• Home
  • Videos
  • Recipes
  • Foodies
  • Quizzes
  • Product Reviews
Home > Uncategorized > Chick-fil-A Is Urging Customers to Change Their Passwords After a Data Breach
Uncategorized

Chick-fil-A Is Urging Customers to Change Their Passwords After a Data Breach

Chick-fil-A pylon sign against a partly cloudy sky.
Sienna Reid
Published August 5, 2026
Chick-fil-A pylon sign against a partly cloudy sky.
Source: Shutterstock

Chick-fil-A is telling customers to update their passwords after a data breach tied to its loyalty program. The company says unauthorized parties ran an automated attack against its website and mobile app between June 17 and June 19, 2026. Chick-fil-A determined on July 13 that certain Chick-fil-A One accounts may have been accessed, and it began notifying affected customers on July 20.

The breach didn’t come from a hack of Chick-fil-A’s own systems. Instead, attackers used email addresses and passwords leaked in a separate, unrelated incident and tested them against Chick-fil-A One accounts, a method known as credential stuffing. Customers who reused a password from another account were the ones exposed, since a stolen login only worked where it had been reused.

As of writing, Chick-fil-A has not released a total count of affected customers. State filings show the breach touched residents in Washington, D.C., Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont. Fox News additionally reported that public filings showed the breach affected 2,182 Texas residents and 39 Massachusetts residents. The company has since reset passwords for compromised accounts, removed stored payment methods, restored account balances and added rewards to the accounts of customers it identified as impacted, according to its notification letter.

How the Attackers Got In

Chick-fil-A One app icon shown on a screen.
Source: Shutterstock

Credential stuffing attacks like this one don’t require breaking into a company’s own systems. Instead, they rely on lists of stolen logins compiled from past, unrelated breaches, sometimes years old, that criminals test automatically across many different websites and apps. That means a password leaked in an old, unrelated breach can still create risk today, especially if it was never changed.

The exposed information varied by account. It may have included customer names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, account QR codes, stored Chick-fil-A credit balances, the last four digits of linked payment cards, birth month and day, phone numbers and saved addresses. Full card numbers, Social Security numbers and bank account details were not among the exposed data.

A Chick-fil-A, Inc. spokesperson told PEOPLE the company identified a security incident that may have affected a limited number of Chick-fil-A One loyalty accounts. “Upon discovering the issue, we took steps to immediately address, secure, and restore accounts, and we are communicating directly with all customers who may have been impacted,” the spokesperson said. The company added that it remains committed to maintaining customer trust.

This Isn’t Chick-fil-A’s First Credential Stuffing Incident

Hex code display with security breach highlighted in red.
Source: Shutterstock

Chick-fil-A dealt with a similar attack before. According to Fox News, the company confirmed in March 2023 that attackers had accessed more than 71,000 customer accounts through a credential stuffing campaign that ran from December 2022 through February 2023. In that earlier incident, attackers accessed personal information and used stored rewards balances in some accounts, similar to the pattern seen in this latest breach.

The company said it is working to prevent a repeat. In its notification letter, Chick-fil-A stated that it is continuing to strengthen its security, account monitoring and fraud controls to help reduce the risk of a similar incident going forward. The chain added that it acted quickly once it noticed suspicious login activity, cutting off further unauthorized access to the affected accounts.

Chick-fil-A’s letter also broke down separate steps for customers by state, from contacting a state Attorney General to obtaining a police report, covering each of the states named in the notice. Requirements like these vary by state, so two people affected by the same breach could receive slightly different guidance based solely on their state, according to the letter.

What Chick-fil-A Customers Should Do Now

Customers seated at a Chick-fil-A dining table.
Source: Shutterstock

Chick-fil-A asked affected customers to create a new password that isn’t used on any other account. Fox News tech journalist Kurt Knutsson, known as CyberGuy, advised doing the same even without a notice, and avoiding minor variations of an old password, since attackers often test those first. Customers can update their password through the official Chick-fil-A app or website, rather than clicking links in unexpected emails.

Chick-fil-A also suggests customers review their account activity, including up to a year of transaction history available in the app, to check for unfamiliar orders or redeemed rewards. The company’s letter further advised reviewing account statements and credit reports, and reporting any errors to card issuers or credit bureaus. Customers can also review their saved phone number and address for unauthorized changes.

For suspected identity theft, Chick-fil-A directed customers to local law enforcement, their state Attorney General, and the Federal Trade Commission, and offered the option to place a fraud alert or credit freeze. The company said it regrets the incident and apologized for the inconvenience, noting customers with questions can call its support line at 888-201-5329, Monday through Friday from 9 a.m. to 9 p.m. ET, or refer to the reference guide included in its notice.

  • Videos
  • Recipes
  • Foodies
  • Quizzes
  • Our Products
  • Product Reviews
  • Recipes
  • Breakfast
  • Lunch
  • Dinner
  • Dessert
  • Snack
  • About Us
  • Contact Us
  • Work With Us
  • Legal
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
Follow Us!
©2025 First Media, All Rights Reserved.

Get AMAZON Prime
Lightning Deals!

Sign up to get the best
Amazon Prime Lightning Deals
delivered your inbox.

    Share
    video

    Choose a
    Platform