Chick-fil-A said a Chick-fil-a Loyalty Account Breach may have exposed information in some Chick-fil-A One accounts after an automated credential-stuffing attack ran between June 17 and June 19. The company said it later concluded on July 13 that attackers may have accessed data in affected accounts.
Chick-fil-A One accounts
The incident involved login attempts using usernames and passwords taken from a third-party source. That is the core risk in credential stuffing: one reused password can open an account even when the site itself has not been directly guessed or cracked.
Chick-fil-A said it detected suspicious login activity involving certain customer accounts and launched an investigation. It also said it recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts.
District of Columbia to Vermont
Notification letters went to customers in 10 jurisdictions: the District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont. The same notice covered accounts that may have exposed names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes.
If customers stored more information in their accounts, attackers also may have accessed the month and day they were born, phone number and address. The company forced affected customers to log out and remove stored payment methods while it restored impacted Chick-fil-A One balances.
Payment data
Chick-fil-A said the exposed details also included the last four digits of payment card numbers and Chick-fil-A gift card balances. The company added rewards to affected accounts for the inconvenience.
That leaves a practical split for customers. A person may have only a login issue, or may also need to watch for account activity tied to saved payment details and gift card balances.
Chick-fil-A told customers to reset their passwords immediately and use a strong, unique password that is not used on other websites. It also told them to review account activity, bank and credit card statements, and credit reports for suspicious activity.
The open question is scale. Chick-fil-A said the incident may have affected only a limited number of Chick-fil-A One Loyalty accounts, but its notice still reached customers across 10 jurisdictions and included payment-related data.







