Got a Chick-fil-A breach notice? The letter is real. The emails that follow are the risk
Got an email saying your Chick-fil-A One account was compromised? Someone probably did log into it, and it was not Chick-fil-A's firewall that failed. Between June 17 and 19, 2026, attackers replayed passwords stolen from other companies' breaches against Chick-fil-A One accounts, and 13,322 people are now receiving breach notices. Here is how to tell the genuine notice from the phishing wave that always follows one, and why your other accounts are the bigger story.
At a Glance
The Chick-fil-A One breach is real, the mailed notification letter is real, and the danger now is the fake email that rides on the news. Attackers used credential stuffing, meaning passwords stolen from other sites, to enter accounts between June 17 and 19, 2026. Chick-fil-A has already reset passwords on affected accounts, ended active sessions, removed stored payment methods and restored spent balances. So any email that asks you to click a link and type your current Chick-fil-A password to "secure your account" or "claim your restored balance" is not cleanup. It is the second wave. Open the app or type chick-fil-a.com yourself, and never sign in from a link.
What actually happened between June 17 and 19
Chick-fil-A noticed suspicious login activity on some Chick-fil-A One accounts. The investigation found that between June 17 and June 19, 2026, attackers signed into customer accounts using automated tools and credentials that the company's notification says were "obtained from a third-party source". Malwarebytes wrote it up on July 22, and BleepingComputer confirmed the scale on July 24: 13,322 people affected in total, a figure put on record in a filing with the Maine attorney general, alongside separate filings with the Texas and Massachusetts attorneys general (2,182 and 39 residents respectively) and notification letters sent to residents of the District of Columbia, Iowa, Maryland, New Mexico, New York, North Carolina, Oregon, Vermont and Rhode Island.
Note what that description is not. Nobody breached Chick-fil-A's servers, cracked its database or slipped past its defenses. The login page worked exactly as designed. The attackers simply arrived holding valid keys: email-and-password pairs stolen from other companies' breaches, bought or downloaded in bulk, then fired at the Chick-fil-A One login by a script until some of them opened a door. That is credential stuffing, and it only works on accounts whose owner reused a password.
One design decision made the job easier. Chick-fil-A One offers multi-factor authentication, but it is optional rather than required, which is why Malwarebytes' write-up urges affected customers to switch it on. An account with MFA enabled would have asked the intruder for a code they did not have. Most loyalty accounts never have it enabled.
What the intruders could see, and what they could spend
Per the notification letters, an attacker inside your account could reach a combination of the following: your name and email address, your Chick-fil-A One membership number, your mobile pay number and the QR code tied to it, the amount of Chick-fil-A credit on the account, and the last four digits of any saved credit or debit card. If you had stored them, your birth date (month and day), phone number and physical address may have been visible too.
Two of those deserve translation. The QR code is not decoration: it is the code a restaurant scans to tie a purchase to your account and its stored value. And the "Chick-fil-A credit" is real money, loaded as gift-card balance or rewards. Chick-fil-A says it restored all affected account balances and added rewards on top, which tells you what the intruders were there for. In the earlier round of attacks against the chain, hijacked accounts had their stored balances spent before the accounts were locked down.
What was not exposed: full card numbers, CVVs and expiry dates. Nobody can charge your card with the last four digits. What they can do with them is far more annoying, and we get to it below.
This is the second time, and the playbook is identical
If this feels familiar, it should. In March 2023, Chick-fil-A disclosed that credential stuffing attacks running from December 2022 through February 2023 had compromised 71,473 customer accounts, with the same categories of data exposed and, in some cases, stored rewards balances spent by the attackers. BleepingComputer covered that incident at the time.
The repeat is not really about Chick-fil-A. Loyalty accounts are the soft underbelly of consumer security: people guard their bank login and then protect a chicken-sandwich app with the same password they used on a forum in 2019. Stored value, saved cards and a login page that scripts can hammer make rewards programs a standing target, which is why the same mechanics keep surfacing everywhere from fast food to retail. We saw the identical pattern drain Argos accounts in the UK. The attackers do not care about your sandwich points. They care that your password works, and that it probably works elsewhere too.
How to tell the real breach notice from the phishing that follows
Every publicized breach produces an echo: a wave of fake "security" messages aimed at the very people who just learned they were exposed. You are primed to expect contact from the brand, so the fake contact lands. Here is the separation test.
The genuine notification is a mailed paper letter. It went out through state breach-notification channels in late July 2026, it tells you what happened and what was exposed, and its action items are things you do yourself: set a new password, watch your statements. It does not need your password, because Chick-fil-A already reset it on affected accounts.
That last fact is your weapon. The company has already reset passwords and logged out sessions. So a message that says "verify your current password to keep your account" is asking for something the real company explicitly no longer wants you to use. There is no legitimate flow, none, in which Chick-fil-A emails you a link and asks you to type your old password into it.
Check where the link really goes before you judge the email. The chain's only real home is chick-fil-a.com. Expect lookalikes shaped like chickfila-one-verify[.]com or chick-fil-a-balance[.]net; both are illustrative shapes we built for this article, not domains reported in this campaign, because the follow-on phishing wave typically registers its hostnames after the breach makes news. A hyphenated brand name like this one is a gift to scammers, since every spacing and hyphen variant looks plausible at a glance. If you are unsure how to read a sender or a link, our guide to verifying whether an email is really from the company walks through it field by field.
The three lures to expect in the next month
1. The fake password reset. "Your Chick-fil-A One account was accessed by an unauthorized party. Reset your password within 24 hours to avoid suspension." The link opens a lookalike login that harvests your email and password, and here is the loop closing: credentials phished off the back of a credential stuffing breach get fed straight into the next credential stuffing attack, against your other accounts.
2. The fake restored balance. This one is dangerous precisely because its premise is true. Chick-fil-A really did restore balances and add bonus rewards to affected accounts. A scam email that says "your $25 credit has been restored, plus a bonus reward. Verify your identity to claim" is telling a half-truth you can confirm in the news, then asking for the card number or login the real company never requests. Real restored credit simply appears in your app. There is nothing to claim.
3. The support call that knows your card's last four. If your phone number was in the account, expect calls or texts from "Chick-fil-A security" or "your bank's fraud team" that mention the card ending in your real last four digits. That detail feels like proof of legitimacy. It is not. It is the breach data being read back to you, the same trick we broke down after the Lidl breach, where leaked personal details became the script for the follow-on fraud. Hang up and call the number on the back of your card.
Block the fake breach email before you type a password
You cannot control what lands in your inbox after a breach, but you can control what happens when you click. SafeBrowz is a free browser extension for Chrome, Firefox and Edge, with Safari pending, plus an Android app, and its job is to check every page as it opens and block the lookalike login before you type a password into it. The free tier runs all three detection layers, with the AI deep scan limited to one a day; Premium lifts that limit for $14.99 a year.
Holding a suspicious Chick-fil-A email right now? Check where its link goes, without opening it →
The password-reuse lesson nobody enjoys
Sit with the mechanics for one paragraph, because they change what "my Chick-fil-A got hacked" means. The password that opened your account was not guessed and not stolen from Chick-fil-A. It leaked from some other service where you used the same one, possibly years ago, and it has been circulating in credential dumps ever since. Which means the exposure did not start with this breach and does not end with it: every other account sharing that password is open to the same automated knock on the door.
So the real to-do list is bigger than one app. Check what actually leaked against your email address at haveibeenpwned.com, typed directly rather than reached from any link, since fake "check if you were affected" pages are a genre of their own that we dissected in the 24-billion-record breach checker scam. Then retire the reused password everywhere it lives, starting with your email account, because whoever controls that mailbox controls every password reset you own. A password manager makes unique passwords sustainable; and turn on multi-factor authentication wherever it is offered, Chick-fil-A One included, preferring an authenticator app over SMS codes for the reasons in our SMS-to-TOTP upgrade guide.
If you got the letter, do this in the next ten minutes
Set a new password from inside the app or by typing the address. Open the Chick-fil-A app, or type chick-fil-a.com into the browser yourself, and use the normal password reset there. Make it a password you use nowhere else. Do not start from any link in any email, even one that looks like the real notice.
Turn on multi-factor authentication in the account settings. It is optional; opt in. This is the single control that would have kept the intruders out.
Change that same password on every other site that shares it. This is the step that actually closes the breach. Email first, then anything financial.
Skim statements for the card that ends in the exposed digits. The full number did not leak, so direct fraud on the card is unlikely; the risk is impersonation. Treat any call or text that quotes those four digits as hostile and dial your bank yourself.
Distrust every Chick-fil-A email for the next few months. Not because the company is careless, but because the scammers now have a believable pretext. Navigate directly; never sign in from a message.
Report what shows up. Phishing emails and texts go to the FTC at reportfraud.ftc.gov. If money was actually taken from you, file at ic3.gov as well, and work through our step-by-step recovery guide.
Where SafeBrowz catches this, and where it cannot
SafeBrowz runs a 3-layer detection architecture: Local + APIs + AI. The honest scope first: no browser tool can see a credential stuffing script hitting Chick-fil-A's own servers, and none can un-reuse a password. What SafeBrowz covers is the part of this story that arrives in your inbox, the lookalike login and reward-claim pages built to profit from the news.
- Layer 1 - Local checks: before any network call, the extension examines the URL itself for the shapes phishing pages wear: suspicious keywords and urgency phrases in the address, missing HTTPS, raw-IP hosts, and Cyrillic or Punycode homograph tricks, which matter for a hyphenated brand name that invites lookalike spellings.
- Layer 2 - API checks: the domain is cross-referenced server-side against our 550+ brand database and blocklists, Google Safe Browsing, PhishTank, URLhaus and ScamAdviser feeds, plus a 30+ scam TLD watchlist. Post-breach phishing pages get reported and blocklisted quickly once a wave starts, and a days-old domain on a cheap TLD is a weighted signal on its own.
- Layer 3 - AI deep scan (Premium): AI content analysis via our proxy reads the rendered page the way an investigator would. A Chick-fil-A logo above a login form, "claim your restored balance" copy and a countdown timer on a hostname the chain does not own is exactly the combination the LLM-based impersonation detection exists for, and it works on brands outside any static list and on pages too new for any feed to have seen.
It cannot recover credit that was already spent, and it does not read your email. It puts a hard warning between your keyboard and the fake reset page at the moment the urgency is doing the deciding.
Detection signatures are derived from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.
Got a Chick-fil-A reset email? Paste the link here instead of clicking it
Copy the link out of the message and check it before it can load. Our 3-layer engine (Local + APIs + AI) returns a verdict in about three seconds. Free, no signup.
Frequently asked questions
Is the Chick-fil-A data breach notification real?
Yes. Chick-fil-A confirmed that attackers used credential stuffing to access Chick-fil-A One accounts between June 17 and 19, 2026, and breach notices covering 13,322 people went out in late July 2026, a total put on record in a filing with the Maine attorney general, as reported by BleepingComputer on July 24, 2026. The genuine notification is a mailed letter that asks nothing of you beyond changing your password yourself. An email that links to a login page and asks for your current password is not the notification; it is phishing built on top of the news.
Was my credit card number stolen in the Chick-fil-A breach?
No. Only the last four digits of a saved card were visible, alongside your name, email, membership and mobile pay numbers, QR code and stored account credit, plus birth date (month and day), phone number and address if you had saved them. Nobody can charge a card with four digits. The real risk is impersonation: a caller or text quoting your card's last four to sound like your bank or Chick-fil-A support. Treat that detail as public and verify any such contact by dialing the number on the back of your card.
What is credential stuffing, in plain terms?
Attackers take email-and-password pairs stolen in past breaches of other companies, then use automated tools to try those same pairs on other login pages, in this case Chick-fil-A One. Any account whose owner reused a password simply opens. Chick-fil-A's systems were not hacked in the traditional sense; the intruders logged in with valid but stolen credentials. That is why the fix is not just a new Chick-fil-A password but retiring that password everywhere you used it, and turning on multi-factor authentication.
Has Chick-fil-A been breached like this before?
Yes. In March 2023 the company disclosed that credential stuffing attacks running from December 2022 through February 2023 compromised 71,473 Chick-fil-A One accounts, with similar data exposed and some stored rewards balances spent by the attackers. The June 2026 incident is the second known round, using the same technique. Loyalty accounts are a recurring target because they hold stored value and saved payment details but are rarely protected with unique passwords or multi-factor authentication.
I got a "claim your restored balance" email from Chick-fil-A. Is it safe?
Treat it as hostile. Chick-fil-A did restore spent balances and add rewards to affected accounts, but that credit appears in your account automatically; there is no claim step, and the company has already reset affected passwords itself. An email that asks you to sign in through its link, verify your identity or enter card details to receive the credit is using the true news as bait. Open the app or type chick-fil-a.com directly and look at your balance there instead.
Last updated 2026-07-27