credit card statements for unfamiliar charges, even though only the last four digits of linked cards were accessible in this breach. Watch your Chick-fil-A One account balance and rewards history for unauthorized redemptions. Attackers who obtained QR codes could attempt to use them for in-store transactions; contact Chick-fil-A directly if your balance is missing or shows unexpected activity.
Customers who believe their identity may have been misused can report it to the Federal Trade Commission at IdentityTheft.gov.
Frequently Asked Questions
What information was exposed in the Chick-fil-A data breach?
Attackers who gained access to Chick-fil-A One accounts could see full names, email addresses, membership and mobile pay numbers, account QR codes, stored credit balances, and the last four digits of linked debit or credit cards. If a customer had filled in optional profile fields, dates of birth, phone numbers, and home addresses were also accessible. Full credit card numbers and passwords were not exposed — the attackers used stolen credentials from other sources and never obtained Chick-fil-A's own password database.
How do I know if my Chick-fil-A One account was hacked?
Chick-fil-A sent notification letters to customers confirmed as affected in 11 states plus DC. However, the company has not disclosed the total number of accounts compromised nationwide, so not receiving a letter does not guarantee your account was untouched. All Chick-fil-A One users should change their passwords, enable MFA via verified phone number, and check their account for unfamiliar charges or missing rewards regardless of notification status.
What is a credential stuffing attack, and how is it different from hacking Chick-fil-A directly?
Credential stuffing does not break into the target company's systems. Attackers acquire lists of real username-and-password combinations from prior breaches at entirely different companies — databases often available on dark-web markets for low cost — and feed them into an automated bot that tries each one against a new target's login page. The attack succeeds specifically because many consumers reuse the same passwords across multiple services. Chick-fil-A's own password database was not compromised in either the 2023 or 2026 attacks; the credentials came from somewhere else.
Why did this happen again after the 2023 breach?
Chick-fil-A offers multi-factor authentication for Chick-fil-A One accounts but does not require it. Credential stuffing attacks work specifically on accounts where only a password is needed to log in. Because the company did not mandate MFA enrollment after the 2023 breach — which exposed over 71,000 accounts using the identical method — the same technique remained effective in 2026. CISA has stated that MFA makes an account approximately 99 percent less likely to be compromised in this type of attack.
Related Articles