Credential-Stuffing Attack Exposes Data of 13,322 Chick-fil-A Customers
Chick-fil-A One combines the restaurant chain’s loyalty program with mobile ordering and payments, making compromised accounts potentially valuable to criminals. In a credential-stuffing attack, hackers use automated tools to test email-and-password combinations obtained from third-party sources, often exploiting passwords reused across services. Chick-fil-A said its own password database was not breached, but successful account takeovers could expose stored personal details, payment identifiers and loyalty balances.
The attack targeted Chick-fil-A’s website and mobile app from June 17 to June 19, 2026, and the company determined on July 13 that customer data may have been accessed. A filing with the Maine Attorney General’s Office put the total at 13,322 people. Exposed data could include names, email addresses, membership and Mobile Pay numbers, QR codes, Chick-fil-A credit balances and the last four digits of payment cards, plus phone numbers, addresses and partial birth dates in some accounts. Chick-fil-A forced logouts, reset passwords, removed stored payment methods, restored affected balances and added rewards, without disclosing a cash compensation amount.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →