• 2 min read
Chick-fil-A says hackers breached customer accounts
Chick-fil-A disclosed a credential stuffing attack from June 17–19, 2026 that exposed customer account data and affected at least thousands of users.

Image: TechRadar
Chick-fil-A says attackers accessed customer accounts during a credential stuffing attack that ran from June 17 to June 19, 2026, exposing account information belonging to an unknown number of users.
In a breach notification sent to affected customers, the company said it detected “suspicious login activity” and launched an investigation. That probe found that unidentified attackers used previously stolen username and password combinations to try to break into Chick-fil-A accounts at scale.
According to the company, the exposed data may include:

Recommended reading
Apple patches Hide My Email flaw after a year
- Names
- Email addresses
- Chick-fil-A One membership numbers
- Mobile pay numbers
- QR codes
- The last four digits of payment cards
- Chick-fil-A credit balances
- In some cases, the month and day of birth, phone number, and address
After discovering the incident, Chick-fil-A logged all users out of their accounts, removed stored payment methods, and restored affected customer balances. The company also said it added rewards to some impacted accounts.
The total number of victims has not been disclosed, but the breach appears to affect at least thousands of people. BleepingComputer reported that Chick-fil-A told the Texas Attorney General that 2,182 Texas residents were impacted. Similar notifications were also sent to authorities in Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
Chick-fil-A operates more than 3,000 restaurants across the United States, Canada and Puerto Rico, employs more than 200,000 people, and generated about $10.3 billion in annual revenue in 2025.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechRadar


