Chick-fil- hit by cyberattack
Incident
Summary
Hide ▲
Show ▼
The Chick-fil-A account breach exposed customer data after a credential-stuffing attack hit its website and mobile app, and the company said at least 2,182 Texans were affected. Unauthorized parties used stolen credentials between June 17 and June 19, 2026, then the company determined on July 13, 2026 that account information may have been accessed. The exposed data included names, email addresses, membership numbers, QR codes, Chick-fil-A credit amounts, and the last four digits of payment cards. Chick-fil-A logged out impacted accounts, removed payment methods, restored balances, and told users to change passwords.
Timeline
-
22.07.2026 09:40 2 articles · 1h ago
Chick-fil-A determines unauthorized parties may have accessed Chick-fil-A One account data
Initial DisclosureChick-fil-A said that after investigating suspicious login activity to certain Chick-fil-A One accounts, it determined on July 13, 2026 that unauthorized parties may have accessed account information after launching an automated attack against its website and mobile application between June 17 and June 19, 2026 using credentials obtained from a third-party source. The exposed data could include names, email addresses, Chick-fil-A One membership numbers and mobile pay numbers, QR codes, the amount of Chick-fil-A credit, and the last four digits of credit or debit cards; Chick-fil-A logged out impacted accounts, removed payment methods, restored account balances, added rewards, and advised affected users to change their passwords.
Show sources
- Chick-fil-A discloses data breach after credential stuffing attacks — www.bleepingcomputer.com — 22.07.2026 09:40
- Chick-fil-A discloses data breach after credential stuffing attacks — www.bleepingcomputer.com — 22.07.2026 09:40