Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data — Threadlinqs Intelligence
As of 2026-07-23, Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data is a high-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1654 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Chick-fil-A confirmed a credential-stuffing account-takeover campaign against its Chick-fil-A One loyalty platform (web and mobile app) between June 17-19, 2026, discovered July 13, 2026. Attackers
On July 22-23, 2026, Chick-fil-A, Inc. began notifying customers and multiple U.S. state attorneys general of a data breach affecting Chick-fil-A One, the company's loyalty and mobile-ordering platform. According to the notifications, unauthorized parties conducted an automated credential-stuffing campaign between June 17 and June 19, 2026, using username/password combinations harvested from prior, unrelated third-party data breaches to attempt logins against Chick-fil-A's website and mobile application. Because the credentials were valid due to password reuse rather than any direct compromise of Chick-fil-A's own systems, a subset of login attempts succeeded, granting attackers access to legitimate customer accounts.
Chick-fil-A determined on July 13, 2026 that customer account information may have been viewed or acquired during the unauthorized access window. Exposed data varies by account and may include the customer's name, email address, Chick-fil-A One membership number, Mobile Pay number and account QR code, remaining loyalty/gift balance, and the last four digits of any payment card stored on the account. For accounts where the customer had voluntarily supplied additional profile data, date of birth, phone number, and residential address may also have been exposed. Chick-fil-A states it does not store full payment-card numbers, CVVs, or bank account credentials, limiting the direct financial-fraud exposure to card-present/card-not-present fraud using the exposed last-four digits in combination with other identity data (i.e., social-engineering/identity-verification bypass rather than direct card cloning).
Remediation actions taken by Chick-fil-A include forcibly logging out all impacted accounts, requiring password resets, removing stored payment methods from affected accounts, restoring any drained loyalty/gift balances, and issuing rewards credits to affected customers. The company has recommended customers set a new, unique password not reused elsewhere and enable multi-factor authentication via a verified mobile number.
Regulatory breach notifications filed to date confirm at least 2,182 Texas residents and 39 Massachusetts residents affected, with additional notifications sent to the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont. Chick-fil-A has not disclosed a nationwide total. No CVE, exploited software vulnerability, or named threat actor/malware family has been identified — this is a pure credential-stuffing/account-takeover (ATO) campaign exploiting password reuse, not an exploit of a Chick-fil-A application flaw.
This is the second publicly disclosed credential-stuffing incident against Chick-fil-A One: in March 2023, the company confirmed a similar campaign that compromised more than 71,000 customer accounts between December 2022 and February 2023, indicating the loyalty platform remains a recurring target for ATO actors monetizing stolen-credential lists against high-value consumer loyalty/payment ecosystems.
Weaknesses (CWE)
CWE-307, CWE-620, CWE-521, CWE-522
Target sectors: food service, quick-service restaurant, hospitality, retail, consumer loyalty programs
Target regions: united states of america, Texas, Massachusetts, District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1589, T1589.001, T1588.005, T1650, T1078, T1110, T1110.004, T1087, T1213, T1119