TechNewsReel
Live

Chick-fil-A Loyalty Accounts Breached in Credential Stuffing Attack

Second such incident in three years exposes names, payment data, and stored credit balances.

TechNewsReel Newsroom · July 27, 2026

Chick-fil-A confirmed on July 13 that attackers gained access to Chick-fil-A One loyalty accounts during a three-day credential stuffing attack in mid-June, marking the second time in three years the fast-food chain has fallen victim to this type of automated breach.

The attack ran from June 17 to June 19, 2026, with attackers using username and password combinations leaked from unrelated prior breaches to infiltrate accounts through the company's website and mobile app.

What Was Exposed

Compromised data includes full names, email addresses, membership numbers, mobile pay numbers, account QR codes, stored credit balances, and the last four digits of saved payment cards. The exposure of stored credit balances means affected customers face direct financial loss, not just identity theft risk.

Chick-fil-A began notifying affected customers, with 2,182 Texas residents receiving breach notices. Notifications were also sent to residents of Iowa, Washington D.C., Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.

A Repeat Pattern

This incident represents a troubling pattern for the Atlanta-based chain. Between December 18, 2022 and February 12, 2023, Chick-fil-A suffered a nearly identical credential stuffing campaign that affected over 71,000 accounts.

The company offers multi-factor authentication for its loyalty app but does not require it, leaving accounts vulnerable when users reuse passwords across multiple services. Credential stuffing attacks exploit this behavior by automatically testing leaked username-password pairs against target sites until matches are found.

Why It Matters

The breach underscores a broader industry failure: basic automated attacks remain highly effective against major consumer platforms despite years of warnings. Loyalty accounts have become attractive targets because they hold stored financial value, turning what might seem like routine account data into directly monetizable assets for attackers.

For brands, the reputational cost compounds with each repeat incident. For customers, the burden falls on password hygiene practices that security experts have long deemed unsustainable at scale.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.