Credential stuffing attack at Chick-fil-A comes with data breach notice for customers

Alina BÎZGĂ

July 22, 2026

Credential stuffing attack at Chick-fil-A comes with data breach notice for customers

Chick-fil-A is notifying customers after cybercriminals gained access to some Chick-fil-A One loyalty accounts in a credential stuffing attack last month.

Key takeaways

  • Chick-fil-A is notifying customers after attackers accessed some Chick-fil-A One accounts in a credential stuffing attack.
  • Criminals used usernames and passwords stolen from previous breaches rather than hack Chick-fil-A directly.
  • Exposed information may include names, email addresses, membership details, rewards balances, payment information, and other personal data stored in affected accounts.
  • The incident is a reminder that using the same password on multiple services can put many online accounts at risk.
  • Monitoring your exposed credentials and using unique passwords can help prevent future account takeovers.

According to the company, attackers used login credentials obtained from a third-party source between June 17 and June 19, 2026 to attempt automated logins against the company's website and mobile app. The suspicious activity was later investigated, and on July 13 Chick-fil-A determined that unauthorized parties may have accessed customer information stored in affected accounts.

“We recently identified suspicious login activity to certain Chick-fil-A One accounts”, the notice reads. “Upon discovery of this activity, Chick-fil-A immediately took steps to prevent any further unauthorized activity and began an investigation. Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source. Based on our investigation, we determined on July 13, 2026 that the unauthorized parties may have accessed information in your Chick-fil-A One account.”

What information was exposed?

Depending on what customers stored in their accounts, the restaurant chain says attackers may have accessed:

  • Names
  • Email addresses
  • Chick-fil-A One membership numbers
  • Mobile pay numbers
  • QR codes
  • Rewards balances and Chick-fil-A credit
  • The last four digits of linked payment cards

If available in affected accounts, attackers may also have viewed:

  • Phone numbers
  • Birth dates
  • Mailing addresses

The company has not said how many customers were affected overall, although filings with the Texas Attorney General indicate that 2,182 Texas residents were impacted. Notification letters have also been sent to residents in several other states in the US including Iowa, Maryland, Massachusetts, Columbia, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont.

It’s important to note that Chick-fil-A says the attackers did not obtain customer passwords from its own systems.

Instead, criminals used credentials stolen during previous breaches elsewhere and tested them against Chick-fil-A accounts.

This technique, known as credential stuffing, continues to be a successful form of account takeover because many people still use the same password across multiple websites.

If a password from an old shopping site, forum, or social media account is leaked, criminals immediately try that same email and password combination on banking apps, streaming services, airline accounts, loyalty programs, retailers, and food delivery platforms.

Sometimes they only need one login to succeed.

If you want to read more on how cybercriminals can compromise your online accounts, check out this article on account takeover attacks:

What Is Account Takeover (ATO) And How to Protect Against It
Explore how ATO attacks work, how to identify them and learn good online practices you can adopt to protect your data, identity, and finances.

Why loyalty accounts are increasingly attractive to cybercriminals

Restaurant loyalty accounts may not seem valuable at first glance, but they often contain much more than reward points.

Many include saved payment methods, billing information, personal details, and digital wallets that can be abused before the legitimate owner notices anything unusual.

Even when payment card numbers aren't fully exposed, criminals can steal rewards, place fraudulent orders, collect personal information for future phishing campaigns, or combine the stolen data with information from other breaches to build more complete identity profiles.

This isn't the first time Chick-fil-A has faced this type of attack. In 2023, the company disclosed that more than 71,000 customer accounts were compromised in a similar credential stuffing campaign that allowed attackers to access personal information and spend stored rewards balances.

What Chick-fil-A is doing

Following the incident, Chick-fil-A says it has:

  • Logged affected users out of their accounts
  • Removed stored payment methods
  • Restored compromised rewards balances
  • Added bonus rewards for affected customers
  • Advised impacted users to reset their passwords

How to protect yourself after a credential stuffing attack

Even if you don't have a Chick-fil-A account, credential stuffing affects anyone who reuses passwords.

To reduce your risk:

  • Change the password for your Chick-fil-A account immediately, even if you did not receive a notification.
  • If you've reused that password anywhere else, change it there too.
  • Use a unique password for every online account. If you find creating unique strong passwords for every online account, consider using a free password generator or opt for a paid and trustworthy password manager in a standalone or all-in-one security suite like Bitdefender Premium Security.
  • Enable multi-factor authentication whenever it's available.
  • Review your Chick-fil-A account for unauthorized orders, changes to your profile, or missing rewards.
  • Check your bank and credit card statements for transactions you don't recognize.
  • Monitor your credit reports for unfamiliar accounts or suspicious activity, especially if your personal information was stored in your Chick-fil-A account.
  • Be cautious of follow-up phishing emails, texts, or phone calls claiming to be from Chick-fil-A or offering compensation for the breach. You can use free AI-powered scam detection tools like Bitdefender Scamio to verify any kind of unsolicited communication, QR codes, texts or emails for signs of fraud.

Why monitoring for exposed credentials matters

Credential stuffing attacks usually begin long before criminals target a company like Chick-fil-A. The stolen usernames and passwords often come from breaches that took place months or even years earlier. That's why it's important to know when your personal information appears in a newly discovered breach.

Bitdefender Digital Identity Protection continuously monitors whether your email addresses, passwords, and other personal information have been exposed in known data breaches. It also alerts you when your credentials appear online, helps you understand which accounts are at risk, and provides clear recommendations so you can secure them before attackers reuse that information in credential stuffing attacks.

When combined with unique passwords and multi-factor authentication, monitoring your digital identity can significantly reduce the chances of an old breach leading to a new account takeover.

tags


Author


Alina BÎZGĂ

Alina is a history buff passionate about cybersecurity and anything sci-fi, advocating Bitdefender technologies and solutions. She spends most of her time between her two feline friends and traveling.

View all posts

You might also like

Bookmarks


loader