Chick-fil-A data breach affects more than 13,000 customers

Chick-fil-A has revealed that a recent wave of credential stuffing attacks compromised the personal data of over 13,000 customers. The company confirmed that the attackers targeted its website and mobile app between June 17 and June 19, using automated tools and stolen credentials to gain unauthorized access to customer accounts.

The breach affected Chick-fil-A One loyalty program members, with hackers accessing sensitive information such as names, email addresses, account numbers, credit/debit card details, and even birth dates and phone numbers in some cases. The company was alerted to the suspicious activity on June 19 and immediately took steps to address the issue, including logging out impacted accounts, restoring balances, and adding rewards to affected customers.

The compromised data was likely obtained from a third-party source, rather than being directly stolen from Chick-fil-A’s systems. This highlights the ongoing threat of credential stuffing attacks, which rely on hackers using stolen or weak passwords to gain access to sensitive information. By exploiting vulnerabilities in customer credentials, attackers can bypass even robust security measures and compromise entire account ecosystems.

Chick-fil-A has sent data breach notification letters to affected customers in multiple states, including Maine, Texas, Massachusetts, the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island. The company advises impacted customers to change their passwords as soon as possible and monitor their accounts for any suspicious activity.

This incident is not an isolated case for Chick-fil-A. In March 2023, the company disclosed a separate data breach affecting over 71,000 customers, also resulting from credential stuffing attacks between December 2022 and February 2023. The recent breach highlights the ongoing challenge of protecting customer credentials in the face of increasingly sophisticated cyber threats.

The incident serves as a reminder for consumers to be vigilant about their online security, particularly when using loyalty programs or mobile apps that require sensitive information. By taking proactive steps to protect their credentials, such as enabling two-factor authentication and regularly changing passwords, individuals can significantly reduce their risk exposure.

In the aftermath of this breach, Chick-fil-A has taken steps to strengthen its security posture, including adding rewards to affected customers as a gesture of goodwill. While the incident is concerning, it also underscores the importance of robust cybersecurity measures and ongoing vigilance in protecting sensitive customer information.


Source: Bleeping Computer — 2026-07-24