Chick-fil-A has announced that some of its loyalty customers may have been impacted by a cyberattack. The company says that unauthorized parties launched an automated attack against its website and mobile application between June 17 and June 19, 2026, using account credentials obtained from a third-party source.
What Information Was Breached?
The information that may have been accessed includes names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, the last four digits of credit/debit card numbers, and remaining credit amounts. If saved to a Chick-fil-A account, the information may have also included the month and day of loyalty members’ birthdays, phone numbers, and addresses.
Chick-fil-A has taken steps to protect its customers, including forcing log-outs of affected accounts, removing stored payment methods, restoring Chick-fil-A One account balances, and adding rewards to those accounts. The company has also reset passwords for impacted accounts and is urging customers to update their passwords as soon as possible.
Original reporting: WPBF West Palm Beach — read the source article.