CHICK-FIL-A alerted customers after discovering that attackers hijacked loyalty accounts using stolen passwords in a credential stuffing attack from June 17-19, 2026. The company detected suspicious login attempts, investigated, and subsequently reset passwords and ended sessions for affected users. Credential stuffing involves using stolen credentials from one site to access accounts on others, exploiting common password reuse among individuals.
Attackers accessed customer data, including names, email addresses, loyalty numbers, and partially masked credit card information. Chick-fil-A advised its customers to create unique passwords, enable multi-factor authentication, and remain vigilant against phishing attempts.