Chick-fil-A data breach hits loyalty rewards accounts

The Chick-fil-A data breach exposed loyalty account details after a credential stuffing attack in June 2026, hitting customers across 10 US states.

The Chick-fil-A data breach has been confirmed, with attackers breaking into a limited number of Chick-fil-A One loyalty accounts between 17 and 19 June 2026 and exposing names, emails and partial payment card details.

The company described the intrusion as a “credential stuffing” attack, as reported by CBS News.

Credential stuffing, sometimes called password stuffing, means the attackers did not crack Chick-fil-A’s own systems; they took usernames and passwords already leaked in unrelated breaches and fired them at Chick-fil-A One, banking on people reusing the same login everywhere.

How the Chick-fil-A data breach actually worked

Because the passwords came from elsewhere, the maths only works when a customer reuses one password across sites.

A login stolen from some forgotten forum in 2019 becomes a working key to a fast-food rewards account in 2026. That reuse is the vulnerability, not any flaw inside Chick-fil-A’s servers.

Credential stuffing has become a favourite because it is cheap and largely automated. Attackers feed billions of leaked login pairs into bots that hammer login pages at scale, and even a success rate below 1% pays off when the input list runs into the hundreds of millions of stolen credentials.

The exposed data went well beyond a name and email. Depending on the account, attackers could see Chick-fil-A One membership and mobile pay numbers, QR codes, account balances, dates of birth, phone numbers, home addresses and the last four digits of a saved payment card.

Who the Chick-fil-A data breach affected

Chick-fil-A has not put a number on it, calling the haul only “a limited number” of accounts. Customers in at least 10 US states were notified, among them New York, Massachusetts and Maryland.

The company framed the incident carefully in its public statement.

A Chick-fil-A spokesperson said:

“We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted.”

What Chick-fil-A did next

In response, Chick-fil-A moved fast on the plumbing. It forced everyone logged out, stripped stored payment methods from accounts, reset passwords itself and restored any balances that had shifted.

Affected customers also received extra loyalty rewards, a small apology baked straight into the app.

The practical takeaway sits with password reuse. Chick-fil-A has already reset the passwords on hit accounts, so the immediate door is shut, yet anyone using that same login on other sites remains exposed until they change it everywhere.

The company says it is contacting every customer who may have been caught up.