Cyberattack may have exposed some Chick-fil-A customer data
Gabe HauariUSA TODAY
July 22, 2026, 12:07 p.m. ET
A recent cyberattack may have exposed the personal information of some Chick-fil-A One loyalty members.
The company confirmed to USA TODAY it recently identified a “security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts.”
“Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted,” the company said in an emailed statement to USA TODAY. “We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day.”
Here’s what we know about the cyberattack and data breach, and who is impacted.
Who is impacted by the Chick-fil-A cyberattack?
The company sent out letters to potentially affected customers on July 20 stating it identified “suspicious login activity” to certain Chick-fil-A One accounts. According to the letter, the cyberattack affected customers in nine states plus Washington DC. The nine states are Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont.
Following an investigation, the company determined “unauthorized parties” launched an attack against its website and mobile app between June 17 and June 19 by using account credentials obtained from a “third-party
What information was exposed in Chick-fil-A cyberattack?
The information exposed may have included names, email addresses, Chick-fil-A One membership and mobile pay numbers, last four digits of credit and debit card numbers, and the amount of Chick-fil-A credit on users’ accounts. Additionally, if saved to users’ accounts, the information may have also included the month and day of the account holder’s birthday, phone number and address.
Chick-fil-A said in the letter it restored impacted customers’ Chick-fil-A One account balances and, as an additional way to thank customers, added rewards to their accounts. The chain also said it “continues to enhance its security monitoring and fraud controls” to minimize the risk of any similar incident in the future.
What can affected customers do?
Chick-fil-A says it has reset affected users’ Chick-fil-A passwords and encourages users to update their passwords as soon as possible.
Gabe Hauari is a national trending news reporter at USA TODAY. You can follow him on X @GabeHauari or email him at Gdhauari@usatoday.com.