Mark RadarMARK RADAR
About
EN
Sign in
Event File FINTECH Personal Data Breaches

Credential-Stuffing Attack Exposes Data of 13,322 Chick-fil-A Customers

2 reports · First detected 2026-07-23 · Last active 2026-07-27

Chick-fil-A One combines the restaurant chain’s loyalty program with mobile ordering and payments, making compromised accounts potentially valuable to criminals. In a credential-stuffing attack, hackers use automated tools to test email-and-password combinations obtained from third-party sources, often exploiting passwords reused across services. Chick-fil-A said its own password database was not breached, but successful account takeovers could expose stored personal details, payment identifiers and loyalty balances.

The attack targeted Chick-fil-A’s website and mobile app from June 17 to June 19, 2026, and the company determined on July 13 that customer data may have been accessed. A filing with the Maine Attorney General’s Office put the total at 13,322 people. Exposed data could include names, email addresses, membership and Mobile Pay numbers, QR codes, Chick-fil-A credit balances and the last four digits of payment cards, plus phone numbers, addresses and partial birth dates in some accounts. Chick-fil-A forced logouts, reset passwords, removed stored payment methods, restored affected balances and added rewards, without disclosing a cash compensation amount.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)