Per Bleeping Computer, the fast-food chain Chick-fil-A is notifying an unknown number of customers about a data breach affecting their Chick-fil-A One accounts, which were targeted in a recent wave of credential stuffing attacks.Chick-fil-A detected suspicious login activity on its website and mobile app between June 17 and June 19, 2026. Attackers used a third-party source of stolen credentials to gain unauthorized access. The compromised information may include customer names, email addresses, membership numbers, mobile pay QR codes, Chick-fil-A credit amounts, and the last four digits of credit/debit card numbers. Birth dates, phone numbers, and addresses could also have been accessed.While the total number of affected customers is undisclosed, 2,182 Texans were impacted, according to information provided to the Texas Attorney General. Chick-fil-A has logged out affected accounts, removed payment methods, and restored account balances and rewards. Customers are advised to change their passwords due to the credential stuffing method used by attackers, which involves reusing stolen login information across multiple platforms to access accounts and steal data.Source: Bleeping Computer
Identity

Chick-fil-A accounts compromised in credential stuffing attacks

(Photo by Justin Sullivan/Getty Images)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



