Back to Insights
Breaches5 min read22 July 2026

Chick-fil-A Hit by Second Credential-Stuffing Attack in Three Years, Exposing Loyalty Account Data

Attackers spent three days in June 2026 feeding stolen passwords into Chick-fil-A One login pages, confirming a repeat of the chain's 2023 breach playbook.

t2s
train2secure NewsdeskSecurity awareness team
A close-up photoreal editorial shot of a smartphone lying on a fast-food restaurant table, its screen showing a generic

Chick-fil-A confirmed on July 13, 2026 that criminals accessed customer accounts across its Chick-fil-A One loyalty platform during a three-day automated attack running from June 17 to June 19, 2026.

What Happened and Who Was Affected

The attack relied entirely on credential stuffing. Criminals assembled large lists of email-and-password pairs leaked from unrelated data breaches, then fed them through automated tools pointed at Chick-fil-A's website and mobile app login pages. No zero-day exploits, no custom malware, no insider threat. The method works because a significant portion of users recycle the same password across multiple services.

Chick-fil-A staff detected unusual login activity, launched an investigation, and formally confirmed the breach roughly three weeks after the attack window closed. The company notified the Texas Attorney General that 2,182 Texas residents were affected. Notification letters also went to customers in Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, Rhode Island, and the District of Columbia.

No total headcount for all affected customers across the United States has been published. Chick-fil-A operates more than 3,000 locations across the US, Canada, Puerto Rico, the United Kingdom, and Singapore, giving it a loyalty user base in the tens of millions.

What Data Was Exposed

The exposed fields paint a clear picture of a loyalty account profile. Criminals who successfully authenticated could see:

  • Full name and email address
  • Chick-fil-A One membership number and mobile pay number
  • Account QR code
  • Stored Chick-fil-A credit balance
  • Last four digits of any saved payment card
  • Birth date, phone number, or physical address if the customer had added those details

Full payment card numbers were not listed among the compromised fields. Even so, the combination of name, email, QR code, and stored credit creates real financial exposure, since loyalty balances can be spent immediately at any register.

What Chick-fil-A Did in Response

The company forced a logout of every affected account and removed saved payment methods from those profiles. Customers who had loyalty balances stolen had those funds restored. The chain also deposited bonus reward points into impacted accounts as a goodwill gesture, and it instructed customers to set new, unique passwords.

Those remediation steps are appropriate for the incident scope. They do not, however, address the systemic issue: a login endpoint that can be targeted by automated tooling with enough volume to compromise thousands of accounts over a 72-hour window.

This Is the Second Time

This is not a novel story for Chick-fil-A. In March 2023 the chain disclosed a credential-stuffing campaign that ran from December 2022 through February 2023, affecting more than 71,000 accounts and resulting in drained loyalty balances. The 2026 incident appears narrower in confirmed scope, but the root cause is identical.

Repeating the same attack vector against the same organization three years apart raises a direct question: what bot-mitigation controls were in place, and were they sufficient? The Verizon 2024 Data Breach Investigations Report notes that credential-based attacks remain the top initial access method across industries, accounting for roughly 77 percent of web application breaches. The tooling required for credential stuffing is inexpensive and widely available on criminal forums.

The Control Failures Worth Understanding

Three control gaps are worth naming plainly here.

First, the absence of effective bot mitigation at the login endpoint. A well-tuned implementation of rate limiting, CAPTCHA, device fingerprinting, or behavioral anomaly detection should make credential-stuffing campaigns economically unviable before thousands of accounts are tested. The fact that this attack ran for three full days before staff detected it suggests that either the controls were absent, tuned too loosely, or bypassed by attackers who rotated IP addresses or used residential proxy networks.

Second, the persistence of password reuse across the user base. This is not purely a Chick-fil-A problem; it is an industry-wide reality. But organizations that store financial value in loyalty accounts, such as stored credit balances and payment card tokens, carry an elevated obligation to push users toward stronger authentication. Offering multi-factor authentication is a start. Making it visible, easy to enable, and ideally the default is the next step. NIST Special Publication 800-63B explicitly addresses phishing-resistant authenticators and the risks associated with shared secrets at scale.

Third, and most directly relevant to security-awareness training: users who reused the same password on Chick-fil-A One and some other breached service made this attack possible. Teaching employees and consumers to treat every account as a separate credential is not a compliance checkbox. It is the last line of defense when a company's login page becomes a target.

What Defenders and Customers Should Do Now

For security teams at any organization running a consumer-facing login portal, this incident offers a concrete checklist:

  • Implement adaptive authentication that flags velocity anomalies, impossible travel, and new device logins for step-up verification.
  • Check whether your MFA offering covers loyalty or consumer accounts, not just employee systems.
  • Subscribe to breach intelligence feeds and proactively reset credentials for users whose email-password pairs appear in public dumps.
  • Run tabletop exercises specifically for account-takeover scenarios, not just ransomware.
  • Review bot-detection configurations quarterly, because adversarial tooling evolves fast.

For affected Chick-fil-A One customers, the immediate steps are straightforward: change the account password now, change it everywhere else you used the same one, enable any additional verification the app provides, and monitor card statements for small unfamiliar charges over the next several weeks. Treat any inbound email or SMS claiming to be from Chick-fil-A and asking you to log in via a link with heavy suspicion. Breached customer contact lists are exactly what phishing crews shop for once an account-takeover campaign wraps up.

For organizations that want to close the human-layer gap that credential stuffing exploits, exploring a structured security awareness program is a practical starting point, particularly one that covers password hygiene and phishing recognition together.

Chick-fil-A's experience is a reminder that credential stuffing is not a sophisticated threat. It is a volume play that succeeds when three conditions align: stolen credentials exist in the wild, users have reused those credentials, and the target's login page lacks the controls to stop automated traffic. Remove any one of those conditions and the attack fails. Right now, only one of those conditions sits fully within the target organization's control.

How password-reuse training could have reduced this incident's impact

  • Teach users to create unique passwords for every account, specifically highlighting why loyalty apps with stored financial value are high-value targets.
  • Run phishing simulations that mimic post-breach lure emails, since attackers routinely follow credential-stuffing campaigns with targeted phishing using the freshly verified contact data.
  • Include bot-mitigation and login-security modules in developer and IT awareness tracks so technical teams recognize the signals of an automated attack early.

Train2Secure offers security awareness courses covering password hygiene, phishing recognition, and account-takeover scenarios that organizations can deploy to employees and, in consumer contexts, loyalty program users.

Start free, no card required

Frequently asked questions

What is a credential-stuffing attack and why does it keep working?

Credential stuffing uses automated tools to test email-and-password pairs stolen from previous breaches against a new login page. It works because a large share of users reuse the same password across multiple services. When one service is breached, every other service where that user recycled the password becomes vulnerable.

Was my full credit card number exposed in the Chick-fil-A June 2026 breach?

No. Chick-fil-A stated that only the last four digits of saved payment cards were accessible to attackers. Full card numbers were not among the exposed fields.

How many customers were affected by the June 2026 Chick-fil-A breach?

The company confirmed 2,182 affected residents in Texas and sent notifications to customers in ten additional US states and territories. A total figure covering all affected customers has not been published.

What should I do if I have a Chick-fil-A One account?

Change your Chick-fil-A One password immediately and update it on any other service where you used the same password. Enable multi-factor authentication if the app offers it. Monitor your payment card statement for unfamiliar small charges, and be cautious of any unexpected emails or texts asking you to log in via a link.

Ready to Reduce Your Human Cyber Risk?

Sign up and start training your team in minutes. No sales calls, no demos — just pick a plan and go. Phishing simulations, video courses, and certificates from day one.

train2secure analytics dashboard showing training completion stats and user progress