Chick-fil-A is alerting customers in 10 states and the District of Columbia after a cyberattack gave hackers potential access to some Chick-fil-A One loyalty accounts, the company confirmed this week.
The Georgia-based fast-food chain said it detected suspicious login activity and determined that between Friday and Sunday, unauthorized parties carried out an automated “credential-stuffing” attack against its website and mobile app, using usernames and passwords obtained from a third-party source. On July 13, the company concluded the attackers may have accessed information in the affected accounts.
According to a notification letter filed with the Massachusetts attorney general’s office, the exposed data may include customers’ names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes, the last four digits of payment card numbers, and Chick-fil-A gift card balances. Customers who had saved additional details to their accounts may have also had their birth month and day, phone number and address exposed.
Chick-fil-A said it forced affected users to log out, stripped stored payment methods from breached accounts and reset their passwords on the company’s end, while restoring loyalty balances and adding rewards to affected accounts as a gesture of goodwill.
“Chick-fil-A continues to enhance its security, monitoring, and fraud controls” to guard against future incidents, the company said. The company is now urging those customers to set a new, unique password rather than reusing one from another site, and to monitor bank statements, credit card activity and credit reports for signs of fraud.
The scope of the breach remains unclear nationwide, though BleepingComputer reported the company told Texas regulators the incident affected 2,182 Texas residents. The chain disclosed a similar breach in 2023 that compromised more than 71,000 customer accounts following a monthslong credential-stuffing campaign.
Beyond Texas, Chick-fil-A sent notification letters to residents of the District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont.
This article was constructed with the assistance of artificial intelligence and published by a member of The Washington Times' AI News Desk team. The contents of this report are based solely on The Washington Times' original reporting, wire services, and/or other sources cited within the report. For more information, please read our AI policy or contact Steve Fink, Director of Artificial Intelligence, at sfink@washingtontimes.com
The Washington Times AI Ethics Newsroom Committee can be reached at aispotlight@washingtontimes.com.

Please read our comment policy before commenting.