Chick-fil-A data security incident may have exposed personal and account information belonging to customers after unauthorized parties launched an automated attack against the company’s website and mobile application. The incident targeted certain Chick-fil-A One accounts between June 17 and June 19, 2026, using account credentials obtained from a third-party source.
Chick-fil-A said it identified suspicious login activity involving certain Chick-fil-A One accounts and immediately took steps to prevent further unauthorized access. The company launched an investigation and determined on July 13, 2026, that unauthorized parties may have accessed information stored in affected accounts.
The company notified affected customers about the incident and outlined the types of information that may have been involved, along with steps taken to secure accounts and protect customers.
Chick-fil-A Data Security Incident Linked to Automated Attack
According to the notice sent to customers, the Chick-fil-A data security incident involved an automated attack against the company’s website and mobile application. The attackers used account credentials, including email addresses and passwords, that were obtained from a third-party source.
The activity took place over a three-day period between June 17 and June 19. After identifying suspicious login activity, Chick-fil-A moved to prevent additional unauthorized activity and began investigating the incident.
The company said its investigation later determined that unauthorized parties may have accessed information in customers’ Chick-fil-A One accounts.

Chick-fil-A One Accounts May Have Exposed Personal Information
The information potentially accessed in the incident varied depending on what customers had stored in their accounts.
Potentially affected data may have included customers’ names, email addresses, Chick-fil-A One membership numbers and mobile pay numbers. The information may also have included QR codes, the last four digits of credit or debit card numbers, and the amount of Chick-fil-A credit, such as an e-gift card balance, associated with an account.
For customers who had additional information saved to their accounts, the potentially exposed data may also have included the month and day of their birthday, phone number and address.
The company did not state that all listed information was accessed for every affected customer.
Chick-fil-A Resets Passwords and Removes Payment Methods
Following the incident, Chick-fil-A said it took immediate action to protect affected accounts. The measures included forcing log-outs from impacted accounts and removing stored payment methods.
The company also restored the balances of impacted Chick-fil-A One accounts. As an additional measure for affected customers, Chick-fil-A said it added rewards to their accounts.
The company said it continues to enhance its security, monitoring and fraud controls to reduce the risk of similar incidents in the future.
Chick-fil-A Urges Customers to Update Passwords
Chick-fil-A said it has reset the passwords associated with affected accounts and urged customers to update their passwords as soon as possible.
The company recommended that customers choose strong, difficult-to-guess passwords that are unique to their Chick-fil-A accounts and not reused across other websites or online services.
The company also encouraged customers to remain vigilant against potential identity theft and fraud. Customers were advised to review their credit reports and account statements carefully and check for any activity that they do not recognize.
The Chick-fil-A data security incident highlights the risks associated with compromised account credentials being used in automated attacks. While the company said it took steps to secure affected accounts and restore balances, customers are being encouraged to take additional precautions to protect their personal information and online accounts.

