Chick-fil-A warns customers following data breach in 10 states

Customer names, account details and payment info potentially compromised in cyberattack

Chick-fil-A warns customers after hackers access loyalty accounts and potentially expose personal data, payment details, and rewards. | ©Image Credit: Chick-fil-A
Chick-fil-A warns customers after hackers access loyalty accounts and potentially expose personal data, payment details, and rewards. | ©Image Credit: Chick-fil-A

Getting your weekly chicken fix may have just opened the door to digital identity theft. Chick-fil-A has issued an urgent warning to customers across 10 states after a cyberattack exposed sensitive account details, stored payment info, and rewards balances. If you’ve used the chain’s popular app to order meals recently, your personal data could already be sitting on hacker forums — and skipping a few immediate account-protection steps right now could end up costing you far more than the price of a combo meal.

Chick-fil-A’s loyalty program under fire

What began as a routine summer weekend for fast-food lovers turned into a digital security nightmare after Chick-fil-A fell victim to a coordinated cyberattack targeting its popular Chick-fil-A One loyalty program.

According to a formal filing with the Massachusetts Attorney General’s Office, automated systems detected a wave of suspicious login activity spanning three days, from June 17 through June 19, 2026. Perpetrators executed a classic “credential-stuffing” campaign — using stolen username and password combinations harvested from previous, unrelated third-party data leaks to break into customer accounts across both the company’s website and mobile application.

What sensitive information was exposed?

While the fast-food giant clarified that full credit card numbers were not compromised, intruders managed to scrape a troubling amount of sensitive, highly personalized data. Depending on what users stored in their profiles, the exposed information includes:

  • Basic Identity Data: Full names, primary email addresses, phone numbers, and home addresses.
  • Account-Specific Identifiers: Loyalty membership numbers, internal mobile pay IDs, personal QR codes, and saved birthdates.
  • Financial and Loyalty Assets: Remaining Chick-fil-A store credit, gift card balances, and the last four digits of linked payment cards.

The Chick-fil-A data breach affected customers across 10 states — including Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont, and Texas — as well as the federal district of Washington, D.C.

How Chick-fil-A responded to the cyberattack

As news of the breach broke, Chick-fil-A moved quickly to reassure its customer base while acknowledging the breach’s scope.

“Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted,” a Chick-fil-A spokesperson said. “We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day.”

To stem the damage, security teams immediately initiated a series of hard resets across the platform. Affected users were forcibly logged out, all saved payment methods were scrubbed from their profiles, passwords were forcibly reset, and any stolen rewards or account balances were fully restored — accompanied by bonus rewards as an apology for the hassle.

What you need to do

The threat extends far beyond missing chicken points. Security experts warn that credentials exposed in this attack could be used to target users on other platforms if they reuse passwords. Here are the steps affected customers should take immediately:

  1. Update Password: Choose a strong, unique password for your Chick-fil-A account and avoid reusing the same credentials across multiple websites.
  2. Monitor Statements: Watch bank account and credit card statements closely for unauthorized charges — especially on cards previously linked to the app.
  3. Protect Your Credit: Consider placing a temporary fraud alert or security freeze on your credit reports through the major credit bureaus (Equifax, Experian, and TransUnion) to prevent identity theft.

Source:
LiveNOW from FOX