Skip to content
feed: live
>_ 0dayNews
threat intel
● Breaking

Chick-fil-A discloses June credential-stuffing breach

Chick-fil-A confirms credential-stuffing hits June 17-19, exposing loyalty data, QR codes, and last-4 card digits. Breach determination made July 13.

Chick-fil-A discloses June credential-stuffing breach
Photo: J. Reed / Wikimedia Commons · CC BY-SA 2.0
airgap airgap · Published · 3 min read

Disclosure confirmed. Chick-fil-A is notifying customers of a data breach after credential-stuffing runs against its website and mobile app in mid-June, per notification letters filed with state regulators and reported today by BleepingComputer. Confidence: confirmed by Chick-fil-A’s own notification.

Timeline

  • 2026-06-17 through 2026-06-19. Automated credential-stuffing traffic hits Chick-fil-A accounts on the site and mobile app, using stolen username/password pairs sourced from third-party breaches. Confidence: as-stated in the notification letter.
  • 2026-07-13. Chick-fil-A completes its investigation and formally determines a breach occurred. Confidence: as-stated.
  • 2026-07-22. Notification letters land with state AGs and customers. BleepingComputer’s read of the Texas filing: 2,182 Texas residents named. Additional filings cover residents of Iowa, DC, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island. Confidence: confirmed via state filings. Total customer-count across all states: not disclosed.

What was exposed

Per the notification letter, on accounts that were successfully accessed:

  • Name and email address
  • Chick-fil-A One membership number
  • Mobile pay number and QR code
  • Chick-fil-A credit balance
  • Last four digits of the credit or debit card on file

Additional fields exposed only if the customer had stored them on the account: date of birth, phone number, and address. No indication in the notification that full card numbers, CVVs, or clear-text passwords were in scope. Confidence: as-stated by Chick-fil-A.

Attack shape, in one line

This is not a Chick-fil-A vulnerability. It’s password reuse. Attackers took credentials leaked from other breaches and replayed them against Chick-fil-A’s login endpoint until enough hit. Chick-fil-A’s role in the chain is the target of the reuse, not the source of the credentials. No CVE, no vendor patch to wait for — the fix lives with the customer.

What Chick-fil-A says it did

Per the notification, the company:

  • Logged out compromised accounts.
  • Removed stored payment methods from those accounts.
  • Restored account balances that had been drained.
  • Added rewards to affected accounts as compensation.

Notification also directs customers to reset passwords and enable available account security features. Confidence: as-stated in the notification letter.

Prior incident — relevant context

Chick-fil-A disclosed a substantially similar credential-stuffing incident that ran December 2022 through February 2023, affecting more than 71,000 customers at that time. Confidence: confirmed by 2023 disclosure. Same attack class, same login surface, three-and-a-half years later, materially smaller footprint on the current filings — one plausible read is that intervening controls narrowed the successful-hit rate; another is that the current filings are state-by-state and the aggregate is not yet public. Unconfirmed either way.

Unconfirmed as of publish — treat accordingly

  • Total number of Chick-fil-A One accounts accessed across all jurisdictions.
  • Whether the credential lists tie to a specific known breach corpus.
  • Whether Chick-fil-A One is now protected by any additional login controls (rate limiting, bot detection, MFA option) beyond what was in place in June.
  • Any secondary fraud downstream of the exposed last-4 and QR codes.

For anyone with a Chick-fil-A One account

  • Reset the Chick-fil-A password. Do not reuse a password used anywhere else.
  • Check recent order and rewards activity on the account.
  • Remove any saved payment methods you don’t need stored.
  • Watch for phishing that uses the loyalty-program details as pretext — names, membership numbers, and QR codes are enough scaffolding for a convincing lure even if the last-4 alone isn’t a fraud vector.

Sources

Confidence, consolidated: June 17-19 attack window and July 13 breach-determination date as-stated by Chick-fil-A; 2,182-Texan count confirmed via state filing, aggregate across all states not disclosed; exposed-field list as-stated in the notification; prior 2022-2023 incident confirmed at 71k+; no CVE, no vendor patch — the exposure is password reuse.

Found this useful? Share it.