
Chick-fil-A is notifying customers in 10 states after a cyberattack allowed hackers to potentially access personal information stored in some Chick-fil-A One loyalty accounts.
The Georgia-based fast-food chain said it recently According to Chick-fil-A, the company concluded on July 13 that attackers may have accessed information stored in affected Chick-fil-A One accounts.
What Information May Have Been Exposed?
Data breach notification letters sent to customers in the District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont state that the information potentially accessed includes:
- Customer names
- Email addresses
- Chick-fil-A One membership numbers
- Mobile Pay numbers and QR codes
- The last four digits of payment card numbers
- Chick-fil-A gift card balances
If customers stored additional information in their accounts, hackers also may have accessed:
- Birth month and day
- Phone numbers
- Mailing addresses
The company has not disclosed the total number of customers affected nationwide. However, filings with state attorneys general indicate the breach affected 2,182 Texas residents and 39 Attack Used Stolen Passwords
According to Chick-fil-A, the attackers used a credential-stuffing technique, in which cybercriminals attempt to log into accounts using usernames and passwords stolen from unrelated data breaches.
Credential-stuffing attacks are often successful when customers reuse the same password across multiple websites and services.
The company said there is no indication its own systems were the source of the stolen login credentials.
Company Response
After discovering the unauthorized activity, Chick-fil-A said it took several steps to secure affected accounts, including:
- Forcing impacted users to log out
- Removing stored payment methods
- Restoring affected Chick-fil-A One rewards balances
- Adding bonus rewards to impacted accounts
“We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts,” the company said in a statement, CBS News reported. “Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted.
“We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day.”
The company also said it continues to strengthen its security, monitoring and fraud detection systems to reduce the risk of similar incidents.
What Customers Should Do
Similar Attack in 2023
This is not the first time Chick-fil-A has experienced a credential-stuffing incident.
In 2023, the company disclosed that more than 71,000 customer accounts were compromised after attackers used stolen login credentials during a series of credential-stuffing attacks between December 2022 and February 2023. Attackers in that incident accessed customer information and used stored rewards balances before the accounts were secured.
The latest incident serves as another reminder for consumers to avoid reusing passwords across multiple online accounts and to enable additional security measures whenever available.
Provided by Dallas Express






