Chick-fil-A chicken restaurant showing data breach from credential stuffing attacks

Fast Food Restaurant Chain Chick-fil-A Suffers Data Breach from Credential Stuffing Attacks

American fast food restaurant chain Chick-fil-A has disclosed that a data breach stemming from credential stuffing attacks leaked customer data.

Chick-Fil-A operates more than 3,000 restaurants across the United States, the United Kingdom, Canada, Singapore, and Puerto Rico. The restaurant chain was voted the most favorite fast food chain for 11 consecutive years, until recently, when it dropped behind Jersey Mike’s Subs.

According to data breach notification letters sent to impacted customers, Chick-fil-A learned of the data breach after detecting suspicious login activity across several accounts and launched an investigation.

Chick-Fil-A confirms credential stuffing data breach

The investigation determined that hackers targeted Chick-fil-A’s website and mobile apps through automated attacks between June 17 and June 19, 2026, using account credentials obtained from a third-party source. Credential stuffing attacks specifically affect users who reuse passwords across websites and mobile apps when their login credentials leak.

“The advent of AI powered attacks makes it more important than ever for companies who serve consumers through mobile apps to thwart attempts by attackers to bombard their back end login APIs via automated bots, malicious scripts, or modified apps,” warned Ted Miracco, CEO, Approov. “Automated attacks will only accelerate going forward, so to protect their customers and themselves, security hygiene dictates that servers should only accept requests from genuine, untampered mobile apps that are running on safe devices.”

While the information collected varied by individual, the data breach leaked customers’ names, birth dates, Mobile Pay phone numbers, addresses, email addresses, Chick-fil-A One membership numbers, QR codes, Chick-fil-A credit amounts, and the last four digits of their credit/debit card numbers.

Meanwhile, the fast food restaurant chain has not disclosed the total number of affected individuals. However, data breach notifications filed in Texas and Massachusetts show that 2,182 Texans and 39 Massachusetts residents were affected. Similar data breach notifications were filed in the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont, suggesting that the leak affected at least several thousand individuals.

Chick-fil-A has also responded to the data breach by logging out all accounts affected by the credential stuffing attack, removing payment methods, restoring Chick-fil-A One account balances, apologizing, rewarding the affected customers, and notifying the affected users.

The fast food restaurant chain has also implemented additional security measures and enhanced monitoring to protect personal information and prevent a similar data breach in the future.

“Chick-fil-A continues to enhance its security, monitoring, and fraud controls as appropriate to minimize the risk of any similar incident in the future,” the fast food chain stated.

The fast food restaurant chain also advised impacted customers to reset their passwords to strong, unique, and long passphrases they do not use on other websites and apps to prevent credential stuffing attacks. Similarly, enabling multifactor authentication should prevent hackers from taking over their accounts when their login credentials leak.

Additionally, customers should monitor their financial accounts and credit reports and notify relevant authorities and banking institutions of any suspicious activity.

“First, are we just going to walk past the fact that Chick-fil-A was compromised through a credential stuffing attack?” asked John Strand, Owner, Black Hills Information Security. “There are probably a hundred jokes we could make about that, but the security lesson is much more important.”

“Credential stuffing sits in one of those gray areas that many organizations never fully test. Most companies hiring a penetration testing firm don’t want testers launching credential stuffing attacks against production systems, and in many cases, that’s the right decision. You don’t want a security assessment accidentally accessing legitimate customer accounts, especially in highly regulated industries like financial services, where the legal and compliance risks can be substantial,” added Strand.

Chick-Fil-A previously breached through credential stuffing

Credential stuffing attacks have previously hit Chick-Fil-A, compromising tens of thousands of accounts. In March 2023, Chick-fil-A determined that hackers breached 71,000 customer accounts between December 2022 and February 2023, through credential stuffing, and used their credit balances.

“Following a careful investigation, we determined that unauthorized parties launched an automated attack against our website and mobile application between December 18, 2022, and February 12, 2023, using account credentials (e.g., email addresses and passwords) obtained from a third-party source,” the restaurant chain stated. “Based on our investigation, we determined on February 12, 2023 that the unauthorized parties subsequently accessed information in your Chick-fil-A One account.”

The attackers sold the compromised accounts for prices ranging between $2 and $200, depending on the account balances and linked payment methods.