Millions of Chick-fil-A fans who rely on the popular Chick-fil-A One loyalty program for mobile orders, rewards, and easy payments should check their inboxes right now. The fast-food chain is warning customers to reset their Chick-fil-A One passwords after hackers accessed some accounts through a credential stuffing attack.
This was not a direct hack of Chick-fil-A’s internal systems. Instead, cybercriminals have made use of credentials hacked from entirely separate third-party data breaches to gain access to accounts on the Chick-fil-A site.
The attempted logins took place between June 17 and June 19, 2026. Chick-fil-A finished their investigation on or about July 13 and began notifying affected individuals in letters sent out between July 20 and July 22. Reports confirm customers across multiple states were impacted, including 2,182 Texas residents.
For impacted Chick-fil-A One accounts, hackers could view names, email addresses, membership numbers, mobile pay numbers, QR codes, gift card balances, and the last four digits of linked payment cards. In some cases, phone numbers, mailing addresses, and month/day of birth were also potentially exposed. Importantly, full payment card numbers were not compromised.
Chick-fil-A explained in its notifications:
“We recently identified suspicious login activity to certain Chick-fil-A One accounts… unauthorized parties launched an automated attack… using account credentials obtained from a third-party source.”
In simple terms, credential stuffing is when attackers take email and password combinations leaked from one site and automatically test them on other websites. It works because many people reuse the same passwords across services. This incident highlights the real risks of password reuse for everyday consumers.
The company initiated forced sign outs on the impacted user accounts, reset passwords, cleared any stored payment cards from the user accounts, corrected any impacted balance issues, and provided additional incentives as well. In addition, the company improved its fraud monitoring efforts. The customers are advised to use unique passwords, monitor their bank accounts and be on the lookout for any phishing attempts. For support, call 1-866-232-2040 (M-Sat 9AM-10PM Eastern time).
According to the security experts, it is best to use password manager to generate and manage unique passwords, turn on multi-factor authentication wherever possible, and check credit report frequently.


