News

Chick-fil-A Notifying Customers of Data Breach; Automated Attack Hit Accounts in June, Personal Information May Have Been Exposed

Last Updated on July 24, 2026 3:45 pm

Chick-fil-A is notifying customers that an automated cyberattack compromised certain Chick-fil-A One accounts in June, potentially exposing personal information including names, email addresses, partial credit card numbers, and account balances.

In a letter dated July 20, 2026, the company said unauthorized parties launched an automated attack against its website and mobile application between June 17 and June 19, 2026. The attackers used account credentials — including email addresses and passwords — obtained from a third-party source to attempt to access Chick-fil-A One accounts. Chick-fil-A said it determined on July 13, 2026 that the unauthorized parties may have successfully accessed customer account information.

According to the notification, the information that may have been exposed includes customers' names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, the last four digits of credit or debit card numbers on file, and any Chick-fil-A credit or e-gift card balances. For customers who had additional information stored in their accounts, the exposed data may also include birthdates, phone numbers, and home addresses.

In response, Chick-fil-A said it forced log-outs of affected accounts, removed stored payment methods, and restored Chick-fil-A One account balances that were impacted. The company has also reset passwords for affected accounts and added bonus rewards to impacted customers' accounts.

Customers who received the notification are being urged to reset their Chick-fil-A One password immediately and to choose a strong, unique password not used on other websites or accounts. The company also recommends that customers monitor their credit reports and account statements for any unauthorized activity.

North Carolina residents affected by the breach may contact the North Carolina Attorney General's Office for information about preventing and avoiding identity theft: Consumer Protection Division, 9001 Mail Service Center, Raleigh, NC 27699-9001, (919) 716-6400, ncdoj.gov.

Customers with questions may call Chick-fil-A's dedicated response line at (888) 201-5329, available Monday through Friday, 9 a.m. to 9 p.m. Eastern Time.

The type of attack used — known as credential stuffing — occurs when cybercriminals use large lists of usernames and passwords stolen from other breaches to attempt to log in to accounts on a different platform. The attacks are automated and can target millions of accounts rapidly. Customers who reuse passwords across multiple websites are at highest risk.

Back to top button