Chick-fil-A Warns of Loyalty Account Breach Affecting Thousands of Customers

💛 A quick favor, if you've got a second.

We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.

It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

Share this story:


✉️ Email


💬 Text

Chick-fil-A has alerted customers to a security incident that compromised an undisclosed number of accounts within its One loyalty program. The fast-food chain discovered unauthorized access to customer accounts and notified affected users across multiple states, including Texas and Massachusetts, according to regulatory filings and the company’s disclosure.

The breach occurred during a concentrated attack spanning June 17 through June 19, 2026, according to Chick-fil-A’s investigation. Attackers deployed automated tools to test email addresses and passwords obtained from third-party sources against the company’s website and mobile application. The company determined on July 13 that unauthorized parties successfully accessed some accounts, likely targeting customers who had reused passwords across multiple platforms.

Public records indicate at least 2,182 Texas residents and 39 Massachusetts residents were affected, with additional notifications sent to customers in Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont and Rhode Island. The exposed information varied by account but may have included customer names, phone numbers, email addresses, saved delivery addresses, loyalty membership details and the last four digits of payment cards stored in accounts.

Chick-fil-A took immediate action by logging affected customers out of their accounts, removing saved payment methods and crediting rewards balances. The company released a statement acknowledging the incident and expressing commitment to maintaining customer trust. However, the disclosure raised concerns about the ongoing vulnerability of loyalty accounts to credential-stuffing attacks, a technique where stolen login information from older breaches is tested against other services.

This marks the second major credential-stuffing incident at Chick-fil-A in less than four years. The company confirmed in March 2023 that attackers had accessed more than 71,000 customer accounts during a campaign running from December 2022 through February 2023. That breach similarly exposed personal information and allowed attackers to access stored rewards balances.

Security experts recommend that affected customers immediately change their Chick-fil-A password to a unique combination never used elsewhere. Customers should review their transaction history, rewards activity and saved payment methods through the mobile application. Anyone who spots unauthorized activity should contact Chick-fil-A directly and monitor their financial accounts for fraudulent charges.

Experts also advise updating passwords on any account where the same login credentials were reused, prioritizing email accounts and financial services. A password manager can help identify and replace duplicate passwords across multiple platforms. Customers should enable multifactor authentication on email and banking accounts, as Chick-fil-A does not currently offer this feature for its loyalty program.

The breach illustrates the risks associated with password reuse and the extended utility of stolen credentials in the criminal marketplace. Attackers can combine exposed information with data from public records and people-search websites to craft convincing phishing messages. Customers should remain vigilant for fraudulent communications claiming to address account security and avoid clicking links in unsolicited messages.

Share this story:


✉️ Email


💬 Text