Between 17 and 19 June 2026, an automated attack targeted the website and mobile app of Chick-fil-A, Inc., the Atlanta-based operator of more than 3,000 quick-service restaurants across the United States, Canada, Puerto Rico, the United Kingdom, and Singapore. The attackers did not need to breach Chick-fil-A's own systems. They used email addresses and passwords harvested from earlier, unrelated data breaches and tried them, at automated speed, against Chick-fil-A One accounts until a fraction of them worked. Chick-fil-A did not detect the intrusion while it was happening. It determined on 13 July, nearly a month after the attack ended, that certain accounts had been accessed without authorisation.
Credential stuffing relies on a simple fact: most people reuse passwords across services. An attacker who buys or scrapes a list of stolen credentials from one breach can run that list against a completely unrelated company's login page, and a meaningful percentage of accounts will open on the first try. There is no vulnerability to exploit, no phishing message to send, and no employee to convince. The login form does exactly what it was built to do: it accepts a correct username and password.
Once inside, the attackers could see names, email addresses, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, the balance of stored Chick-fil-A credit on each account, and the last four digits of the linked card. Where customers had saved a date of birth, phone number, or home address to their profile, that came out too. None of it required a second step. The same login that displayed a user's rewards balance also displayed everything an attacker needed to spend it or resell the account.
Chick-fil-A has not said how many customers were affected nationwide. State filings put a floor under the number: at least 2,182 residents of Texas and 39 in Massachusetts, with notification letters also going to residents of Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island. This is not a new failure mode for the company. In March 2023, Chick-fil-A confirmed an almost identical attack had compromised the accounts and stored rewards balances of more than 71,000 customers over a three-month window. Three years and one very similar disclosure later, the control that would have stopped a stolen password from being a functioning login still does not exist.
Chick-fil-A's response after the fact was reasonable: it logged out every affected account, stripped stored payment methods, restored account balances, and added bonus rewards as an apology. None of that happened before the accounts were accessed. The defences that failed here were not exotic. Chick-fil-A had already lived through the exact same attack once. Rate limiting, anomaly detection, and password reuse warnings can all reduce how many stolen credentials succeed, but none of them changes what happens the moment one does: a password that is technically correct still opens the account, moves the balance, and exposes the card, regardless of who is actually typing it in.
A login is not the point at which value should change hands. Viewing or spending stored Chick-fil-A credit, redeeming a mobile pay QR code, or changing the payment details on an account are execution events, not authentication events. Under GoFirm, before any of those actions completes, a real-time confirmation request goes to the named accountholder's registered device, requiring a biometric confirmation on a separate channel from the one the attacker is using.
A credential-stuffed login has one thing an attacker needs and one thing they do not: a technically valid password, and no way to produce a biometric confirmation on the real accountholder's own device. It does not matter that the password worked, or that it came from a breach that had nothing to do with Chick-fil-A. A stolen password, however correctly typed, cannot produce that confirmation. The execution boundary holds regardless of how the credential was obtained.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
1. Gatlan, S. 2026. Chick-fil-A discloses data breach after credential stuffing attacks. BleepingComputer, 22 July 2026.
2. Massachusetts Office of Consumer Affairs and Business Regulation. 2026. Chick-fil-A, Inc. data breach notification. Mass.gov, July 2026.
Back to Blog
Case Studies·4 min read
Chick-fil-A's loyalty accounts were breached by the same attack twice
By GoFirm
