Chick-fil-A Warns of Account Exposure
Coverage from CBS News, ConsumerAffairs, and others
Chick-fil-A says attackers used credentials obtained from a third-party source to target Chick-fil-A One accounts through automated login attempts against its website and mobile app between June 17 and June 19, 2026.
The company determined that some accounts may have been accessed, potentially exposing contact details, loyalty and payment-related information, and account balances. Chick-fil-A forced logouts, removed stored payment methods, restored affected balances, and reset passwords while advising customers to update credentials and monitor their accounts.
The current version adds that affected accounts may have contained additional personal identifiers, including birthdays, phone numbers, and home addresses, and identifies North Carolina regulators as providing guidance. The core incident, remediation, and risk assessment otherwise remain substantially unchanged.
The update adds a firmer timeline and sharper scale details: Chick-fil-A determined potential account access on July 13, and reporting now ties the incident to specific state filing counts plus Washington, D.C. notices. It also clarifies the affected data set and remediation steps, including restored balances and added rewards.
The story has broadened from a multi-state Chick-fil-A loyalty breach into a more clearly documented state-regulatory incident, with Maine now joining Texas and Massachusetts in the reporting trail. The current version also sharpens the exposure description by emphasizing loyalty/payment identifiers and the credential-reuse access path.
The story has shifted from a general account-takeover breach report to a more regulator-backed picture, with Texas and Massachusetts filings adding clearer confirmation of the incident and its scope. The core facts remain the same, but the current version strengthens the case that this was a credential-stuffing event affecting loyalty accounts and partial payment data.
Chick-fil-A says attackers used credentials obtained from a third party to access some Chick-fil-A One accounts through its website and mobile app. Potentially exposed information includes names, email addresses, loyalty identifiers, rewards or payment-related data, and other details stored in accounts; the company forced logouts, removed stored payment methods, restored balances, and urged password changes. The incident matters because reused credentials can enable account takeover and expose personal information held in consumer loyalty platforms.
