Chick-fil-A Data Breach Exposes Sensitive Information on Customer Accounts

Published
July 22, 2026
Updated
July 22, 2026
Chick-fil-A Data Breach Exposes Sensitive Information on Customer Accounts
Chick-fil-A
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Chick-fil-A Inc., the largest quick-service chicken restaurant chain in the United States, has disclosed a data breach that affected customer accounts on its Chick-fil-A One platform in June 2026. The breach has impacted at least 39 Massachusetts residents, 2,182 Texas residents and two Vermont residents.

Chick-fil-A recently identified suspicious login activity on certain Chick-fil-A One accounts. Upon discovering this activity, the company took steps to prevent any further unauthorized access and began an investigation into the incident.

The company determined that unauthorized parties launched an automated attack against the Chick-fil-A website and mobile application between June 17 and June 19, 2026. The attackers used account credentials, including email addresses and passwords, that were obtained from a third-party source.

The company's investigation concluded that the unauthorized parties may have accessed personal information stored in affected customers' Chick-fil-A One accounts. The specific information potentially exposed varied depending on what each customer had stored in their account.

The types of personal information that may have been exposed include names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, last four digits of credit or debit card numbers, financial account information and the amount of Chick-fil-A credit on accounts (such as e-gift card balances).

If customers had saved additional details to their accounts, the exposed data may have also included the month and day of their birthday, phone number and address.

Chick-fil-A's response to the breach

The company reset passwords for all affected accounts and directed customers to create new passwords as soon as possible. Chick-fil-A urged customers to choose a strong password that is not easy to guess and that is unique to their Chick-fil-A account. The company specifically recommended not reusing a password from other websites or online services.

Chick-fil-A stated that it continues to enhance its security, monitoring and fraud controls to reduce the risk of any similar incidents in the future. The company also encouraged affected customers to remain vigilant by carefully reviewing their credit reports and account statements to ensure all activity is valid.

Chick-fil-A provided a reference guide with information on ordering free credit reports, placing fraud alerts, requesting security freezes and contacting the Federal Trade Commission. The guide also included contact information for the three major credit bureaus and resources for residents of several states.

Customers with questions about the breach can contact Chick-fil-A's dedicated toll-free line at 888-201-5329, available Monday through Friday from 9 a.m. to 9 p.m. Eastern Time.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Chick-fil-A
Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
Information Types Exposed
  • Chick-fil-A One membership number
  • Financial Account
  • QR code
  • Address
  • Amount of Chick-fil-A credit
  • Email address
  • Last four digits of credit/debit card number
  • Mobile pay number
  • Month and
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image