Chick-fil-A warns customers their data might have been stolen
A cyberattack on the company's app and website may have exposed names, addresses, and payment details for customers across the U.S.
Chick-fil-A is warning customers that hackers may have stolen their personal information last month. The fast-food company says an automated cyberattack hit its website and mobile app between June 17 and June 19, 2026. Criminals used stolen passwords from another source to try to break into Chick-fil-A One accounts. The company sent letters to customers and government officials on July 20 to let them know what happened.
An internal investigation finished on July 13 found that hackers spent three days trying to log into customer accounts. They did this by using passwords that had already been exposed in a different data breach somewhere else. This type of attack — where criminals reuse stolen passwords from one site to break into another — is called a credential stuffing attack.
The information that may have been stolen includes customer names, email and home addresses, phone numbers, and birthdays. Hackers may have also seen Chick-fil-A One account details like membership numbers, mobile pay IDs, and QR codes. On top of that, they could have viewed reward balances, gift card credits, and the last four digits of saved payment cards.
Chick-fil-A has not said exactly how many customers were affected across the whole country. However, records filed with state governments show that at least 2,182 people in Texas and 39 people in Massachusetts were impacted. The technology news site BleepingComputer was the first to report those numbers.
The company also sent notification letters to officials in Washington, D.C., Maryland, New York, North Carolina, Oregon, Vermont, and other states. This is required by law in many states when a data breach occurs. It helps make sure customers are informed and can take steps to protect themselves.
To help protect affected accounts, Chick-fil-A logged customers out and reset their passwords. The company also removed any saved payment methods and restored any rewards or balances that were taken. As a way to say sorry, Chick-fil-A added bonus rewards to the accounts that were affected.
Customers who need help can call Chick-fil-A's support line at 888-201-5329. The line is available Monday through Friday from 9 a.m. to 9 p.m. Eastern Time. Security experts also suggest using a password manager to help keep track of strong, unique passwords for different accounts.
We regret that this incident occurred and apologize for any inconvenience it may cause you.
Comprehension quiz preview
1. When did the cyberattack on Chick-fil-A's website and app take place?
2. What does the word 'unauthorized' mean as used in this article?
3. Why did Chick-fil-A add bonus rewards to affected customers' accounts?