Contained Medium impact Data breach Checked 2d ago

Chick-fil-A One accounts hit by credential stuffing

Chick-fil-A confirmed that a credential stuffing attack broke into Chick-fil-A One loyalty accounts between June 17 and 19, 2026, using passwords stolen from other companies' breaches. More than 13,000 customer accounts were accessed, exposing names, partial payment card numbers, QR codes and reward balances. The company began notifying affected customers in late July. A Texas customer filed a proposed federal class action on July 23, and by early August a law firm was reviewing additional claims for Texas and Massachusetts customers.

Started
Jun 17, 2026
Latest activity
Sep 1, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
United States
Sectors
Retail, Consumers
Scale
more than 13,000 Chick-fil-A One customer accounts nationwide; state filings show at least 2,182 in Texas and 39 in Massachusetts

Current status

Massachusetts's September 1, 2026 breach report still lists 39 affected residents, with no newer report of renewed access, a wider count, or official closure.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Impact

Attackers logged into loyalty accounts using stolen passwords and could see customer names, email addresses, membership numbers, partial card numbers, QR codes, gift card balances, and, for some customers, saved phone numbers, addresses and birth dates; there is no report of funds being stolen from Chick-fil-A itself.

What to do

Chick-fil-A One users should set a unique password for the app and turn on any available multi-factor login option, since this was reused-password abuse, not a hack of Chick-fil-A's own systems.

Timeline

  1. Sep 1, 2026

    Massachusetts published an updated 2026 breach report listing Chick-fil-A with 39 affected residents, the same count reported in August.

    Containedmass.gov
  2. Aug 5, 2026

    Dapeer Law, P.A. said it was reviewing potential legal claims on behalf of Chick-fil-A One customers in Texas and Massachusetts who received breach notifications, though no lawsuit from the firm had been filed.

    Containedfinance.yahoo.com
  3. Aug 3, 2026

    State data-breach notification filings obtained by law firm Dapeer Law showed 2,221 confirmed affected customers in Texas and Massachusetts combined (2,182 in Texas, 39 in Massachusetts), with exposed data varying by state to include names, email addresses, Chick-fil-A One membership numbers, mobile payment information, QR codes, partial card numbers, gift card balances and, for some customers, stored phone numbers, addresses and birth dates.

    Containedcbsnews.com
  4. Jul 23, 2026

    A Texas customer filed a proposed federal class action against Chick-fil-A over the loyalty account breach.

    Containedajc.com
  5. Jul 22, 2026

    Chick-fil-A confirmed the breach and said it was notifying more than 13,000 affected customers.

    Containedscworld.com
  6. Jun 19, 2026

    The credential stuffing attack against Chick-fil-A One accounts ran from June 17 to June 19, 2026.

    Emergingbleepingcomputer.com

Sources

Related reports