2026 Chick-fil-A — credential stuffing Jun 17–19; Maine AG 13,322 Chick-fil-A One accounts
Data compromised
Per company/Maine AG filings: names, emails, Chick-fil-A One membership numbers, rewards balances, mobile pay numbers, last four of stored cards; birth dates, phones, addresses if stored in compromised accounts. Maine AG: 13,322 people nationwide; Texas 2,182; Massachusetts 39.
Technical writeup
Verified company / AG disclosure — attacks June 17–19, 2026; multi-state notices July 2026; Maine AG count published ~July 23 (BleepingComputer). Chick-fil-A detected credential stuffing against website and mobile app using third-party-sourced credentials, compromising Chick-fil-A One loyalty accounts. Maine AG filing shared with BleepingComputer lists 13,322 people affected nationwide; Texas reported 2,182 and Massachusetts 39. Exposed fields include names, emails, membership and mobile-pay numbers, reward balances, card last-four, and optionally DOB/phone/address. Chick-fil-A logged out impacted accounts, removed payment methods, restored balances, added apology rewards, and advised password changes. Distinct from the earlier Dec 2022–Feb 2023 wave (>71,000). BreachHistory indexes 13,322 per Maine AG.
Root cause
Automated credential-stuffing attacks against Chick-fil-A website and mobile app using email/password pairs from a third-party source (Jun 17–19, 2026); confirmed Jul 13, 2026
References
- https://www.bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13-000-customers/
- https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/
- https://www.mass.gov/doc/2026-1188-chick-fil-a-inc/download
- https://www.securityweek.com/over-71k-impacted-by-credential-stuffing-attacks-on-chick-fil-a-accounts/
- https://www.documentcloud.org/documents/28512980-chick-fil-a-data-breach-notice/