logo

Chick-fil-A Confirms Customer Data Accessed in Cyberattack

ID: 143c6b39-6bf5-593e-be00-6ef2fd39c8d6

STIX ID: report--143c6b39-6bf5-593e-be00-6ef2fd39c8d6

Feed Name: The Cyber Express

Threat Score
50/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Samiksha Jain

...
...

Chick-fil-A disclosed an automated credential-stuffing attack on its website and mobile app between June 17–19, 2026, using credentials obtained from a third-party source; unauthorized parties may have accessed Chick-fil-A One account data (names, emails, membership numbers, QR codes, last four of payment cards, account balances, and potentially phone numbers, addresses, and birthdays). The company forced logouts, reset passwords, removed stored payment methods, restored affected balances, notified customers, and said it is enhancing security and fraud monitoring while urging customers to change passwords and watch for fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.