Chick-fil-A notified customers that unauthorized parties accessed their Chick-fil-A One loyalty accounts in a credential stuffing attack that targeted the company's website and mobile app between June 17 and June 19, 2026. The company said it determined on July 13 that customer account information may have been compromised.
