- Chick-fil-A is notifying customers across the country about a cyberattack that occurred between June 17 and June 19, 2026, targeting its website and mobile application.
- Hackers accessed Chick-fil-A One accounts using credentials obtained from a separate third-party breach, with an internal investigation confirming the breach on July 13.
- The exposed data includes customer names, email and home addresses, phone numbers, birth dates, Chick-fil-A One account details such as membership numbers and mobile pay IDs, reward balances, gift card credits, and the last four digits of saved payment cards.
- While the total number of affected customers nationally has not been released, state filings indicate 2,182 residents in Texas and 39 in Massachusetts were impacted, with notification letters also sent to regulators in several other states.
- In response, Chick-fil-A forced log-outs, reset customer passwords, removed saved payment methods, restored stolen account balances, and added bonus rewards to affected accounts, while advising customers to create unique passwords.
IN FULL
Chick-fil-A warns customers in its reward program their data might have been stolen