Chick-fil-A Loyalty Accounts Hijacked Using Stolen Passwords
Chick-fil-A Loyalty Accounts Hijacked Using Stolen Passwords 🚨
Fast-food chain Chick-fil-A is warning customers after attackers hijacked loyalty accounts using stolen passwords in a credential stuffing attack. Chick-fil-A detected suspicious login activity against some Chick-fil-A One accounts in June and launched an investigation. The company concluded that unauthorized parties ran an automated credential stuffing attack against its website and mobile app between June 17 and June 19, 2026, using usernames and passwords obtained from previous data breaches or other third-party sources.
Chick-fil-A reset passwords and ended active sessions for affected accounts while investigating the incident.
What is Credential Stuffing? 🤔
Credential stuffing is an attack where criminals take username-password pairs stolen from one service and automatically try them on many other websites and apps to see where they still work. Because many people reuse passwords, attackers often gain access to accounts without ever breaking into the company’s systems in the traditional sense. Cybercriminals obtain large lists of breached credentials from previous data breaches, dark web markets, or public dumps. They use automated tools to fire those credentials at login endpoints for popular services like retailers, banks, and loyalty programs. They then take over accounts where the credentials still work, siphoning off stored value, personal data, or loyalty rewards, or reselling the access to other criminals.
What Information Was Compromised? 🔍
According to Chick-fil-A’s breach notifications, the attackers may have accessed a combination of:
- Name and email address
- Chick-fil-A One membership number and mobile pay number
- QR codes associated with the account
- Balance of any Chick-fil-A credit, such as gift cards or rewards on the account
- Last four digits of the stored credit or debit card number
If customers saved more details in their Chick-fil-A One account, attackers may also have seen:
- Birthdate (month and day)
- Phone number
- Physical address
What Should You Do? ⚠️
If you have or suspect you had a Chick-fil-A One account, you should act even if you haven’t received a letter. Customers should set a new, unique password for their Chick-fil-A One account that they do not use anywhere else. If you’ve used the same password elsewhere, change it on those accounts too. If you cannot log in because your account was locked or reset, follow Chick-fil-A’s recovery process. Additionally, turn on multi-factor authentication (MFA) if you haven’t already, as Chick-fil-A supports MFA for Chick-fil-A One accounts using a verified mobile phone number. Finally, be aware that attackers can use the exposed data to craft more convincing phishing messages and scams.