Mark RadarMARK RADAR
EN
Event File FINTECH Personal Data Breaches

Chick-fil-A Says Credential-Stuffing Attack Exposed Customer Data

1 reports · First detected 2026-07-23 · Last active 2026-07-23

Credential stuffing uses automated login attempts built on username-password pairs stolen elsewhere, exploiting consumers who reuse credentials. The attack on Chick-fil-A One is significant because a restaurant loyalty account can combine identity details, stored value, rewards and payment-linked information in one place. Chick-fil-A said the credentials came from a third-party source, distinguishing the incident from a direct theft of passwords from its own systems while still exposing account data after attackers logged in.

Chick-fil-A said attackers accessed some accounts between June 17 and June 19, 2026, and the company determined on July 13 that personal information may have been viewed. Potentially exposed data included names, email addresses, membership and mobile-pay numbers, QR codes, account credit and the final four digits of stored cards; birth dates, phone numbers and addresses were also at risk where saved. Texas reported 2,182 affected residents and Massachusetts 39, while the nationwide total remains undisclosed. Chick-fil-A reset passwords, forced logouts, removed stored payment methods and restored stolen rewards or credit where needed.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)