The Chick-fil-A data breach has left customers exposed after attackers hijacked Chick-fil-A One accounts using stolen login credentials.
The chain confirmed the incident in breach notification letters filed with multiple state Attorney General offices, including Texas and Massachusetts. Chick-fil-A operates more than 3,000 restaurants across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore.

How the Chick-fil-A Data Breach Happened
Chick-fil-A said unauthorized parties ran an automated credential stuffing attack against its website and app between June 17 and June 19, 2026, using login credentials pulled from an unrelated third-party source. On July 13, 2026, the company determined the attackers may have accessed information in affected Chick-fil-A One accounts.
The exposed data includes the following customer information:
- Names
- Email addresses
- Birth dates
- Phone numbers
- Home addresses
- Chick-fil-A One membership numbers
- Mobile pay numbers
- QR codes
- Remaining credit balances
- Last four digits of stored card numbers
TROYPOINT Tip: Protect your identity and personal info from a data breach by using Aura Identity Theft Protection which is TROYPOINT’s recommended identity theft protection.
Aura Identity Theft Protection Review
Chick-fil-A’s Response
Chick-fil-A told Texas regulators the breach affects 2,182 residents and told Massachusetts regulators it affects 39 residents. The company has not disclosed a nationwide total. Below is their official statement:
“Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source. Based on our investigation, we determined on July 13, 2026 that the unauthorized parties may have accessed information in your Chick-fil-A One account.”
Hide Your Digital Fingerprint

Chick-fil-A logged out impacted accounts, removed saved payment methods, restored account balances, and added rewards as a gesture of apology.
This marks the second time in three years Chick-fil-A accounts have been hit by credential stuffing, following a similar attack that compromised over 71,000 accounts in early 2023.
Chick-fil-A joins a growing list of credential stuffing victims, including Panera Bread, GrubHub, and Dollar Tree.
Final Thoughts
Chick-fil-A’s quick cleanup limited the damage, but the breach shows how little it takes for credentials stolen elsewhere to compromise an unrelated account. Lock down any account holding payment info with a password you don’t use anywhere else.
For more details, refer to the report from BleepingComputer and the official filing with the Massachusetts Attorney General.
We want to know your thoughts. What do you think about this story? Let us know in the comment section below!
Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.




