Chick-fil-A discloses customer data breach following automated credential stuffing attacks

LowUnited States2026-07-22T00:00:00Z

As per reports, Chick-fil-A issued data breach notification letters to affected customers following automated credential stuffing attacks targeting its website and mobile application between 17 June and Friday 19 June.

Following are the details:

• Unauthorized parties conducted automated login attempts using account credentials obtained from third-party sources to gain access to Chick-fil-A One loyalty accounts.
• Investigations completed on Monday (13 July) confirmed that unauthorized parties accessed stored customer information within affected accounts.
• Potentially exposed information includes names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, Quick Response codes, rewards balances, store credit, dates of birth, phone numbers, addresses, and the last 04 digits of payment cards.
• Chick-fil-A initiated security responses including forced account log-outs, removal of stored payment methods, restoration of account balances, and issuance of bonus rewards to impacted customers.
• The restaurant chain advised affected account holders to update account passwords across the platform and any external services sharing identical login credentials.

Book a Demo

Please enable JavaScript in your browser to complete this form.
Are you using any Analysis tool or had used before ?
LinkedIn, Friends of Friend, etc.