Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Reform councillors told to call donations inquiry ‘establishment stitch-up’ | Reform UK

    July 24, 2026

    Chris Mason: What his first week in power tells us about Andy Burnham

    July 24, 2026

    ECB to start implementing enhanced repo facility for central banks

    July 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Reform councillors told to call donations inquiry ‘establishment stitch-up’ | Reform UK
    • Chris Mason: What his first week in power tells us about Andy Burnham
    • ECB to start implementing enhanced repo facility for central banks
    • Sam Altman’s biometric startup World raises $52.5 million via crypto sale
    • Meta, Microsoft, Nvidia, IBM, and others back open-weight AI
    • BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
    • Sealed In Foil: BMAG’s New Focus On Trading Cards
    • Scientists discover a compound that could supercharge aging muscle repair
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, July 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Chick-fil-A data breach affects more than 13,000 customers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 24, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    American fast food restaurant chain Chick-fil-A has confirmed that over 13,000 customers had their data stolen in a recent wave of credential stuffing attacks.

    As BleepingComputer first reported, the company revealed in data breach notification letters filed with multiple attorney general’s offices that it detected attacks targeting its website and mobile app between June 17 and June 19 after identifying suspicious login activity to certain Chick-fil-A One accounts.

    Chick-fil-A says the attackers used automated tools and credentials “obtained from a third-party source” to hack into Chick-fil-A One accounts and steal customer data.

    image

    “We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts. Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted,” the company told BleepingComputer.

    During the attacks, the threat actors accessed a combination of customers’ names, email addresses, Chick-fil-A One membership numbers, the amount of Chick-fil-A credit, the mobile pay numbers, and the last four digits of the credit/debit card number. Additionally, they may have also gained access to birth dates, phone numbers, and addresses if stored in the compromised accounts.

    While the company didn’t say how many individuals had their data exposed, Chick-fil-A notes in a filing shared by the Office of the Maine Attorney General with BleepingComputer on Wednesday that the resulting data breach affected 13,322 people in total.

    In separate filings, it also told the Texas attorney general’s office the data breach impacts 2182 Texans and the Massachusetts AG that it affects 39 residents. Chick-fil-A has also sent data breach notification letters to residents of the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.

    In response to the incident, Chick-fil-A says it logged out all impacted accounts, removed payment methods, restored all affected Chick-fil-A One account balances, and has also added rewards to affected accounts as a way of apologizing. Since the accounts were compromised because they were using credentials stolen from third-party services, Chick-fil-A also advised impacted customers to change their passwords as soon as possible.

    Chick-fil-A also disclosed in March 2023 that hackers stole the personal information of over 71,000 customers after hacking their accounts in another series of credential stuffing attacks between December 2022 and February 2023.

    As one of the largest fast food companies in the United States, Chick-fil-A operates a network of over 3,000 restaurants across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    affects breach ChickfilA customers data
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

    Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

    ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

    Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

    Man gets six years for hacking 750 women’s Snapchat accounts

    Clop ransomware targets Windchill, FlexPLM in data theft attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Reform councillors told to call donations inquiry ‘establishment stitch-up’ | Reform UK

    July 24, 2026

    Chris Mason: What his first week in power tells us about Andy Burnham

    July 24, 2026

    ECB to start implementing enhanced repo facility for central banks

    July 24, 2026

    Sam Altman’s biometric startup World raises $52.5 million via crypto sale

    July 24, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Reform councillors told to call donations inquiry ‘establishment stitch-up’ | Reform UK

    July 24, 2026

    Chris Mason: What his first week in power tells us about Andy Burnham

    July 24, 2026

    ECB to start implementing enhanced repo facility for central banks

    July 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.