What Happened to Chick-fil-A Data Breaches?
Chick-fil-A has experienced two significant data breaches involving its Chick-fil-A One loyalty accounts. The first, affecting over 71,000 accounts, occurred between late 2022 and early 2023, leading to a class-action settlement in October 2023. A more recent credential-stuffing attack in June 2026 compromised customer data in at least 10 states, prompting immediate company action and ongoing customer notifications as of July 2026.
Quick Answer
As of July 22, 2026, Chick-fil-A is actively notifying customers about a recent data breach that occurred between June 17 and June 19, 2026. This incident involved unauthorized parties using credentials obtained from a third-party source to access Chick-fil-A One loyalty accounts, potentially exposing personal information and payment details. The company has taken steps to secure accounts, restore balances, and is advising affected customers to monitor their financial accounts. This follows a previous breach in late 2022/early 2023 that resulted in a class-action settlement.
📊Key Facts
📅Complete Timeline9 events
Start of First Credential Stuffing Attack
Unauthorized parties began an automated 'credential-stuffing' attack targeting Chick-fil-A One accounts, using login information obtained from third-party sources.
End of First Credential Stuffing Attack
The automated attack on Chick-fil-A One accounts concluded, having potentially compromised over 71,000 user accounts.
Class Action Lawsuit Filed
A class-action lawsuit was filed against Chick-fil-A, accusing the company of 'reckless' and 'negligent' cybersecurity practices following the 2022-2023 data breach.
Settlement Reached for First Breach
Chick-fil-A reached a settlement in principle for the class-action lawsuit related to the data breach that affected over 71,000 user accounts. Details of the settlement were not immediately released.
Start of Second Credential Stuffing Attack
Unauthorized parties launched a new automated 'credential-stuffing' attack against Chick-fil-A's website and mobile application, using credentials from a third-party source.
End of Second Credential Stuffing Attack
The automated attack targeting Chick-fil-A One accounts concluded, potentially compromising customer data in multiple states.
Chick-fil-A Confirms Data Access
Following an investigation into suspicious login activity, Chick-fil-A determined that unauthorized parties may have accessed information in affected Chick-fil-A One accounts.
Initial Public Disclosure and Notifications Begin
Chick-fil-A began notifying affected customers and state Attorney General offices about the June 2026 data breach.
Widespread Reporting and Customer Guidance
News outlets widely reported on the 2026 Chick-fil-A data breach, detailing the types of information exposed, affected states, and the company's recommendations for customers to secure their accounts and monitor for fraud.
🔍Deep Dive Analysis
Chick-fil-A, the prominent fast-food chain, has faced two notable data breaches impacting its customer loyalty program, Chick-fil-A One. The first incident, affecting over 71,000 user accounts, took place between December 8, 2022, and February 12, 2023. Attackers utilized an automated 'credential-stuffing' method, employing usernames and passwords acquired from external sources to gain unauthorized access to customer accounts. The compromised data included names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, and the last four digits of payment card numbers. This breach led to a class-action lawsuit, alleging negligence in the company's cybersecurity practices. In October 2023, Chick-fil-A reached a settlement in principle to resolve this class action, though specific details of the settlement were not publicly disclosed at the time.
The more recent and ongoing data breach occurred between June 17 and June 19, 2026. Similar to the previous incident, this was also a 'credential-stuffing' attack where unauthorized parties leveraged login credentials (email addresses and passwords) obtained from a third-party source to access Chick-fil-A One accounts. Chick-fil-A detected suspicious login activity and, following an investigation, determined by July 13, 2026, that information in affected accounts may have been accessed. The potentially exposed data includes customers' names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes, the last four digits of payment card numbers, and Chick-fil-A gift card balances. If customers had stored additional details, their birth month and day, phone number, and address could also have been accessed.
This 2026 breach has impacted customers in at least 10 states and the District of Columbia, including Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont. Specific numbers reported to state authorities include 2,182 residents in Texas and 39 in Massachusetts. In response, Chick-fil-A immediately forced affected customers to log out of their accounts, removed stored payment methods, and restored any impacted Chick-fil-A One balances. The company also added rewards to affected accounts as a gesture of inconvenience and reset passwords, strongly advising users to create strong, unique credentials. Chick-fil-A has stated its commitment to enhancing security, monitoring, and fraud controls to minimize future risks.
As of July 22, 2026, Chick-fil-A is in the process of notifying all potentially impacted customers directly. Cybersecurity experts emphasize that such credential-stuffing attacks highlight the dangers of password reuse across multiple online services. Customers are advised to remain vigilant, monitor their financial accounts and credit reports for any suspicious activity, and consider placing fraud alerts or security freezes. The recent breach may lead to further legal actions, with law firms already investigating potential class-action lawsuits on behalf of affected individuals.
What If...?
Explore alternate histories. What if Chick-fil-A Data Breaches made different choices?