Chick-fil-A accounts hacked via stolen passwords

Published July 22, 2026

Chick-fil-A is telling customers that attackers broke into some Chick-fil-A One rewards accounts using stolen passwords. The attackers could see personal details, mobile pay QR codes, and reward balances, though Chick-fil-A restored the accounts.

Report priority
Medium
Targets
Chick-fil-A One

How it works

Attackers took usernames and passwords stolen from other websites and tried them against Chick-fil-A's login page, a technique called credential stuffing that works whenever someone reuses the same password on multiple sites.

What to do

Chick-fil-A is notifying affected customers directly, and at least 2,182 Texas customers were confirmed impacted according to a filing with the Texas Attorney General, so check your email for a notice from Chick-fil-A and review your Chick-fil-A One account for unfamiliar activity or a missing balance.

Chick-fil-A has logged out affected accounts, removed saved payment methods, and restored balances and rewards, but there is no personal patch beyond changing your Chick-fil-A One password to one you do not use anywhere else and enabling any extra login verification the app offers.

Technical details

An attacker buys or finds a list of stolen email and password pairs from an unrelated data breach. Between June 17 and June 19, 2026, they run those logins against the Chick-fil-A One website and app. Any account that reused one of those passwords lets the attacker in, exposing the customer's name, membership number, mobile pay QR code, and reward balance.

This was a credential stuffing attack, not a breach of Chick-fil-A's own systems. Attackers used a third-party list of previously leaked credentials and automated login attempts against the Chick-fil-A One web and mobile platform. Exposed data included names, emails, membership numbers, mobile pay QR codes, Chick-fil-A credit balances, and the last four digits of stored card numbers, with birth dates, phone numbers, and addresses possibly accessed for some accounts. No full card numbers were reported exposed.