Chick-fil-A Says Credential-Stuffing Attack Exposed Customer Data
Credential stuffing uses automated login attempts built on username-password pairs stolen elsewhere, exploiting consumers who reuse credentials. The attack on Chick-fil-A One is significant because a restaurant loyalty account can combine identity details, stored value, rewards and payment-linked information in one place. Chick-fil-A said the credentials came from a third-party source, distinguishing the incident from a direct theft of passwords from its own systems while still exposing account data after attackers logged in.
Chick-fil-A said attackers accessed some accounts between June 17 and June 19, 2026, and the company determined on July 13 that personal information may have been viewed. Potentially exposed data included names, email addresses, membership and mobile-pay numbers, QR codes, account credit and the final four digits of stored cards; birth dates, phone numbers and addresses were also at risk where saved. Texas reported 2,182 affected residents and Massachusetts 39, while the nationwide total remains undisclosed. Chick-fil-A reset passwords, forced logouts, removed stored payment methods and restored stolen rewards or credit where needed.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.