Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
ID: f939498b-7db7-5abe-b1bc-487701e4482c
STIX ID: report--f939498b-7db7-5abe-b1bc-487701e4482c
Feed Name: GBHackers
## Executive Summary Chick-fil-A confirmed a credential-stuffing data breach affecting Chick-fil-A One loyalty accounts (unauthorized activity June 17–19, 2026). Attackers used externally obtained credentials to perform large-scale automated logins, exposing personal data (names, emails, membership numbers, QR codes, stored balances, last four payment digits and, for some users, DOB, phone numbers, and addresses). Chick-fil-A reset passwords, terminated sessions, removed saved payment methods, and restored compromised balances; the exposed data increases risk of account takeover, phishing, and fraudulent redemption of loyalty funds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
