Read the full article on KETV 7
Chick-fil-A customers in these states may have been part of data breach, company says
Sr Digital Curator
Chick-fil-A loyalty customers in some states are being urged to change their login info after a cyberattack that may have exposed personal data.
In a letter to potentially impacted customers, Chick-fil-A said it identified suspicious login activity to certain Chick-fil-A One accounts, which prompted an investigation.
Advertisement
“We determined that unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials (e.g., email addresses and passwords) obtained from a third-party source,” the letter says. “Based on our investigation, we determined on July 13, 2026 that the unauthorized parties may have accessed information in your Chick-fil-A One account.”
Letters were sent to Chick-fil-A One members in Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont and Washington, D.C.
What information was breached?
The information may have included names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, the last four digits of credit/debit card numbers and remaining credit amounts, if any.
If saved to your Chick-fil-A account, the information may have included the month and day of loyalty members’ birthdays, phone numbers and addresses.
What to do if you’re impacted
In its letters to impacted customers, Chick-fil-A said it forced log-outs of accounts affected by the breach, removed stored payment methods, restored Chick-fil-A One account balances and added rewards to those accounts.
Chick-fil-A also reset passwords for impacted accounts, and customers should update that password as soon as possible. For further instructions, click here.



