Chick-fil-A discloses June credential-stuffing breach
Chick-fil-A confirms credential-stuffing hits June 17-19, exposing loyalty data, QR codes, and last-4 card digits. Breach determination made July 13.
Disclosure confirmed. Chick-fil-A is notifying customers of a data breach after credential-stuffing runs against its website and mobile app in mid-June, per notification letters filed with state regulators and reported today by BleepingComputer. Confidence: confirmed by Chick-fil-A’s own notification.
Timeline
- 2026-06-17 through 2026-06-19. Automated credential-stuffing traffic hits Chick-fil-A accounts on the site and mobile app, using stolen username/password pairs sourced from third-party breaches. Confidence: as-stated in the notification letter.
- 2026-07-13. Chick-fil-A completes its investigation and formally determines a breach occurred. Confidence: as-stated.
- 2026-07-22. Notification letters land with state AGs and customers. BleepingComputer’s read of the Texas filing: 2,182 Texas residents named. Additional filings cover residents of Iowa, DC, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island. Confidence: confirmed via state filings. Total customer-count across all states: not disclosed.
What was exposed
Per the notification letter, on accounts that were successfully accessed:
- Name and email address
- Chick-fil-A One membership number
- Mobile pay number and QR code
- Chick-fil-A credit balance
- Last four digits of the credit or debit card on file
Additional fields exposed only if the customer had stored them on the account: date of birth, phone number, and address. No indication in the notification that full card numbers, CVVs, or clear-text passwords were in scope. Confidence: as-stated by Chick-fil-A.
Attack shape, in one line
This is not a Chick-fil-A vulnerability. It’s password reuse. Attackers took credentials leaked from other breaches and replayed them against Chick-fil-A’s login endpoint until enough hit. Chick-fil-A’s role in the chain is the target of the reuse, not the source of the credentials. No CVE, no vendor patch to wait for — the fix lives with the customer.
What Chick-fil-A says it did
Per the notification, the company:
- Logged out compromised accounts.
- Removed stored payment methods from those accounts.
- Restored account balances that had been drained.
- Added rewards to affected accounts as compensation.
Notification also directs customers to reset passwords and enable available account security features. Confidence: as-stated in the notification letter.
Prior incident — relevant context
Chick-fil-A disclosed a substantially similar credential-stuffing incident that ran December 2022 through February 2023, affecting more than 71,000 customers at that time. Confidence: confirmed by 2023 disclosure. Same attack class, same login surface, three-and-a-half years later, materially smaller footprint on the current filings — one plausible read is that intervening controls narrowed the successful-hit rate; another is that the current filings are state-by-state and the aggregate is not yet public. Unconfirmed either way.
Unconfirmed as of publish — treat accordingly
- Total number of Chick-fil-A One accounts accessed across all jurisdictions.
- Whether the credential lists tie to a specific known breach corpus.
- Whether Chick-fil-A One is now protected by any additional login controls (rate limiting, bot detection, MFA option) beyond what was in place in June.
- Any secondary fraud downstream of the exposed last-4 and QR codes.
For anyone with a Chick-fil-A One account
- Reset the Chick-fil-A password. Do not reuse a password used anywhere else.
- Check recent order and rewards activity on the account.
- Remove any saved payment methods you don’t need stored.
- Watch for phishing that uses the loyalty-program details as pretext — names, membership numbers, and QR codes are enough scaffolding for a convincing lure even if the last-4 alone isn’t a fraud vector.
Sources
- BleepingComputer, 2026-07-22: Chick-fil-A discloses data breach after credential stuffing attacks — carries the state-filing excerpt and Chick-fil-A’s response language.
Confidence, consolidated: June 17-19 attack window and July 13 breach-determination date as-stated by Chick-fil-A; 2,182-Texan count confirmed via state filing, aggregate across all states not disclosed; exposed-field list as-stated in the notification; prior 2022-2023 incident confirmed at 71k+; no CVE, no vendor patch — the exposure is password reuse.
Found this useful? Share it.


