Chick-fil-A Warns of Account ExposureChick-fil-A Warns of Account ExposureCoverage from CBS News, ConsumerAffairs, and others
00/00/0000
DailyWeekly
Chick-fil-A says attackers used credentials obtained from a third-party source to target Chick-fil-A One accounts through automated login attempts against its website and mobile app between June 17 and June 19, 2026.
The company determined that some accounts may have been accessed, potentially exposing contact details, loyalty and payment-related information, and account balances. Chick-fil-A forced logouts, removed stored payment methods, restored affected balances, and reset passwords while advising customers to update credentials and monitor their accounts.
Looking Back
16 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
Jul 20
Jul 23
Jul 25
Jul 28
Jul 30
Aug 2
Aug 4
History
08/24/2026
The current version adds that affected accounts may have contained additional personal identifiers, including birthdays, phone numbers, and home addresses, and identifies North Carolina regulators as providing guidance. The core incident, remediation, and risk assessment otherwise remain substantially unchanged.
08/02/2026
The update adds a firmer timeline and sharper scale details: Chick-fil-A determined potential account access on July 13, and reporting now ties the incident to specific state filing counts plus Washington, D.C. notices. It also clarifies the affected data set and remediation steps, including restored balances and added rewards.