Back to Industry

Industry - Data Breach

moderateAnti-PrivacyData Breach

Executive Summary

An automated attack on Chick-fil-A's website and mobile app between June 17-19 exposed customer data from the Chick-fil-A Rewards program, including email addresses, partial credit card numbers, birth dates, phone numbers, and addresses. The company confirmed a "limited number" of loyalty accounts were affected but has not disclosed the total number of impacted customers. The breach occurred during a significant nationwide surge in data breaches, with over 471 million breach notifications sen...

What Happened

Between June 17 and June 19, 2026, Chick-fil-A experienced an automated cyberattack targeting its website and mobile app, specifically affecting customers enrolled in the Chick-fil-A One Rewards loyalty program. The breach exposed customer information including email addresses, the last four digits of credit card numbers, birth dates (month and day), phone numbers, and physical addresses. Chick-fil-A confirmed that a limited number of loyalty accounts were compromised and disclosed the incident to state attorneys general in Massachusetts, Texas, and other states, though the company has not publicly released the total number of affected customers.

Who Is Affected

Customers who participate in the Chick-fil-A One Rewards loyalty program are affected, with their personal and partial financial information now exposed. While the exact number of impacted users has not been disclosed, the breach affected customers across multiple states including Georgia, Massachusetts, and Texas. All affected individuals face increased risk of identity theft, phishing attempts, and targeted fraud using the combination of personal details that were exposed.

Why It Matters

This breach is part of a dramatic escalation in data compromises nationwide, with over 471 million breach notifications already sent in 2026 - exceeding the entire total for 2025. Security experts note that artificial intelligence is making cyberattacks significantly easier and more efficient to execute, suggesting that automated attacks like this one may become increasingly common. The incident underscores the vulnerability created by loyalty apps and the accumulation of personal data in mobile platforms, affecting millions of consumers who use similar reward programs across the restaurant and retail industries.

What You Should Do

If you are a Chick-fil-A Rewards member, monitor your credit card statements and bank accounts closely for unauthorized charges, paying particular attention to the card whose last four digits may have been exposed. Enable pass-keys for account authentication wherever available, as security experts identify these as a crucial but underutilized protection measure. Limit the personal information you share with loyalty apps going forward, avoid linking credit cards when possible, and consider whether the benefits of each app justify the data vulnerability it creates. Be alert for phishing emails or text messages that use your exposed information to appear legitimate, and never click links or provide additional details in response to unsolicited communications claiming to be from Chick-fil-A.

Summary generated from verified sources and reviewed before publication. How we summarize.

An automated attack on Chick-fil-A's website and mobile app between June 17-19... - Industry | PrivacyWire