Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data

Chick-fil-A Confirms Data Breach After Credential Stuffing (TL-2026-1654), also tracked as Chick-fil-A One Credential Stuffing Breach (2026), is a high-severity data breach, first published 2026-07-23. It has no confirmed attribution, affects Chick-fil-A, Inc. Chick-fil-A One (loyalty/rewards and mobile-ordering, maps to 18 MITRE ATT&CK techniques (T1071.001, T1074, T1078), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-1654

Threat ID
TL-2026-1654
Also known as
Chick-fil-A One Credential Stuffing Breach (2026), Chick-fil-A Loyalty Account Takeover Incident
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-07-23
Last reviewed
2026-07-23
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
food service, quick-service restaurant, hospitality, retail, consumer loyalty programs
Target regions
united states of america, Texas, Massachusetts, District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont
Detection rules
9
Indicators of compromise
19

Malware and tooling in Chick-fil-A Confirms Data Breach After Credential Stuffing

Malware and tooling: unattributed automated credential-stuffing tooling

Chick-fil-A confirmed a credential-stuffing account-takeover campaign against its Chick-fil-A One loyalty platform (web and mobile app) between June 17-19, 2026, discovered July 13, 2026. Attackers used username/password pairs sourced from unrelated third-party breaches to log into customer accounts, exposing names, emails, membership numbers, Mobile Pay numbers/QR codes, loyalty balances, partial payment-card numbers, and in some cases dates of birth, phone numbers, and addresses.

How Chick-fil-A Confirms Data Breach After Credential Stuffing works

On July 22-23, 2026, Chick-fil-A, Inc. began notifying customers and multiple U.S. state attorneys general of a data breach affecting Chick-fil-A One, the company's loyalty and mobile-ordering platform. According to the notifications, unauthorized parties conducted an automated credential-stuffing campaign between June 17 and June 19, 2026, using username/password combinations harvested from prior, unrelated third-party data breaches to attempt logins against Chick-fil-A's website and mobile application. Because the credentials were valid due to password reuse rather than any direct compromise of Chick-fil-A's own systems, a subset of login attempts succeeded, granting attackers access to legitimate customer accounts.

Chick-fil-A determined on July 13, 2026 that customer account information may have been viewed or acquired during the unauthorized access window. Exposed data varies by account and may include the customer's name, email address, Chick-fil-A One membership number, Mobile Pay number and account QR code, remaining loyalty/gift balance, and the last four digits of any payment card stored on the account. For accounts where the customer had voluntarily supplied additional profile data, date of birth, phone number, and residential address may also have been exposed. Chick-fil-A states it does not store full payment-card numbers, CVVs, or bank account credentials, limiting the direct financial-fraud exposure to card-present/card-not-present fraud using the exposed last-four digits in combination with other identity data (i.e., social-engineering/identity-verification bypass rather than direct card cloning).

Remediation actions taken by Chick-fil-A include forcibly logging out all impacted accounts, requiring password resets, removing stored payment methods from affected accounts, restoring any drained loyalty/gift balances, and issuing rewards credits to affected customers. The company has recommended customers set a new, unique password not reused elsewhere and enable multi-factor authentication via a verified mobile number.

Regulatory breach notifications filed to date confirm at least 2,182 Texas residents and 39 Massachusetts residents affected, with additional notifications sent to the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont. Chick-fil-A has not disclosed a nationwide total. No CVE, exploited software vulnerability, or named threat actor/malware family has been identified — this is a pure credential-stuffing/account-takeover (ATO) campaign exploiting password reuse, not an exploit of a Chick-fil-A application flaw.

This is the second publicly disclosed credential-stuffing incident against Chick-fil-A One: in March 2023, the company confirmed a similar campaign that compromised more than 71,000 customer accounts between December 2022 and February 2023, indicating the loyalty platform remains a recurring target for ATO actors monetizing stolen-credential lists against high-value consumer loyalty/payment ecosystems.

MITRE ATT&CK techniques used in TL-2026-1654

Command and Control

T1071.001 Web Protocols; T1090 Proxy

Collection

T1074 Data Staged; T1119 Automated Collection; T1213 Data from Information Repositories

Initial Access

T1078 Valid Accounts

Defense Evasion

T1078 Valid Accounts

Discovery

T1087 Account Discovery

Credential Access

T1110 Brute Force; T1110.004 Credential Stuffing

Impact

T1531 Account Access Removal; T1657 Financial Theft

Resource Development

T1586 Compromise Accounts; T1588.005 Exploits; T1650 Acquire Access

Reconnaissance

T1589 Gather Victim Identity Information; T1589.001 Credentials; T1592 Gather Victim Host Information; T1595.002 Vulnerability Scanning

Affected products and versions in Chick-fil-A Confirms Data Breach After Credential Stuffing

  • Chick-fil-A, Inc. — Chick-fil-A One (loyalty/rewards and mobile-ordering platform)
    Vulnerable versions: Chick-fil-A One website member portal; Chick-fil-A One mobile application (iOS/Android)

Remediation for Chick-fil-A Confirms Data Breach After Credential Stuffing

Immediate actions

  • Force password reset and terminate all active sessions for affected Chick-fil-A One accounts
  • Remove stored payment methods from accounts flagged for unauthorized access
  • Restore any depleted loyalty/gift balances and issue compensating rewards credit
  • Notify affected customers and required state attorneys general per applicable breach-notification statutes
  • Instruct customers to set a new, unique password not reused on any other site or app

Workarounds

  • Customers should review Chick-fil-A One account activity and linked payment methods for unrecognized changes
  • Customers should enable available MFA and avoid reusing the same password across loyalty/rewards platforms

Longer-term hardening

  • Deploy bot-detection / web application firewall (WAF) controls tuned to credential-stuffing patterns (high-volume distinct-account login attempts, low per-account attempt velocity, headless-browser/automation fingerprints)
  • Implement leaked-credential monitoring to proactively force resets when customer email/password pairs appear in third-party breach corpora
  • Enforce mandatory or strongly-incentivized multi-factor authentication (SMS/authenticator) for loyalty and payment-linked accounts
  • Add device fingerprinting and impossible-travel / anomalous-login velocity detection to the authentication pipeline
  • Rate-limit and CAPTCHA-gate authentication endpoints on both web portal and mobile API
  • Tokenize or reduce retained payment-card metadata (avoid storing even last-four digits where not operationally required)

Weaknesses (CWE) in Chick-fil-A Confirms Data Breach After Credential Stuffing

CWE-307, CWE-620, CWE-521, CWE-522

Timeline of Chick-fil-A Confirms Data Breach After Credential Stuffing

  • Prior, separate Chick-fil-A One credential-stuffing campaign begins (disclosed March 2023), ultimately compromising more than 71,000 customer accounts.
  • Prior 2022-2023 Chick-fil-A One credential-stuffing campaign window closes.
  • Chick-fil-A publicly confirms the earlier credential-stuffing campaign affecting 71,000+ accounts, establishing the loyalty platform as a recurring ATO target.
  • Unauthorized credential-stuffing login attempts against Chick-fil-A One website and mobile app begin.
  • Credential-stuffing attack window against Chick-fil-A One closes.
  • Chick-fil-A determines that customer account information may have been viewed or acquired during the June 17-19 unauthorized access window.
  • Chick-fil-A terminates active sessions, forces password resets, removes stored payment methods, restores balances, and issues rewards credits for affected accounts.
  • Chick-fil-A begins notifying affected customers and files breach notifications with multiple U.S. state attorneys general (TX: 2,182; MA: 39; plus DC, IA, MD, NM, NY, NC, OR, RI, VT).
  • Breach becomes widely reported in security and consumer media (GBHackers, BleepingComputer, Malwarebytes, Forbes, and others).

Sources cited for Chick-fil-A Confirms Data Breach After Credential Stuffing

Threats related to Chick-fil-A Confirms Data Breach After Credential Stuffing

Detection coverage for TL-2026-1654

As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1654 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats