A Texas law firm is weighing a possible Chick-fil-a Lawsuit after a June cyberattack exposed information tied to Chick-fil-A One loyalty accounts, with state filings pointing to 2,221 affected people in Texas and Massachusetts.
Dapeer Law, P.A. said it is reviewing potential legal claims for account holders who received breach notices after the June incident, a step that puts the company’s response under fresh scrutiny just as customers begin asking what may have been taken and whether a court fight is next.
Chick-fil-A said hackers used usernames and passwords stolen or exposed elsewhere to try to get into customer accounts between June 17 and June 19. The company said it determined on July 13 that attackers may have accessed information in affected accounts, then began notifying impacted customers on July 20. The firm’s review has landed at a moment when that timeline matters: the breach was not just discovered, it was confirmed, notices went out, and now the legal questions are starting to form around what the company did before and after the intrusion.
The information that may have been accessed could include names, email addresses, Chick-fil-A One membership numbers, mobile payment information, QR codes, the last four digits of payment card numbers and gift card balances. For customers who stored the information, it could also include phone numbers, addresses and birth dates. State filings obtained by the law firm indicate 2,182 people were affected in Texas and 39 in Massachusetts, giving the case a defined footprint rather than a vague cyber rumor.
That is where the dispute begins to sharpen. Chick-fil-A said it identified a security incident affecting a limited number of loyalty accounts, secured impacted accounts and notified affected customers. It also said it forced affected users to log out, removed stored payment methods and restored impacted Chick-fil-A One balances. Dapeer Law, by contrast, said it is still evaluating whether Chick-fil-A’s account security measures met legal standards during the credential-stuffing attack, which means the question is not just who was touched by the breach, but whether the company’s defenses were enough under the law.
Chick-fil-A also told affected customers to reset passwords, use a unique password not shared with other websites and monitor Chick-fil-A One accounts, bank accounts and credit card statements for suspicious activity. The investigation does not mean a lawsuit has been filed, and it does not mean the company has been found liable. It does mean the June incident has moved from a cybersecurity problem into a legal review with a countable group of customers, a documented timeline and a decision point still ahead for the Texas firm.
Whether Dapeer Law files suit will decide how far this Chick-fil-a Lawsuit search term goes beyond headlines. For now, the case is still a review, but the numbers, the notices and the account-level details have already made it concrete enough to draw lawyers in.

