ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Threat actors target Chick-fil-A website and app in credential stuffing campaign

Chick-fil-A, the American fast-food restaurant chain, recently disclosed a data security incident in which threat actors used credential stuffing attacks to target its website and mobile application.

 

Chick-fil-A is a U.S.-based fast food restaurant chain specialising in chicken sandwiches and other chicken-based items. Headquartered in Atlanta, Georgia, the company operates thousands of restaurants across the United States through a franchise-based business model.

 

In a data security incident notice filed with the Massachusetts Attorney General’s Office, Chick-fil-A said it recently identified suspicious login activity affecting certain Chick-fil-A One accounts. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.

 

“Following a careful investigation, we determined that unauthorised parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source. 

 

“Based on our investigation, we determined on July 13, 2026 that the unauthorised parties may have accessed information in your Chick-fil-A One account,” the company said in its filing.

 

The compromised data included names, dates of birth, addresses, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, last four digits of credit/debit card numbers, and Chick-fil-A e-gift card balance details. 

 

Although the company has reported the incident to regulators in multiple states, including Texas, Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island, the total number of affected individuals has not yet been determined.

 

“As soon as Chick-fil-A discovered the incident, we immediately took action to protect customers’ accounts, which included forcing log-outs of affected accounts and removing any stored payment methods. 

 

“We also restored impacted customers’ Chick-fil-A One account balances. As an additional way to say thank you for being a loyal Chick-fil-A customer, we have added rewards to your account. 

 

“Chick-fil-A continues to enhance its security, monitoring, and fraud controls as appropriate to minimise the risk of any similar incident in the future,” Chick-fil-A added.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543