Start with Identity
← Blog
News

Chick-fil-A's second credential stuffing breach in three years hit 13,322 loyalty accounts

Automated login attempts using credentials obtained from a third-party source, not a Chick-fil-A breach, compromised 13,322 Chick-fil-A One loyalty accounts over three days in June, exposing membership numbers, stored credit, and partial card numbers.

By SWI Community TeamJul 24, 2026Updated Aug 6, 2026

Chick-fil-A disclosed that automated credential stuffing attacks compromised 13,322 Chick-fil-A One loyalty accounts between June 17 and June 19, 2026. Attackers used credentials obtained from an unrelated third-party source, reused passwords rather than any flaw in Chick-fil-A's own systems, to log into accounts automatically at scale. Exposed data included names, email addresses, loyalty membership numbers, stored credit balances, mobile pay numbers, and the last four digits of payment cards, with birthdates, phone numbers, and addresses exposed where customers had stored them. Chick-fil-A logged out every compromised account, removed stored payment methods, restored account balances, and added rewards for affected customers, notifying individuals across multiple states including 2,182 in Texas and 39 in Massachusetts. This is the company's second such incident: a March 2023 disclosure covered roughly 71,000 customer records compromised between December 2022 and February 2023.

Why it matters

Credential stuffing doesn't require breaking anything, it requires only that customers reuse a password that leaked somewhere else, which makes it a recurring risk regardless of how well a company secures its own systems. A second incident in three years, same attack class, same loyalty program, is the pattern worth noting: credential stuffing defenses (rate limiting, bot detection, and mandatory MFA on accounts holding stored payment methods) have to be treated as permanent infrastructure, not a one-time response to the first incident.

Stored value and mobile pay numbers turn a loyalty account into a target with real cash value attached, which is exactly why loyalty programs specifically, not just primary email or banking logins, need the same authentication rigor as financial accounts.

Source: BleepingComputer

Independent analysis. No vendor sponsorship.