Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
Chick-fil-A Confirms Data Breach After Credential Stuffing (TL-2026-1654), also tracked as Chick-fil-A One Credential Stuffing Breach (2026), is a high-severity data breach, first published 2026-07-23. It has no confirmed attribution, affects Chick-fil-A, Inc. Chick-fil-A One (loyalty/rewards and mobile-ordering, maps to 18 MITRE ATT&CK techniques (T1071.001, T1074, T1078), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-1654
- Threat ID
- TL-2026-1654
- Also known as
- Chick-fil-A One Credential Stuffing Breach (2026), Chick-fil-A Loyalty Account Takeover Incident
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-07-23
- Last reviewed
- 2026-07-23
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- food service, quick-service restaurant, hospitality, retail, consumer loyalty programs
- Target regions
- united states of america, Texas, Massachusetts, District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Chick-fil-A Confirms Data Breach After Credential Stuffing
Malware and tooling: unattributed automated credential-stuffing tooling
Chick-fil-A confirmed a credential-stuffing account-takeover campaign against its Chick-fil-A One loyalty platform (web and mobile app) between June 17-19, 2026, discovered July 13, 2026. Attackers used username/password pairs sourced from unrelated third-party breaches to log into customer accounts, exposing names, emails, membership numbers, Mobile Pay numbers/QR codes, loyalty balances, partial payment-card numbers, and in some cases dates of birth, phone numbers, and addresses.
How Chick-fil-A Confirms Data Breach After Credential Stuffing works
On July 22-23, 2026, Chick-fil-A, Inc. began notifying customers and multiple U.S. state attorneys general of a data breach affecting Chick-fil-A One, the company's loyalty and mobile-ordering platform. According to the notifications, unauthorized parties conducted an automated credential-stuffing campaign between June 17 and June 19, 2026, using username/password combinations harvested from prior, unrelated third-party data breaches to attempt logins against Chick-fil-A's website and mobile application. Because the credentials were valid due to password reuse rather than any direct compromise of Chick-fil-A's own systems, a subset of login attempts succeeded, granting attackers access to legitimate customer accounts.
Chick-fil-A determined on July 13, 2026 that customer account information may have been viewed or acquired during the unauthorized access window. Exposed data varies by account and may include the customer's name, email address, Chick-fil-A One membership number, Mobile Pay number and account QR code, remaining loyalty/gift balance, and the last four digits of any payment card stored on the account. For accounts where the customer had voluntarily supplied additional profile data, date of birth, phone number, and residential address may also have been exposed. Chick-fil-A states it does not store full payment-card numbers, CVVs, or bank account credentials, limiting the direct financial-fraud exposure to card-present/card-not-present fraud using the exposed last-four digits in combination with other identity data (i.e., social-engineering/identity-verification bypass rather than direct card cloning).
Remediation actions taken by Chick-fil-A include forcibly logging out all impacted accounts, requiring password resets, removing stored payment methods from affected accounts, restoring any drained loyalty/gift balances, and issuing rewards credits to affected customers. The company has recommended customers set a new, unique password not reused elsewhere and enable multi-factor authentication via a verified mobile number.
Regulatory breach notifications filed to date confirm at least 2,182 Texas residents and 39 Massachusetts residents affected, with additional notifications sent to the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont. Chick-fil-A has not disclosed a nationwide total. No CVE, exploited software vulnerability, or named threat actor/malware family has been identified — this is a pure credential-stuffing/account-takeover (ATO) campaign exploiting password reuse, not an exploit of a Chick-fil-A application flaw.
This is the second publicly disclosed credential-stuffing incident against Chick-fil-A One: in March 2023, the company confirmed a similar campaign that compromised more than 71,000 customer accounts between December 2022 and February 2023, indicating the loyalty platform remains a recurring target for ATO actors monetizing stolen-credential lists against high-value consumer loyalty/payment ecosystems.
MITRE ATT&CK techniques used in TL-2026-1654
Command and Control
T1071.001 Web Protocols; T1090 Proxy
Collection
T1074 Data Staged; T1119 Automated Collection; T1213 Data from Information Repositories
Initial Access
Defense Evasion
Discovery
Credential Access
T1110 Brute Force; T1110.004 Credential Stuffing
Impact
T1531 Account Access Removal; T1657 Financial Theft
Resource Development
T1586 Compromise Accounts; T1588.005 Exploits; T1650 Acquire Access
Reconnaissance
T1589 Gather Victim Identity Information; T1589.001 Credentials; T1592 Gather Victim Host Information; T1595.002 Vulnerability Scanning
Affected products and versions in Chick-fil-A Confirms Data Breach After Credential Stuffing
- Chick-fil-A, Inc. — Chick-fil-A One (loyalty/rewards and mobile-ordering platform)
Vulnerable versions: Chick-fil-A One website member portal; Chick-fil-A One mobile application (iOS/Android)
Remediation for Chick-fil-A Confirms Data Breach After Credential Stuffing
Immediate actions
- Force password reset and terminate all active sessions for affected Chick-fil-A One accounts
- Remove stored payment methods from accounts flagged for unauthorized access
- Restore any depleted loyalty/gift balances and issue compensating rewards credit
- Notify affected customers and required state attorneys general per applicable breach-notification statutes
- Instruct customers to set a new, unique password not reused on any other site or app
Workarounds
- Customers should review Chick-fil-A One account activity and linked payment methods for unrecognized changes
- Customers should enable available MFA and avoid reusing the same password across loyalty/rewards platforms
Longer-term hardening
- Deploy bot-detection / web application firewall (WAF) controls tuned to credential-stuffing patterns (high-volume distinct-account login attempts, low per-account attempt velocity, headless-browser/automation fingerprints)
- Implement leaked-credential monitoring to proactively force resets when customer email/password pairs appear in third-party breach corpora
- Enforce mandatory or strongly-incentivized multi-factor authentication (SMS/authenticator) for loyalty and payment-linked accounts
- Add device fingerprinting and impossible-travel / anomalous-login velocity detection to the authentication pipeline
- Rate-limit and CAPTCHA-gate authentication endpoints on both web portal and mobile API
- Tokenize or reduce retained payment-card metadata (avoid storing even last-four digits where not operationally required)
Weaknesses (CWE) in Chick-fil-A Confirms Data Breach After Credential Stuffing
CWE-307, CWE-620, CWE-521, CWE-522
Timeline of Chick-fil-A Confirms Data Breach After Credential Stuffing
- Prior, separate Chick-fil-A One credential-stuffing campaign begins (disclosed March 2023), ultimately compromising more than 71,000 customer accounts.
- Prior 2022-2023 Chick-fil-A One credential-stuffing campaign window closes.
- Chick-fil-A publicly confirms the earlier credential-stuffing campaign affecting 71,000+ accounts, establishing the loyalty platform as a recurring ATO target.
- Unauthorized credential-stuffing login attempts against Chick-fil-A One website and mobile app begin.
- Credential-stuffing attack window against Chick-fil-A One closes.
- Chick-fil-A determines that customer account information may have been viewed or acquired during the June 17-19 unauthorized access window.
- Chick-fil-A terminates active sessions, forces password resets, removes stored payment methods, restores balances, and issues rewards credits for affected accounts.
- Chick-fil-A begins notifying affected customers and files breach notifications with multiple U.S. state attorneys general (TX: 2,182; MA: 39; plus DC, IA, MD, NM, NY, NC, OR, RI, VT).
- Breach becomes widely reported in security and consumer media (GBHackers, BleepingComputer, Malwarebytes, Forbes, and others).
Sources cited for Chick-fil-A Confirms Data Breach After Credential Stuffing
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
- Chick-fil-A discloses data breach after credential stuffing attacks
- Chick-fil-A loyalty accounts hijacked using stolen passwords
- Chick-fil-A Sends Data Breach Notifications After Password Attacks
- Chick-fil-A hit by credential stuffing attack exposing customer data
- Chick-fil-A One Data Breach: Credential Stuffing Hits Loyalty App a Second Time
- Chick-fil-A data breach hits loyalty app accounts in June attack
- Chick-fil-A reveals data breach in rewards program
- Chick-fil-A Data Breach Hits Customers After Credential Stuffing
Threats related to Chick-fil-A Confirms Data Breach After Credential Stuffing
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000
- Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the Claims
- SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claims
- ZeroBytes Breaches French Tax Authority (DGFiP): Stolen Credentials and MFA Bypass Expose Tax Data of 678,438 Taxpayers and Businesses
- "TheHatman" Azure/Entra Directory Exfiltration Campaign Exposes Millions of Employee Records at McDonald's, Vodafone, Kyndryl, TCS, HCL and Others
- Argentine Football Association (AFA) Breached via Year-Old Infostealer Credential Compromise — "All Egyptian Cyber Warriors"
Detection coverage for TL-2026-1654
As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1654 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.