Skip to main content

Chick-fil-A data breach may have exposed customer loyalty info

Chick-fil-A loyalty passwords may have been leaked.

A popular quick-serve chicken restaurant chain is disclosing a June 2026 cyberattack that impacted its loyalty program.

Unauthorized parties launched an automated attack against the Chick-fil-A website and mobile application between June 17-19, 2026, using account credentials such as email addresses and passwords obtained from an unidentified third-party source. Based on the retailer’s investigation, it determined on July 13, 2026, that the intruders may have gained access to information from some customers’ Chick-fil-A One loyalty accounts.

[READ MORE: Verizon: Almost 1,000 digital security breaches hit retailers in 2025]

In a letter dated July 20, 2026, Chick-fil-A sent to customers who may have been affected by the breach, the retailer said personal information including their name, email address, Chick-fil-A One membership number and mobile pay number, QR code, last four digits of their credit/debit card number, and the amount of Chick-fil-A credit on their account. In addition, if saved to the customer’s loyalty account, the information may have included the month and day of their birthday, phone number, and address.

Chick-fil-A said it “immediately took steps to prevent any further unauthorized activity” upon discovering it, which included forcing logouts of affected accounts and removing any stored payment methods. The retailer, which routinely receives top scores in customer satisfaction rankings, also restored impacted customers’ Chick-fil-A One account balances and has added rewards to their accounts.

The retailer has also advised customers to reset their passwords again and has provided customers who may have been affected with a reference guide and a toll-free number they can call for more information.

“Chick-fil-A continues to enhance its security, Chick-fil-A continues to enhance its security, monitoring, and fraud controls as appropriate to minimize the risk of any similar incident in the future,” the retailer said in the letter.

Advertisement - article continues below
Advertisement

The retailer has not publicly announced how many customers may have had their information exposed. But according to Bleeping Computer, Chick-fil-A told the Texas state attorney general that 2,182 Texas residents may have been affected and told the Massachusetts state attorney general that 39 residents of that state may have had information leaked in the breach.

Chick-fil-A also reportedly sent data breach notification letters to consumers living in Iowa, Washington, D.C., Maryland, New Mexico, New York, North Carolina, Oregon, Vermont and Rhode Island. The retailer previously suffered a series of data breaches between December 2022 and February 2023. 

The company has not yet released a public comment. However, in emailed commentary to Chain Store Age, Paul Bischoff, consumer privacy advocate at tech research firm Comparitech, said although this incident was reported as a data breach, Chick-fil-A didn't say hackers infiltrated its network.

"(T)his was a credential stuffing attack," Bischoff said in the email. "Hackers used email and passwords from previous data breaches at other companies to break into Chick-fil-A accounts. Thankfully, none of the compromised personal information poses a direct threat to breach victims' money or identities. They should be on the lookout for targeted phishing emails and other scams."

X
This ad will auto-close in 10 seconds