Chick-fil-A notified customers after credential stuffing attacks compromised Chick-fil-A One accounts through stolen credentials from a third-party source. The breach may have exposed names, email addresses, membership details, payment-related data, and other personal information for affected users. #ChickfilA #ChickfilAOne
Keypoints
- Chick-fil-A detected suspicious login activity in Chick-fil-A One accounts.
- Attackers used automated credential stuffing against the website and mobile app in June 2026.
- The compromised accounts may have exposed personal, membership, and payment-related information.
- Chick-fil-A reset impacted accounts, removed payment methods, and restored balances.
- The company previously suffered a similar credential stuffing incident in 2023.