Chick-fil-A Urges Password Resets After Credential Stuffing Attack

Chick-fil-A has alerted customers to update their Chick-fil-A One account passwords following the detection of unauthorized access to certain loyalty accounts. The breach occurred between June 17 and June 19, 2026, when attackers executed a credential stuffing attack against the company’s website and mobile application.

Credential stuffing involves cybercriminals using automated tools to test large volumes of stolen email and password combinations from previous data breaches, exploiting the common practice of password reuse across multiple platforms. In this instance, the attackers targeted Chick-fil-A One accounts, leading to unauthorized access for customers across ten U.S. states.

In response, Chick-fil-A has taken several measures to secure affected accounts. The company has reset passwords for compromised accounts, logged users out of active sessions, and removed stored payment methods to prevent further unauthorized transactions. Additionally, Chick-fil-A is advising all Chick-fil-A One users, regardless of whether they have received a formal notification, to proactively change their passwords to unique, strong combinations not used elsewhere.

The compromised data may include customer names, email addresses, mobile payment numbers, and partial payment card details associated with Chick-fil-A One accounts. While full card numbers were not confirmed to be stolen, the exposure of partial financial data and personal contact information increases the risk of fraud and targeted phishing attempts.

Chick-fil-A has emphasized that the attack leveraged credentials obtained from unrelated third-party breaches, indicating that the company’s core authentication systems were not directly compromised. This incident marks the second credential stuffing attack affecting Chick-fil-A One accounts, following a previous campaign between 2022 and 2023 that impacted over 70,000 accounts. The recurrence underscores the persistent threat posed by credential stuffing and the critical importance of robust password practices.

To enhance account security, Chick-fil-A recommends that users create unique passwords for their Chick-fil-A One accounts and avoid reusing passwords across different services. Enabling multi-factor authentication (MFA) via a verified mobile phone number is also advised to add an extra layer of protection during the login process.

Customers are encouraged to monitor their Chick-fil-A account activity, as well as bank and credit card statements, for any unauthorized transactions or reward redemptions. Vigilance against phishing emails or SMS messages impersonating Chick-fil-A is crucial, as attackers may exploit the exposed data for social engineering attacks.

This incident highlights the attractiveness of loyalty programs to cybercriminals due to the valuable customer data and stored payment information they contain. It serves as a reminder for both consumers and organizations to prioritize cybersecurity measures, including the use of strong, unique passwords and the implementation of multi-factor authentication, to safeguard personal information against evolving threats.