logo

Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data

ID: f939498b-7db7-5abe-b1bc-487701e4482c

STIX ID: report--f939498b-7db7-5abe-b1bc-487701e4482c

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Divya

...
...

## Executive Summary Chick-fil-A confirmed a credential-stuffing data breach affecting Chick-fil-A One loyalty accounts (unauthorized activity June 17–19, 2026). Attackers used externally obtained credentials to perform large-scale automated logins, exposing personal data (names, emails, membership numbers, QR codes, stored balances, last four payment digits and, for some users, DOB, phone numbers, and addresses). Chick-fil-A reset passwords, terminated sessions, removed saved payment methods, and restored compromised balances; the exposed data increases risk of account takeover, phishing, and fraudulent redemption of loyalty funds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.