The record
Written from the 2 reports below. Nothing here is unsourced.
- Chick-fil-A disclosed on June 19, 2026, that a credential stuffing attack compromised over 13,000 Chick-fil-A One customer accounts between June 17 and June 19.
- The attack targeted the company’s website and mobile application, exploiting reused credentials from other breaches.
- In response, Chick-fil-A logged out impacted accounts, removed stored payment methods, and restored points balances.
- Affected customers have been notified and advised to change passwords.
- There is no evidence the breach extended to payment card data or internal systems, but the incident highlights ongoing risks from credential reuse across loyalty programs.
- Watch for any follow-up reports on whether compromised credentials led to fraudulent transactions before detection.
What to watch next
- If you use Chick-fil-A One, change your password now.
- Consider enabling MFA on all retail loyalty accounts.
- Watch for follow-up on fraudulent transaction reports.
What changed2
Every report on this story, newest first. Times are when each outlet published.
BleepingComputer[1]
Chick-fil-A data breach affects more than 13,000 customersBleepingComputer[2]
Chick-fil-A discloses data breach after credential stuffing attacks
Why it matters2
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Chick-fil-A One customers account compromise· immediate
- Chick-fil-A brand reputation damage· weeks
Coverage1
All filed from United StatesSingle origin
Named United States · Chick-fil-A · Chick-fil-A One · District of Columbia · Iowa · Maryland · Massachusetts · New Mexico · New York · North Carolina · Oregon · Rhode Island · Vermont
The 2 reports are listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.

