
Chick-fil-A
Chick-fil-A is urging some customers to reset their passwords after discovering hackers gained unauthorized access to Chick-fil-A One loyalty accounts in an automated credential stuffing attack.
The company said the incident affected certain customer accounts between June 17 and June 19, 2026, with attackers using email addresses and passwords obtained from a third-party source rather than breaching its own systems.
Following an investigation, Chick-fil-A determined on July 13 that unauthorized parties may have accessed information stored within affected rewards accounts. Customers have since begun receiving data breach notification letters detailing what happened and what information may have been exposed.
What information was accessed in the Chick-fil-A hack?
According to the notification, attackers may have accessed customers’ names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, the last four digits of linked credit or debit cards, and the balance of any store credit or gift cards on the account.
If customers had saved additional information to their profiles, hackers may also have accessed the month and day of birth, phone number, and mailing address.
Chick-fil-A said the attack involved stolen login credentials that had been obtained elsewhere, allowing attackers to sign into accounts using valid usernames and passwords.

Wikipedia CommonsPeople absolutely love the fast food chain’s chicken sandwiches.
“We recently identified suspicious login activity to certain Chick-fil-A One accounts,” the company said.
“Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source.”
What Chick-fil-A is doing next
The company said it immediately forced affected users to log out of their accounts, removed stored payment methods, restored impacted Chick-fil-A One balances, and reset passwords for affected customers.

Costco customers “perplexed” by sauce for new food court item

Restaurant blasts customers for “stealing” over viral dine-and-dash videos
“We have reset your Chick-fil-A password. Please update your Chick-fil-A password as soon as possible,” the company wrote, encouraging users to create a strong, unique password that is not used on other websites or services.
Chick-fil-A also said it is continuing to strengthen its security, monitoring, and fraud controls to reduce the risk of similar incidents in the future.
Customers who received the notification are also being encouraged to monitor their financial accounts and credit reports for any suspicious activity.
The security incident comes as Chick-fil-A continues expanding beyond its traditional restaurants.
Back in 2025, the chain announced plans to launch Daybright, a standalone concept focused on specialty drinks, smoothies, and coffee that won’t serve its signature chicken sandwiches or waffle fries as it explores new ways to grow the brand.