Chick-fil-A alerts customers in 10 states after a credential-stuffing cyberattack exposed personal information in loyalty accounts.
Chick-fil-A has notified customers in 10 states that a security incident may have exposed personal information linked to a limited number of Chick-fil-A One loyalty accounts. The Georgia-based fast-food chain identified suspicious login activity between June 17 and June 19, 2026, caused by unauthorized parties using an automated "credential-stuffing" attack. This occurred when hackers used usernames and passwords obtained from third-party sources to access the company's website and mobile app. The affected regions include Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont, and Washington, D.C. Compromised data may include customer names, email addresses, membership numbers, and the last four digits of payment cards. For customers who saved additional details, attackers may have also accessed birth dates, phone numbers, and addresses. Chick-fil-A responded by resetting passwords, ending active sessions, and restoring impacted loyalty balances. The company added rewards to affected accounts to compensate for the inconvenience and urged customers to use unique passwords to prevent future issues.