All Breaches
June 17, 2026 Verified Retail

Chick-fil-A 2026 Data Breach

The Chick-fil-A 2026 data breach resulted from automated credential-stuffing attacks against Chick-fil-A One loyalty accounts between June 17 and June 19, 2026. Company notices and state attorney-general records show that 13,322 people were affected. The attackers used email and password pairs obtained from other sources to access some accounts through the website and mobile application.

After investigating suspicious sign-ins, Chick-fil-A determined on July 13, 2026 that unauthorized parties may have accessed information in customer accounts. The incident does not mean that passwords were stolen from Chick-fil-A systems; attackers tested credentials previously exposed by third parties. It is a separate 2026 event illustrating the risk created by password reuse.

Verified Types of Data

The information varied by individual and may include names, email addresses, Chick-fil-A One membership numbers, mobile-pay numbers, QR codes, loyalty-credit balances, and the last four digits of a stored credit or debit card. A birth date, phone number, and physical address may also have been viewed when those details were saved in the compromised account.

There is no report that complete payment-card numbers or card security codes were exposed. Passwords are also not included as a data class for this incident because the credentials used in the attack came from outside Chick-fil-A. However, successful account access created risks involving loyalty-credit theft, QR-code misuse, profile-data viewing, and changes to account settings.

How Credential Stuffing Worked

Credential stuffing uses automated tools to test email and password pairs leaked by another service across many platforms. If a customer reused the same password for Chick-fil-A One, the attacker could successfully sign in. This method does not require a breach of Chick-fil-A's password database; its main advantage comes from people reusing the same credentials on multiple services.

An attack may also progress through a weak recovery method or an unsecured email account. Affected users should therefore change not only the Chick-fil-A password but every account using the same or a very similar password. The primary email, financial services, shopping accounts, and other loyalty programs should receive priority.

Loyalty Credit and Mobile-Payment Risks

Chick-fil-A One credit and QR codes are loyalty assets with monetary value. Unauthorized access may allow a criminal to spend a balance or misuse mobile-payment identifiers. Chick-fil-A said it signed out impacted accounts, removed stored payment methods, and restored affected Chick-fil-A One balances.

Review credit and reward history in the application, and preserve screenshots and timestamps of unfamiliar use, a new device, or an account change. Change the account password and check email security before adding a payment method again. Someone who knows the final four card digits may impersonate customer service, but that partial information does not verify the caller.

Security Actions to Take Now

Create a long, unique Chick-fil-A One password that is not used anywhere else. Update every account that shared the old password. A password manager makes unique credentials practical to create and store. Enable multi-factor authentication if offered, and prefer an authenticator application or security key where possible.

Review active sessions, recovery addresses, connected applications, and automatic forwarding rules on the primary email account. If an unfamiliar sign-in or password-reset alert appears, close all sessions and change the password from a clean device. Adding a separate PIN to the mobile-carrier account can provide additional protection from phone-number takeover attempts.

Fraudulent Notices and Support Messages

Following disclosure of the incident, criminals may send fake messages saying “restore your balance,” “add your payment method again,” or “verify your account.” Open the Chick-fil-A application yourself or type chick-fil-a.com directly instead of using a message link. Never provide a password, complete card number, or one-time code to an unsolicited contact.

Unexpected messages claiming that the company added rewards to the account may also be used for phishing. Check the complete sender address and domain rather than the display name. Report messages that create urgency, demand an attachment be opened, or request an unusual payment method without replying. Contact customer support only through the official application or website.

How to Interpret a LeakData Match

This record represents the company-confirmed incident affecting 13,322 Chick-fil-A One accounts. No customer rows have been imported into LeakData, so the absence of a result in an email search does not prove that a person received no notice or was unaffected. Customers contacted directly by Chick-fil-A should treat their account as part of the targeted group and take the recommended actions.

Replace reused passwords first, then inspect loyalty credit, reward history, stored payment methods, and the account profile. Report suspicious activity through the official support channel and enable transaction alerts on the card account. This record is distinct from Chick-fil-A's earlier 2022–2023 credential-stuffing incident and covers only the June 2026 attack.

13.3 Thousand
Affected Accounts
10
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

10
Names
Email addresses
Loyalty program membership numbers
Mobile payment numbers
QR codes
Loyalty credit balances
Partial credit card data
Dates of birth
Phone numbers
Physical addresses

Additional Information

Added DateJuly 26, 2026
Breach DateJune 17, 2026
Domainchick-fil-a.com
SourceThird-party breach
Last Content UpdateJuly 26, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information