Between June 17 and June 19, 2026, attackers used email-and-password combinations obtained from another source to sign in to Chick-fil-A One accounts through the company’s website and app. Chick-fil-A said its investigation determined on July 13 that some account data had been accessed. If you received a notice—or reused your Chick-fil-A password anywhere else—open the app or website directly, change that password now, and check rewards, orders, and saved payment methods.
This was a credential stuffing attack: automated login attempts using passwords exposed elsewhere. Chick-fil-A’s notice does not say that its internal password database was stolen.
What happened in the 2026 Chick-fil-A account breach
According to the company’s breach notice, attackers tried combinations of email addresses and passwords acquired from a third party. Some combinations worked because customers had reused credentials. Chick-fil-A logged affected customers out of active sessions, removed stored payment methods, and restored rewards and account credit where necessary.
The distinction matters. A credential stuffing incident can expose what is visible inside an account without proving that the service itself lost the password originally. It also means changing only the Chick-fil-A password is insufficient if the same password protects email, banking, shopping, or social accounts.
What information may have been exposed
| Account area | Information described in the notice |
|---|---|
| Identity and membership | Name, email address, Chick-fil-A One membership number, and mobile-pay number. |
| Rewards and account access | Account QR codes, Chick-fil-A credit balance, rewards, and order history visible after login. |
| Payment context | The last four digits of a stored payment card. The notice does not say full card numbers were exposed. |
| Optional profile details | Date of birth, phone number, and mailing address, if the customer had stored them. |
An account QR code or reward balance can be abused even when a full card number is unavailable. Treat unexplained reward redemption, changed profile details, or unfamiliar orders as signs that someone may have entered the account.
How to check whether your account was affected
- Look for a Chick-fil-A notification about the June 17–19 incident, but do not use sign-in links in unexpected email or text messages.
- Open the official app or type
chick-fil-a.comyourself. A forced logout or removed payment method may reflect the company’s containment steps. - Review recent orders, rewards, account credit, profile details, and saved payment methods.
- Check your email account for password-reset messages or Chick-fil-A alerts you did not request.
- If you cannot sign in or see changes you did not make, contact Chick-fil-A CARES through the company’s official support page.
What to do now
- Change the Chick-fil-A One password. Use a new password that you have never used on another site.
- Change every account that reused it. Start with the email account that can reset your other passwords, then banking, payment, shopping, and social accounts. Our guide to creating strong, unique passwords explains a practical setup.
- Turn on multifactor authentication elsewhere. Chick-fil-A One does not currently advertise an MFA control for customer accounts, so the uniqueness of the password matters especially here.
- Remove payment methods you do not need stored. Check card activity, but do not cancel a card solely because its last four digits appeared in the account.
- Document missing rewards or credit. Take screenshots and contact official support before making further changes.
- Watch for follow-up phishing. A message that knows your name, membership details, or partial card digits is not automatically legitimate. Navigate to the service independently.
- Check the scope realistically. The difference between a data breach and a broader data leak determines which credentials and accounts need attention.
FAQ
Was Chick-fil-A’s password database hacked?
The company’s notice attributes the incident to credential stuffing with email-and-password combinations obtained from another source. It does not report theft of Chick-fil-A’s internal password database.
Were full payment card numbers exposed?
The notice lists the last four digits of a stored card, not the full card number. Still review transactions and remove a saved payment method if you no longer need it.
Does changing the Chick-fil-A password protect my other accounts?
No. Any other account using the same or a similar password remains at risk. Change the email account first, then financial and other high-value accounts, using a different password for each.
References
- Chick-fil-A, Inc., consumer data-breach notice filed with the Massachusetts Attorney General, July 2026.
- Chick-fil-A, “Contact CARES,” official customer-support page, accessed July 22, 2026.
- U.S. Federal Trade Commission, “How To Recover Your Hacked Email or Social Media Account,” accessed July 22, 2026.

