top of page

Chick-fil-A Customer Accounts Hacked in Credential Stuffing Attack

  • 2 hours ago
  • 2 min read

Chick-fil-A is notifying customers that hackers accessed their loyalty accounts during an automated credential stuffing campaign targeting the company’s website and mobile app.


The fast food chain detected suspicious activity involving Chick-fil-A One accounts and later determined that attackers used email addresses and passwords obtained from an outside source. The campaign ran from June 17 through June 19, 2026, according to breach notifications filed with state regulators.


“Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source,” Chick-fil-A said.


The attackers may have accessed customer names, email addresses, membership numbers, mobile payment identifiers, account QR codes, rewards balances and the last four digits of stored payment cards. Birth dates, telephone numbers and mailing addresses may also have been exposed when customers had saved that information to their profiles.


Chick-fil-A has not disclosed the total number of affected accounts. Regulatory filings indicate that at least 2,182 Texas residents and 39 Massachusetts residents were impacted. Notifications were also submitted in several other states and Washington, D.C.


Credential stuffing attacks rely on automated tools that test stolen username and password combinations across popular websites and applications. The technique is particularly effective against people who reuse passwords.


“Credential stuffing works because most organizations treat account authentication as a solved problem,” said Seemant Sehgal, founder and CEO of BreachLock. “The credentials used here came from a third-party source, which means Chick-fil-A's own security controls were likely functioning exactly as designed, and the attack succeeded anyway.”


Chick-fil-A logged affected users out of their accounts, removed stored payment methods and restored compromised rewards balances. The company also advised customers to change their passwords.


The incident follows a similar Chick-fil-A credential stuffing campaign disclosed in 2023 that affected more than 71,000 customers.


Ted Miracco, CEO of Approov, warned that AI-powered automation will make these attacks easier to launch at scale. “Automated attacks will only accelerate going forward,” he said, arguing that companies should verify that requests are coming from legitimate, untampered mobile applications.

bottom of page