
Some Chick‑fil‑A One members got an unwelcome surprise in June when the Atlanta-based chicken giant revealed that outsiders may have slipped into their rewards accounts during a short but aggressive automated attack.
The company says the suspicious activity hit between June 17 and June 19, 2026, targeting its website and mobile app. In response, Chick‑fil‑A logged affected users out of their accounts, stripped out stored payment methods and restored Chick‑fil‑A One balances. The chain also reported the incident to several state authorities and notified impacted customers.
How the attack worked
According to Boston 25, Chick‑fil‑A told regulators that attackers used email-and-password combinations obtained from a third-party source, then fired those credentials at Chick‑fil‑A One accounts in an automated credential‑stuffing attack.
The company says that on July 13 it concluded that unauthorized parties may have accessed information in certain rewards accounts, and it began sending data breach notices to residents in multiple states.
What might have been exposed
Chick‑fil‑A warned that exposed account information could include customers’ names, email addresses, Chick‑fil‑A One membership numbers, mobile‑pay numbers, QR codes, Chick‑fil‑A One card balances and the last four digits of linked credit or debit cards.
If customers had added them to their profiles, month and day of birth, telephone numbers and physical addresses may also have been accessed. Filings with state authorities show that at least 2,182 Texans and 39 Massachusetts residents received notification letters, according to BleepingComputer.
How Chick‑fil‑A responded
The chain says it moved quickly once it spotted the problem. Impacted accounts were logged out, stored payment methods were deleted, and any affected Chick‑fil‑A One balances were restored. Chick‑fil‑A also handed out extra rewards to customers whose accounts were caught up in the incident.
For anyone trying to sort out whether their account was involved, the company has posted guidance and reporting instructions on its support site, per Chick-fil-A.
Why credential‑stuffing keeps working
Security pros have been warning about this playbook for years. In a credential‑stuffing attack, criminals take username-and-password pairs stolen from other data breaches and try them in bulk on different sites and apps, hoping people reused the same login details.
That tactic keeps paying off because, frankly, many users still recycle passwords across multiple services. Chick‑fil‑A ran into a similar automated campaign in early 2023 that affected tens of thousands of accounts, a reminder that rewards apps make tempting targets, as reported by The Atlanta Journal‑Constitution.
What customers should do
If you have a Chick‑fil‑A One account, now is a good time to change your password, avoid reusing it on other sites and keep an eye on your card statements for any odd charges.
Customers who received a notification or suspect something is off can call a dedicated Chick‑fil‑A line at 888‑201‑5329 from 9 a.m. to 9 p.m. ET, Monday through Friday, or use the company’s suspicious‑activity reporting tools, according to Boston 25.









