Chick-fil-A said a security incident may have exposed customer data tied to Chick-fil-A One Loyalty accounts in 10 states after unauthorized parties used stolen login credentials in an automated attack between June 17 and June 19. The company said it detected suspicious login activity, investigated the accounts and later concluded on July 13 that some information may have been accessed.
The company said the hack affected a limited number of loyalty accounts, but the data that may have been exposed reaches beyond basic contact details. It includes names, email addresses, Chick-fil-A One membership numbers, Mobile Pay numbers and QR codes, the last four digits of payment card numbers and Chick-fil-A gift card balances.
For Maryland customer Isabel Maloney, that is enough to change how she sees the app. “It definitely makes me hesitate to get another app like this for sure,” she said, adding that she “probably won’t use it moving forward just after hearing about that.” Her reaction reflects a basic reality of this kind of breach: once account details and payment-linked information are in play, the harm can outlast the incident itself.
The attack used a credential-stuffing method, which means attackers took usernames and passwords obtained from a third-party source and tried them across a website and mobile app to see where they still worked. Dr. Anton Dahbura said that is what makes the scam so effective. “They know about one place, then they try other places to see if they can get in with the same username and password,” he said. He added that attackers are often “collecting pieces of information,” and that the risk grows when those pieces are combined over time.
That is also why the company’s assurance that only a limited number of loyalty accounts were affected does not fully settle the matter. The notification letters describe account-identifying and payment-related details that can be used together in ways customers do not expect, especially when a QR code, a membership number and partial card data are sitting in the same place. Chick-fil-A said it immediately secured and restored impacted accounts and is communicating directly with everyone who may have been affected.
Cyber experts say reused credentials keep this kind of attack common, and Dahbura argued companies need to do more to stop it. “They patiently collect information about you, and pretty soon, they have enough information to do things that can be quite damaging,” he said. For customers, the immediate question is not just whether a password was exposed once, but whether the same login was reused elsewhere before the attack was caught.

