A wiped rewards balance and a locked screen: that’s what thousands of Chick-fil-A One users encountered in June 2026. The instinct is to assume the chain got hacked. The reality is more unsettling. Attackers already had the passwords — collected from other breaches, purchased off dark web markets, and tested at machine speed until they found accounts where those credentials still worked. Over a three-day automated campaign, criminals ran credential stuffing attacks against Chick-fil-A’s website and mobile app, according to Malwarebytes. Your spicy chicken sandwich app is now a financial target.
The Attack Runs on Your Recycled Passwords
Criminals didn’t break into Chick-fil-A’s systems — they walked through the front door with keys left behind at other sites.
No Ocean’s Eleven sophistication required. Attackers obtain massive lists of username-password pairs from prior data dumps and dark web markets. Automated tools then fire those credentials at login pages across the internet — think of it as a bot playing Wordle with every possible answer simultaneously, at industrial scale. Where a match hits, criminals drain the account, siphoning loyalty balances, stored value, and personal data, or reselling access to other bad actors.
Chick-fil-A’s own systems weren’t compromised in the traditional sense. The attackers already possessed the credentials because users reused the same passwords across multiple services.
What they harvested was substantial. According to Chick-fil-A’s breach notifications, exposed data included:
- Names, email addresses, and membership numbers
- Mobile pay details and QR codes
- Gift card and reward balances
- The last four digits of stored payment cards
Accounts with fuller profiles also exposed birthdates, phone numbers, and physical addresses — enough to fuel highly targeted follow-up scams.
What You Should Do Right Now
Whether or not you’ve received a breach notification, treat your Chick-fil-A One account as compromised and act immediately.
If you have a Chick-fil-A One account, change your password now — something unique that you haven’t used anywhere else. Then change it on every other account that shared that same password. Chick-fil-A has already reset credentials and terminated active sessions for affected accounts, but waiting for an official letter is a gamble worth skipping. Enable multi-factor authentication through a verified mobile number; the app supports it. If you’re locked out, follow the company’s account recovery process.
The exposed data creates a second threat wave. Attackers now hold enough detail — loyalty balances, partial card data, contact information — to craft convincing phishing messages that look legitimate. Be deeply skeptical of any unsolicited communication referencing your rewards or payment updates. As Malwarebytes observed, “we’ve designed and adopted a system that no longer works well for most people: passwords.” Even newer alternatives like passkeys face adoption barriers that leave most users stuck in the same vulnerable cycle.
This isn’t new territory for Chick-fil-A. A similar credential stuffing campaign ran from December 18, 2022 through February 12, 2023, according to Bitdefender. The pattern repeats because the underlying conditions haven’t changed. Until MFA becomes the default and unique passwords become habit, loyalty accounts remain someone else’s easy payday.





























