Fast-food chain Chick-fil-A is notifying an undisclosed number of customers that their online accounts were accessed during a series of credential stuffing attacks targeting the company’s website and mobile application. The company said the attackers used email address and password combinations obtained from external sources rather than exploiting a vulnerability in Chick-fil-A’s own systems.
According to Chick-fil-A, the automated attacks took place between June 17 and June 19, 2026. Following an internal investigation, the company determined on July 13 that unauthorized individuals may have gained access to certain Chick-fil-A One loyalty accounts. Credential stuffing attacks rely on usernames and passwords previously exposed in unrelated data breaches, allowing attackers to compromise accounts when people reuse the same login credentials across multiple online services.
The company said the information accessible to attackers depended on what each customer had stored in their account. Potentially exposed data includes names, email addresses, physical addresses, phone numbers, dates of birth, Chick-fil-A One membership numbers, QR codes associated with customer accounts, stored reward balances, and the last four digits of saved payment cards. Mobile payment identifiers and other account details may also have been visible to unauthorized users. Chick-fil-A said full payment card numbers were not stored in affected accounts.
As part of its response, Chick-fil-A reset passwords for affected accounts, signed impacted users out of existing sessions, removed saved payment methods where appropriate, and restored any loyalty rewards that had been fraudulently redeemed. The company also said it credited affected customers with additional reward points as a goodwill gesture while continuing to review the incident.
The restaurant chain emphasized that the intrusion did not result from a breach of its internal infrastructure. Instead, attackers relied on credentials stolen during unrelated incidents involving other online services. Because credential stuffing depends on password reuse, organizations frequently encourage customers to create unique passwords for every online account and enable multi-factor authentication whenever it is available.
This is not the first time Chick-fil-A has dealt with credential stuffing attacks. In 2023, the company disclosed that more than 71,000 customer accounts had been compromised during a months-long automated campaign that similarly relied on reused usernames and passwords obtained from third-party data breaches.
Chick-fil-A has not disclosed how many customers were affected by the latest incident. The company said it continues to investigate the attacks and is contacting individuals whose accounts may have been accessed. Customers are also being advised to change passwords used on other online services if they were reused for their Chick-fil-A account and to monitor their accounts for any unauthorized activity.