Chick-fil-A customers’ information exposed in data breach

Published July 22, 2026 2:48 PM CDT

A Chick-fil-A restaurant is seen on July 05, 2022 in Houston, Texas. (Photo by Brandon Bell/Getty Images)

An internal data breach has exposed information from some certain customers of Chick-fil-A’s loyalty accounts in what the company described as an automated attack on their website and mobile app. 

The fast food chain has begun notifying customers of a security breach, according to a filing with the Massachusetts Attorney General’s Office. 

What we know:

According to the customer notification, the company said suspicious login activity occurred between June 17 and June 19, 2026, when unauthorized parties used email-and-password combinations obtained from a third‑party source to access some customer accounts. 

Dig deeper:

Information accessed may have included customer names, email addresses, loyalty membership numbers, mobile pay numbers, QR codes, the last four digits of stored payment cards and any Chick-fil-A credit on the account. In some cases, birthdays, phone numbers and addresses saved to profiles were also exposed. 

What they're saying:

A Chick-fil-A spokesperson said the company "recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts."

"Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted," the spokesperson said. "We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day."

Why you should care:

The company advised customers to monitor financial accounts and credit reports for signs of fraud and provided guidance on placing fraud alerts or security freezes with credit bureaus. 

Chick-fil-A said it forced log-outs for affected accounts, removed stored payment methods, restored account balances and added rewards for impacted customers. The company also reset passwords and urged users to choose strong, unique credentials.


 

The Source: This story was written with information provided by Chick-fil-A and Commonwealth of Massachusetts. This story was reported from Orlando. 


 

Food and DrinkConsumer