Chick-fil-A Data Breach Exposes Customer Accounts in Credential Stuffing Attack

Chick-fil-A Data Breach Exposes Customer Accounts in Credential Stuffing Attack

First seen 23 Jul 2026, 01:23 UTC BleepingcomputerFeeds.FeedburnerFoxbusinessFox5Atlanta 83% similarity 57.8

Article Content

Browse articles
ThreatCluster

Chick-fil-A has reported a data breach affecting customer accounts due to credential stuffing attacks that occurred between June 17 and June 19, 2026. The attackers accessed accounts using stolen credentials obtained from a third-party source. The compromised data includes names, email addresses, membership numbers, mobile payment details, and the last four digits of credit/debit card numbers. Affected customers were notified, and the company has taken steps to secure accounts by logging out users, removing payment methods, and restoring account balances. The breach has impacted at least 2,182 customers in Texas and others across several states including Massachusetts and Maryland. Chick-fil-A has advised customers to change their passwords and monitor their accounts for suspicious activity.

Key Points: • Chick-fil-A experienced a data breach due to credential stuffing attacks. • Compromised data includes names, email addresses, and payment details. • At least 2,182 customers in Texas were affected, with notifications sent to others across multiple states.

ThreatCluster AI

Timeline

2026-06-17
Credential stuffing attacks began
Attackers targeted Chick-fil-A's website and mobile app using stolen credentials.
BleepingComputer
2026-06-19
Credential stuffing attacks ended
The automated attacks against Chick-fil-A accounts concluded after two days.
BleepingComputer
2026-07-13
Breach discovery
Chick-fil-A confirmed unauthorized access to customer accounts during an investigation.
BleepingComputer
2026-07-22
Public notification of breach
Chick-fil-A notified affected customers and the media about the data breach.
Foxbusiness

Community

Browse all →