American fast-food restaurant chain Chick-fil-A has notified an undisclosed variety of prospects a few information breach after their accounts had been hacked in a current wave of credential stuffing assaults.
Chick-fil-A, which payments itself because the third largest quick-service restaurant firm in the US, operates a community of greater than 3,000 eating places and offers catering companies in the US, Canada, Puerto Rico, the UK, and Singapore.
In a knowledge breach notification despatched to affected people and filed with a number of Legal professional Common’s places of work, the corporate stated it detected the assault after figuring out suspicious login exercise on particular Chick-fil-A One accounts.
As Chick-fil-A found whereas investigating the incident, attackers focused Chick-fil-A’s web site and cellular app in June.
“After cautious investigation, we decided that between June 17 and June 19, 2026, an unauthorized third occasion launched an automatic assault towards our web site and cellular software utilizing account credentials (similar to e mail deal with and password) obtained from third-party sources,” the corporate stated. “After investigation, we decided that an unauthorized occasion might have accessed info in your Chick-fil-A One account on July 13, 2026.”
Data uncovered on this breach consists of buyer names, e mail addresses, Chick-fil-A One membership and cellular pay numbers, QR codes, Chick-fil-A credit score quantities, and final 4 digit combos of credit score/debit card numbers. As well as, the attacker might have additionally accessed your date of beginning, telephone quantity, and deal with, if saved on a compromised account.
Chick-fil-A didn’t say what number of prospects had their accounts compromised within the June credential stuffing assault, however advised the Texas legal professional basic that the ensuing information breach affected 2,182 Texans. Chick-fil-A additionally despatched information breach notifications to residents of Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.
In credential stuffing, attackers use automated instruments to compromise consumer accounts with stolen username and password pairs. This tactic is particularly efficient when reusing credentials throughout a number of platforms. The top objective is to steal private and monetary info after taking up an account, which may then be offered to different cybercriminals or used for id theft or different malicious functions.
Following this incident, Chick-fil-A logged out all affected accounts, eliminated fee strategies, restored balances on Chick-fil-A One accounts, and added rewards to affected accounts as a method of apologizing. Accounts had been compromised utilizing stolen credentials, and the restaurant chain suggested affected customers to alter their passwords as quickly as potential.
A Chick-fil-A spokesperson didn’t instantly reply to a request for remark from BleepingComputer on Tuesday in regards to the variety of buyer accounts compromised within the assault.
Chick-fil-A additionally confirmed in March 2023 that menace actors accessed the non-public info of greater than 71,000 prospects and used their saved rewards balances after hacking their accounts in a wave of comparable credential stuffing assaults from December 2022 to February 2023.

Safety groups doc 54% of profitable assaults and difficulty a warning on solely 14%. The remaining strikes invisibly by way of the atmosphere.
Picus’ whitepaper reveals tips on how to take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
