Chick-fil-A, a leading American fast-food restaurant chain, has alerted customers about a significant data breach affecting their accounts due to a series of credential stuffing attacks.
As the third largest quick-service restaurant chain in the U.S., Chick-fil-A operates over 3,000 locations and offers catering services across the United States, Canada, Puerto Rico, the United Kingdom, and Singapore.
In a data breach notification submitted to several Attorney General’s offices, Chick-fil-A acknowledged detecting unauthorized login attempts on specific Chick-fil-A One accounts.
During the investigation, Chick-fil-A revealed that attackers targeted both its website and mobile app in June 2026.
“After thorough investigation, we found that from June 17 to June 19, 2026, unauthorized parties executed automated attacks on our platform using account credentials obtained from third-party sources including email addresses and passwords,” the company stated. “We confirmed that on July 13, 2026, unauthorized access to your Chick-fil-A One account may have occurred.”
The breach exposed sensitive customer information, including names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, credit amounts, and the last four digits of credit/debit card numbers. Additionally, if saved on a compromised account, the attacker may have accessed personal details such as date of birth, phone number, and address.
While Chick-fil-A hasn’t disclosed the exact number of compromised accounts during the June credential stuffing attack, it did inform the Texas Attorney General of a data breach affecting 2,182 Texans. The company also notified residents in Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
Credential stuffing attacks involve the use of automated tools to compromise user accounts with stolen username and password pairs, especially effective when users reuse credentials across multiple platforms. These attacks aim to exfiltrate personal and financial information for identity theft or resale to other cybercriminals.
In response to the incident, Chick-fil-A took several measures including logging out affected accounts, removing payment methods, restoring balances on Chick-fil-A One accounts, and offering rewards to impacted users as an apology. The company urged all affected customers to change their passwords immediately.
A spokesperson for Chick-fil-A did not provide immediate comments regarding the number of compromised accounts when contacted by BleepingComputer.
Additionally, in March 2023, Chick-fil-A revealed that more than 71,000 customers’ personal information was accessed, and their stored rewards were misused during earlier credential stuffing attacks occurring from December 2022 to February 2023.
Security teams report that only 54% of successful attacks are documented, with warnings issued for just 14%. The remaining incidents go unnoticed.
Picus’ whitepaper explores how to effectively test SIEM and EDR rules in breach and attack simulations, ensuring threats do not remain undetected.
Source: www.bleepingcomputer.com




