
On July 23, 2026, Texas resident Brian Williams filed a class action lawsuit against Chick-fil-A Inc. in the U.S. District Court for the Northern District of Georgia.
The suit alleges the chain failed to secure the personal and payment details of Chick-fil-A One members, leaving them open to an attack built on passwords stolen from somewhere else.
Beach details
Chick-fil-A One is a free rewards program whose members earn points toward free food. Signing up requires consumers to provide personal information, which the data breach that occurred on or about June 17, 2026, allegedly exposed. This includes:
- Names
- Email addresses
- Phone numbers
- Home addresses
- Dates of birth
- The last four digits of stored credit and debit cards
- Chick-fil-A One membership numbers, account balances and mobile pay numbers
Cybercriminals used email addresses and passwords taken from another source and tried them on Chick-fil-A One accounts, the complaint claims, citing news reports. Because many consumers reuse the same email and password, attackers often use this strategy to compromise multiple accounts.
Chick-fil-A allegedly discovered the breach on July 13. However, proposed class action claims it did not notify Chick-fil-A One members until July 20, a delay the suit calls inexcusable.
Legal claims
Williams says he has spent time researching the breach and monitoring his financial statements and claims the exposure stripped value from his personal information and subjected him to a lasting risk of fraud.
The lawsuit brings four claims on behalf of a nationwide class of affected customers:
- Negligence, alleging the company owed reasonable care over the data it collected, including under Federal Trade Commission standards, and breached that duty
- Breach of implied contract, stating consumers handed over personal details with an unspoken promise Chick-fil-A would keep them safe
- Unjust enrichment, claiming Chick-fil-A kept money it saved by underspending on security
- Declaratory judgment, asking the court to rule the company has a legal duty to secure customer data and does not
Williams seeks class certification, compensatory and punitive damages, restitution, disgorgement, attorneys' fees and at least 10 years of credit monitoring for everyone affected. He also wants an order requiring the chain to upgrade its security.
What this means for Chick-fil-A One members
The proposed class covers anyone in the United States whose information the breach compromised, excluding Chick-fil-A's own officers, directors and affiliates.
There is no settlement and no claims process as of filing. Chick-fil-A has not yet answered the complaint in court.
.png)







.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)



