
Nearly 15,000 individuals were affected after a data security incident at Chick-fil-A last month compromised sensitive personal information.
In a data security incident notice filed with the Massachusetts Attorney General’s Office, Chick-fil-A said it recently identified suspicious login activity involving certain Chick-fil-A One accounts. The company launched an investigation with external cybersecurity experts, secured affected systems, and notified law enforcement authorities.
“Following a careful investigation, we determined that unauthorised parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source.
“Based on our investigation, we determined on July 13, 2026 that the unauthorised parties may have accessed information in your Chick-fil-A One account,” the company said in its filing.
The compromised data included names, dates of birth, addresses, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, last four digits of credit/debit card numbers, and Chick-fil-A e-gift card balance details.
The incident was reported to regulators in Maine, where Chick-fil-A said that 13,322 individuals were affected. The company also reported that the breach impacted 2,182 Texas residents and 39 Massachusetts residents.
“As soon as Chick-fil-A discovered the incident, we immediately took action to protect customers’ accounts, which included forcing log-outs of affected accounts and removing any stored payment methods.
“We also restored impacted customers’ Chick-fil-A One account balances. As an additional way to say thank you for being a loyal Chick-fil-A customer, we have added rewards to your account.
“Chick-fil-A continues to enhance its security, monitoring, and fraud controls as appropriate to minimise the risk of any similar incident in the future,” Chick-fil-A added.
At the time of publication, no known threat group had claimed responsibility for the cyber attack targeting Chick-fil-A. The fast-food chain has also not disclosed details about the attackers behind the credential-stuffing campaign or the extent of the data compromised.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543