Chick-fil-A Serves Up Another Credential Stuffing Breach: What Password Reuse Reveals About Loyalty Program Risks

Chick-fil-A disclosed a June 2026 credential stuffing breach impacting Chick-fil-A One loyalty accounts across multiple states. Attackers used reused passwords from third-party breaches to access names, partial payment details, addresses and more. The company reset passwords and restored balances. This echoes a prior 2023 incident, highlighting ongoing risks of password reuse.
Chick-fil-A Serves Up Another Credential Stuffing Breach: What Password Reuse Reveals About Loyalty Program Risks
Written by Eric Hastings

Chick-fil-A just notified customers in at least 10 states. Their Chick-fil-A One loyalty accounts fell to attackers. The fast-food giant detected suspicious logins. Then it investigated. The result? A classic credential stuffing campaign that succeeded because users recycled passwords from other breaches.

The attacks hit between June 17 and June 19, 2026. They targeted the company’s website and mobile app. SecurityWeek reported that threat actors deployed automated tools. Those tools tested email and password pairs lifted from unrelated third-party sources. No systems at Chick-fil-A were breached. The credentials simply worked.

Data accessed included names, email addresses, membership numbers, mobile pay numbers or QR codes, account balances and partial payment card details. In some accounts, attackers also saw phone numbers, home addresses or birth dates without the year. Chick-fil-A moved fast once it confirmed the compromise on July 13. It forced logouts, reset passwords, stripped stored payment methods and restored any drained balances while adding extra rewards.

“As soon as Chick-fil-A discovered the incident, we immediately took action to protect customers’ accounts, which included forcing log-outs of affected accounts and removing any stored payment methods. We also restored impacted customers’ Chick-fil-A One account balances,” the company stated in notifications reviewed by Cybernews. Customers received letters dated around July 20 urging immediate password changes.

This marks the second documented credential stuffing wave against Chick-fil-A One. An earlier campaign from December 2022 to February 2023 exposed similar data for more than 71,000 customers. That earlier breach prompted notifications to state attorneys general and similar remediation steps. Yet the problem returned. Why? Because password reuse remains widespread. And attackers know it.

The Mechanics Behind Persistent Success

Credential stuffing exploits one stubborn human behavior. People create one strong password. Then they use it everywhere. When one site suffers a breach, those credentials flood underground markets. Bots test them at scale against other services. Success rates stay low, often under 1 percent. But volume makes the tactic profitable. A single campaign can test millions of pairs in hours.

Chick-fil-A’s case fits the pattern. The TechRepublic article outlined how attackers gained access without cracking any internal defenses. They simply logged in as legitimate users. Once inside, they could view loyalty points, saved payment info or personal details tied to the account. Some accounts saw balances drained before the company intervened.

But here’s the twist. The fast-food chain didn’t just notify. It invalidated sessions across affected accounts. It removed payment instruments. It credited balances and tossed in bonus rewards as goodwill. Those steps limit damage. They don’t erase the root cause. Passwords remain the weak link when users repeat them.

Industry observers point to broader trends. Recent discussions on X highlight how infostealer malware and prior breaches feed these lists. One post from FusionAuth noted that such attacks originate from new devices and data-center IPs firing thousands of attempts quickly. Real user behavior looks nothing like that. Yet many organizations still rely primarily on username and password checks.

The scale here appears smaller than the 2023 incident. Submissions to attorneys general in Massachusetts and Texas suggest thousands or tens of thousands of impacted customers, according to SecurityWeek. Exact figures stay undisclosed. Chick-fil-A operates more than 3,000 locations and employs over 200,000 people. Its loyalty program draws millions of app users chasing free sandwiches and points.

And the exposure matters. A name paired with an email, phone and partial card number can fuel identity theft or phishing. Loyalty accounts often link to payment methods for quick mobile orders. Attackers who gain access can rack up charges or drain stored value before detection. In the prior breach, some customers reported unauthorized redemptions.

Chick-fil-A’s response echoes its earlier playbook. It advises strong, unique passwords for its platform. It encourages monitoring accounts for fraud. No evidence emerged that data was published or held for ransom. The company continues to bolster monitoring and fraud controls.

Why Password Habits Refuse to Die

Despite years of warnings, password reuse persists. A 2025 report cited in recent coverage showed billions of credentials circulating from large breaches. Users juggle dozens of accounts. Remembering unique phrases for each feels impossible without tools. So they reuse. Or they tweak one base password with minor changes that bots easily guess.

Experts recommend password managers, multifactor authentication and passkeys as practical defenses. Chick-fil-A’s app supports additional verification in some flows. But adoption lags. During the June attack window, bot detection or rate limiting on login attempts from unfamiliar IPs or devices could have blocked more attempts. Many organizations now layer behavioral signals. Device fingerprinting, geolocation checks and login velocity all help separate legitimate users from scripts.

Forbes contributor Davey Winder covered the notification letters in detail. The July 22 piece quoted the company’s admission of the automated attack using third-party credentials. It listed the exact data categories at risk. The story also referenced Chick-fil-A’s previous 2023 disclosures, showing a repeating vulnerability.

Similar incidents hit other consumer brands. DraftKings suffered a credential stuffing wave in 2022 that let attackers cash out accounts for hundreds of thousands of dollars before authorities caught them. The pattern repeats across retail, airlines and restaurant chains with loyalty programs. These programs store just enough personal and financial data to make takeover attractive.

So what changes? Organizations must stop depending solely on passwords. Passkeys tied to device biometrics offer stronger, phishing-resistant alternatives. Adaptive authentication that challenges unusual logins reduces friction for normal users while blocking bots. Regular credential spraying tests against employee and customer accounts can surface reuse risks before attackers do.

Customers bear responsibility too. After this breach, many will reset their Chick-fil-A password. But will they stop using it on other sites? The evidence suggests not. One X thread from cybersecurity accounts urged unique credentials and MFA everywhere. Another noted that Chick-fil-A restored balances quickly, minimizing financial loss for most.

The incident underscores a larger truth. Data breaches at one company become ammunition for attacks on others. The underground economy thrives on this recycled information. Until password hygiene improves at scale or authentication evolves beyond shared secrets, these attacks will continue. Chick-fil-A’s latest notification serves as both warning and reminder. Convenience and security still clash. And users pay the price when they choose the former.

Recent coverage from Forbes and GBHackers reinforces that the company acted within weeks of the attack window. No internal breach occurred. The vector stayed external. Yet the outcome feels familiar. Another loyalty program. Another list of exposed details. Another call to update passwords.

Security teams at similar organizations should review login telemetry for anomalous patterns. High volumes of failed attempts from cloud providers or foreign IPs often signal stuffing campaigns in progress. Blocking those early can prevent the notifications that follow. For Chick-fil-A, the cycle has repeated. Breaking it requires more than customer letters. It demands systemic change in how accounts are protected.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us