Back to Exposure Report
Retail / Food ServiceJuly 2026United States

Chick-fil-A

No vulnerability was exploited. Attackers logged in with valid credentials — and a loyalty program nobody classified as sensitive turned out to hold dates of birth, addresses and stored value.

Names and email addressesPhysical addressesDates of birthPhone numbersMembership & mobile pay numbersStored credit balancesLast four digits of payment cards
1

What happened?

Chick-fil-A disclosed that unauthorized parties accessed Chick-fil-A One customer accounts through credential stuffing attacks against its website and mobile app between June 17 and June 19, 2026. The attackers used username and password pairs stolen from unrelated third-party breaches.

No Chick-fil-A system was exploited. No vulnerability was involved. Every access used a valid credential that a customer had reused from somewhere else. This is the second such incident for the chain; a 2023 credential stuffing attack affected 71,473 accounts.

2

What data was actually inside?

Accessed accounts exposed customer names, email addresses, physical addresses, dates of birth, and phone numbers where stored. Also exposed: Chick-fil-A One membership numbers, mobile pay numbers and QR codes, the amount of stored Chick-fil-A credit, and the last four digits of saved credit and debit card numbers.

Chick-fil-A has not disclosed the total number of affected accounts. Note what is on that list that has nothing to do with buying chicken: date of birth, home address, and phone number. Those are identity elements, sitting in a marketing system, because the signup form asked for a birthday to send a free sandwich.

3

Who gets hurt and how?

The immediate harm is theft of stored value. Mobile pay numbers and QR codes are bearer instruments — anyone holding the code can spend the balance. Chick-fil-A restored affected credit balances, but customers had to discover the loss first.

The durable harm is the identity set. Name, date of birth, address, phone number, and the last four digits of a card is the exact bundle a call center uses to verify a caller. It does not enable direct financial fraud on its own. It enables the social engineering call that does — to a bank, a mobile carrier, or a healthcare provider. And because the entry vector was password reuse, every affected customer is now confirmed to reuse credentials, which makes them a priority target everywhere else they hold an account.

4

What did they think they were doing right?

The payment path was almost certainly reviewed. Retail security programs are built around PCI DSS, and PCI DSS is very specific about cardholder data. Chick-fil-A stored only the last four digits of card numbers — which is exactly what the standard is designed to produce, and it worked. No full card numbers were exposed.

The assumption underneath is that protecting card data is the same as protecting customer data. It is not. The loyalty platform was in scope for a marketing roadmap and out of scope for the data classification exercise, because loyalty programs are understood as engagement tools. Nobody ran the review that would have asked why a rewards database holds dates of birth.

5

What did they not know about their own data?

A loyalty program accumulates fields the way a junk drawer accumulates objects. Each one was added by a specific campaign for a specific reason — a birthday reward, a delivery pilot, a text-message promotion — and each one was justified in isolation. Nobody ever re-inventories the aggregate.

The result is a system holding regulated personal data under state privacy law, with a security posture set by a marketing team. Chick-fil-A has not disclosed an affected account count, which is itself informative: determining the number requires knowing which accounts were accessed and what each contained. The 2023 incident produced a precise figure of 71,473. That this one has not, yet, suggests the same question is still being answered.

If a single credential in your environment was compromised today, could you say within 24 hours exactly what data was accessed?

6

What does attribution look like the morning after?

Credential stuffing produces a uniquely hard attribution problem. Every access looks like a legitimate login, from a real credential, often through the mobile app. Separating the attacker's sessions from the customer's own requires behavioral analysis of authentication logs across a three-day window and millions of accounts — and the answer determines who gets a letter.

Because dates of birth and addresses were exposed, most state statutes are engaged, including the 30-day notification deadline California introduced under SB 446 effective January 1, 2026. The California AG breach list is where those filings surface. Chick-fil-A's remediation — forcing logouts, stripping stored payment methods, restoring balances, and prompting password resets — is straightforward. Deciding who to send it to is not.

7

What would have changed the outcome?

An inventory that classified the loyalty database by what it actually contains, rather than by what the department that owns it is called.

Credential stuffing cannot be prevented by hardening a perimeter, because it does not cross one. The only variable an organization controls is what a valid session can reach. That question is answerable in advance — but only if someone has enumerated every customer-facing system and the specific data elements behind each. The companies that survive this attack class are not the ones with better firewalls. They are the ones who already knew that the rewards program was holding dates of birth, and moved them before an attacker went looking. Compare the ExfilSquad portal campaign, where the same unclassified-system problem exposed fifteen organizations at once.

Chick-fil-A found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.