💼 businessEvent1 views3 min read

What Happened to Chick-fil-A Data Breaches?

Chick-fil-A has experienced two significant data breaches involving its Chick-fil-A One loyalty accounts. The first, affecting over 71,000 accounts, occurred between late 2022 and early 2023, leading to a class-action settlement in October 2023. A more recent credential-stuffing attack in June 2026 compromised customer data in at least 10 states, prompting immediate company action and ongoing customer notifications as of July 2026.

Share:

Quick Answer

As of July 22, 2026, Chick-fil-A is actively notifying customers about a recent data breach that occurred between June 17 and June 19, 2026. This incident involved unauthorized parties using credentials obtained from a third-party source to access Chick-fil-A One loyalty accounts, potentially exposing personal information and payment details. The company has taken steps to secure accounts, restore balances, and is advising affected customers to monitor their financial accounts. This follows a previous breach in late 2022/early 2023 that resulted in a class-action settlement.

📊Key Facts

Accounts affected (2022-2023 breach)
Over 71,000
CBS News, Bleeping Computer
States affected (2026 breach)
10 states + D.C.
CBS News, Bleeping Computer
Texas residents affected (2026 breach)
2,182
Claim Depot, Bleeping Computer
Massachusetts residents affected (2026 breach)
39
Newsweek, Claim Depot
Vermont residents affected (2026 breach)
2
Claim Depot

📅Complete Timeline9 events

1
December 8, 2022Major

Start of First Credential Stuffing Attack

Unauthorized parties began an automated 'credential-stuffing' attack targeting Chick-fil-A One accounts, using login information obtained from third-party sources.

2
February 12, 2023Major

End of First Credential Stuffing Attack

The automated attack on Chick-fil-A One accounts concluded, having potentially compromised over 71,000 user accounts.

3
March 9, 2023Major

Class Action Lawsuit Filed

A class-action lawsuit was filed against Chick-fil-A, accusing the company of 'reckless' and 'negligent' cybersecurity practices following the 2022-2023 data breach.

4
October 26, 2023Critical

Settlement Reached for First Breach

Chick-fil-A reached a settlement in principle for the class-action lawsuit related to the data breach that affected over 71,000 user accounts. Details of the settlement were not immediately released.

5
June 17, 2026Major

Start of Second Credential Stuffing Attack

Unauthorized parties launched a new automated 'credential-stuffing' attack against Chick-fil-A's website and mobile application, using credentials from a third-party source.

6
June 19, 2026Major

End of Second Credential Stuffing Attack

The automated attack targeting Chick-fil-A One accounts concluded, potentially compromising customer data in multiple states.

7
July 13, 2026Critical

Chick-fil-A Confirms Data Access

Following an investigation into suspicious login activity, Chick-fil-A determined that unauthorized parties may have accessed information in affected Chick-fil-A One accounts.

8
July 20, 2026Critical

Initial Public Disclosure and Notifications Begin

Chick-fil-A began notifying affected customers and state Attorney General offices about the June 2026 data breach.

9
July 22, 2026Critical

Widespread Reporting and Customer Guidance

News outlets widely reported on the 2026 Chick-fil-A data breach, detailing the types of information exposed, affected states, and the company's recommendations for customers to secure their accounts and monitor for fraud.

🔍Deep Dive Analysis

Chick-fil-A, the prominent fast-food chain, has faced two notable data breaches impacting its customer loyalty program, Chick-fil-A One. The first incident, affecting over 71,000 user accounts, took place between December 8, 2022, and February 12, 2023. Attackers utilized an automated 'credential-stuffing' method, employing usernames and passwords acquired from external sources to gain unauthorized access to customer accounts. The compromised data included names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, and the last four digits of payment card numbers. This breach led to a class-action lawsuit, alleging negligence in the company's cybersecurity practices. In October 2023, Chick-fil-A reached a settlement in principle to resolve this class action, though specific details of the settlement were not publicly disclosed at the time.

The more recent and ongoing data breach occurred between June 17 and June 19, 2026. Similar to the previous incident, this was also a 'credential-stuffing' attack where unauthorized parties leveraged login credentials (email addresses and passwords) obtained from a third-party source to access Chick-fil-A One accounts. Chick-fil-A detected suspicious login activity and, following an investigation, determined by July 13, 2026, that information in affected accounts may have been accessed. The potentially exposed data includes customers' names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes, the last four digits of payment card numbers, and Chick-fil-A gift card balances. If customers had stored additional details, their birth month and day, phone number, and address could also have been accessed.

This 2026 breach has impacted customers in at least 10 states and the District of Columbia, including Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont. Specific numbers reported to state authorities include 2,182 residents in Texas and 39 in Massachusetts. In response, Chick-fil-A immediately forced affected customers to log out of their accounts, removed stored payment methods, and restored any impacted Chick-fil-A One balances. The company also added rewards to affected accounts as a gesture of inconvenience and reset passwords, strongly advising users to create strong, unique credentials. Chick-fil-A has stated its commitment to enhancing security, monitoring, and fraud controls to minimize future risks.

As of July 22, 2026, Chick-fil-A is in the process of notifying all potentially impacted customers directly. Cybersecurity experts emphasize that such credential-stuffing attacks highlight the dangers of password reuse across multiple online services. Customers are advised to remain vigilant, monitor their financial accounts and credit reports for any suspicious activity, and consider placing fraud alerts or security freezes. The recent breach may lead to further legal actions, with law firms already investigating potential class-action lawsuits on behalf of affected individuals.

What If...?

Explore alternate histories. What if Chick-fil-A Data Breaches made different choices?

Explore Scenarios
Building relationship map...

People Also Ask

What information was exposed in the recent Chick-fil-A data breach (June 2026)?
The recent breach may have exposed customers' names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes, the last four digits of payment card numbers, and Chick-fil-A gift card balances. If stored, birth month/day, phone number, and address were also at risk.
How did the Chick-fil-A data breaches happen?
Both the 2022-2023 and 2026 data breaches were 'credential-stuffing' attacks. This means unauthorized parties used usernames and passwords obtained from a third-party source (not Chick-fil-A directly) to gain access to Chick-fil-A One loyalty accounts.
What has Chick-fil-A done in response to the 2026 breach?
Chick-fil-A forced affected customers to log out, removed stored payment methods, restored impacted Chick-fil-A One balances, and added rewards for inconvenience. They also reset passwords and advised customers to create strong, unique passwords. The company is enhancing its security measures.
Was there a previous Chick-fil-A data breach?
Yes, Chick-fil-A experienced a data breach between December 2022 and February 2023, affecting over 71,000 accounts. This incident also involved a credential-stuffing attack and led to a class-action lawsuit that was settled in principle in October 2023.
What should I do if I think my Chick-fil-A account was affected?
Chick-fil-A advises affected customers to immediately update their passwords to a strong, unique one not used elsewhere. It is also recommended to monitor financial accounts and credit reports for suspicious activity and consider placing fraud alerts or security freezes.