American fast-food chain Chick-fil-A disclosed on July 22, 2026 that attackers used credential stuffing to break into Chick-fil-A One loyalty accounts during a three-day window in mid-June.
Credential stuffing is the boring breach that never goes away: bots spray username/password pairs stolen from older leaks against a rewards app, and any account that reused a password becomes a miniature data breach of its own.
What happened
According to notification letters summarized by BleepingComputer, Chick-fil-A spotted suspicious logins, investigated, and determined unauthorized parties launched automated attacks against its website and mobile app between June 17 and June 19, 2026, using email/password pairs from a third-party breach source. On July 13, 2026, Chick-fil-A concluded attackers may have accessed data inside compromised Chick-fil-A One accounts.
What data was exposed
Per the company’s Massachusetts sample notice, exposed fields can include names, email addresses, Chick-fil-A One membership and mobile-pay numbers, QR codes, stored reward balances, and the last four digits of saved payment cards. Birth dates, phone numbers, and addresses are in scope if the victim stored them in the profile.
A Maine Attorney General filing shared with BleepingComputer lists 13,322 people affected nationwide. Texas reported 2,182 residents affected; letters also went to Iowa, DC, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
What was not exposed
Chick-fil-A emphasized attackers could only view masked card data—the last four digits—not full payment card numbers or CVV codes. That limits direct card fraud but not social engineering using membership numbers and email addresses.
Not the 2023 incident
Chick-fil-A previously disclosed that more than 71,000 accounts were compromised in a separate credential-stuffing campaign between December 2022 and February 2023. The June 2026 wave is a new event with fresh regulator filings—not a belated re-notification of the older case.
What Chick-fil-A did
The company logged out impacted accounts, removed stored payment methods, restored Chick-fil-A One balances, and added bonus rewards as an apology. Those are good containment steps, but they do not fix the root cause: password reuse across the internet.
Action items
- Change your Chick-fil-A password—and every other site where you reused it.
- Use a password manager and unique credentials for food-delivery and loyalty apps.
- Watch for phishing pretending to be “free nuggets” breach compensation.
- Review stored payment methods in the app even if only last-four digits leaked.
Canonical record
Full entry: Chick-fil-A credential stuffing June 2026. Sources: BleepingComputer, Massachusetts AG sample notice.