Thursday, July 23, 2026

Chick-fil-A Cyberattack Potentially Exposes Customer Data

Chick-fil-A confirmed on Wednesday that a recent security breach may have compromised the personal information of a limited number of customer loyalty accounts. The Atlanta-based fast-food chain acted swiftly to secure the affected accounts and inform the customers potentially impacted by this incident.

A spokesperson for Chick-fil-A stated, “We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts.” Upon realising the breach, the company took immediate measures to secure and restore the affected accounts and has been communicating directly with those impacted.

The chain expressed regret for any inconvenience and reaffirmed its commitment to maintaining customer trust. Notification to potentially impacted customers began on Monday following the discovery of suspicious login activity tied to specific Chick-fil-A One accounts.

USA Today reported that unauthorized entities targeted the company’s website and mobile app between June 17 and June 19, allegedly utilising login credentials obtained from a third-party source. The breach has reportedly affected customers in several states, including Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont, and Washington, D.C.

The data potentially compromised includes customers’ names, email addresses, details of Chick-fil-A One memberships, mobile payment information, the last four digits of payment cards, and the amount of Chick-fil-A credit available in their accounts. In response to the breach, Chick-fil-A reset passwords for the affected accounts, restored any impacted loyalty balances, and provided additional rewards to customers. The company has not disclosed the total number of accounts affected.

Read More