Chick-fil-A has confirmed that a credential stuffing attack compromised more than 13,000 Chick-fil-A One loyalty accounts between June 17 and June 19, 2026. The company determined on July 13 that customer data had been exposed and began sending breach notification letters on July 20.
What Happened
The attack is a textbook credential stuffing campaign. Attackers loaded username and password pairs harvested from prior, unrelated data breaches at other companies and fired them in bulk against Chick-fil-A's login endpoints — both the website and the mobile app. The technique exploits one of the most persistent bad habits in consumer security: reusing the same password across multiple services.
No vulnerability in Chick-fil-A's systems was exploited. Attackers simply tried leaked credentials until they found combinations that worked.
State filings confirm the geographic spread: 2,182 affected customers in Texas and 39 in Massachusetts, with notifications also sent to residents of Washington D.C., Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island. The total confirmed count stands at 13,322.
Data Exposed
For each compromised Chick-fil-A One account, attackers had access to:
- Full name and email address
- Chick-fil-A One membership number
- Mobile pay number and QR code
- Account credit balance (stored value)
- Last four digits of any saved credit or debit cards
- Potentially: date of birth, phone number, and home address (if stored in the profile)
Full payment card numbers were not exposed. However, the mobile pay QR code and stored balance represent real financial value that attackers could drain.
Chick-fil-A's Response
The company took immediate steps after identifying the breach:
- Logged out all impacted accounts
- Removed all saved payment methods from affected accounts
- Restored drained account credit balances
- Added bonus rewards to affected accounts as compensation
- Forced password resets on compromised accounts
- Stated it is "enhancing its security and monitoring controls"
In their official statement, Chick-fil-A said: "We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts."
A Repeat Incident
This is the second credential stuffing breach for Chick-fil-A. The first was disclosed in March 2023 and covered a months-long campaign from December 2022 through February 2023, ultimately affecting over 71,000 customers. The recurrence raises legitimate questions about whether Chick-fil-A's bot detection, rate-limiting, and account-protection controls have materially improved since then.
Notably, Chick-fil-A offers optional multi-factor authentication (MFA) on its loyalty app but does not require it — a design choice that contributed to the attack's success.
What Affected Customers Should Do
If you received a notification or believe your account may have been involved:
- Change your Chick-fil-A One password to a unique, strong password not used anywhere else
- Enable MFA on the Chick-fil-A One app (available in account settings)
- Check your account balance and report any unauthorized charges
- Monitor saved payment cards linked to your account for unusual activity
- Consider a password manager if you reuse passwords — this is exactly how credential stuffing wins
The Bigger Picture
Chick-fil-A isn't uniquely negligent here. Credential stuffing is a volume game that targets every consumer-facing login endpoint in existence. What makes it effective is a problem that sits squarely outside any one company's control: the sheer volume of username/password pairs circulating on dark web markets from years of prior breaches.
The downstream blast radius of large-scale credential dumps — breaches at other companies becoming ammunition against entirely unrelated services — is one of the defining characteristics of the modern threat landscape. The only durable defense at the user level is unique credentials per service and MFA wherever it's offered.
The fact that this is Chick-fil-A's second incident of the same type within three years suggests the company has more work to do on the detection and friction side, particularly around mandatory MFA enrollment and aggressive bot-detection at login.
Source: BleepingComputer