Reused passwords have once again given cybercriminals an easy way into customer accounts.
Chick-fil-A has disclosed that attackers used a credential-stuffing campaign against its website and mobile app, gaining access to a limited number of customer accounts across 10 U.S. states. The incident highlights how password reuse continues to fuel account takeover attacks even when a company’s own systems are not breached.
Depending on what users stored in their accounts, attackers may have accessed personal information, loyalty rewards, gift card balances, and partial payment card details.
Timeline and scope of attack
From June 17 through 19, attackers launched an automated credential-stuffing campaign against Chick-fil-A’s website and mobile app, testing usernames and passwords that the company says were obtained from a “third-party source.”
In a statement to CBS News, the company confirmed that the attackers may have accessed some information. There are currently no reports of the attackers publishing data stolen from the breach or reaching out for ransom.
Stolen information includes customers’ names, their email addresses, and Chick-fil-A One membership numbers. Others include Mobile Pay numbers and QR codes, partial card numbers, and gift card balances used with the restaurant.
USA Today also highlighted customers’ birthdays, excluding the year of birth, phone numbers, and physical addresses, as part of the data accessed. The publication says that information could only have been accessed if customers added it to their Chick-fil-A accounts.
Unusual login activity prompted an internal investigation that concluded by July 13 and led to this discovery.
Affected states include the District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, and Vermont. On July 20, Chick-fil-A began notifying affected customers and disclosing the breach in separate state breach filings.
How Chick-fil-A responded
Chick-fil-A invalidated active sessions, restored affected loyalty balances, and notified impacted customers.
“Upon discovering the issue, we took steps to immediately address, secure, and restore accounts, and we are communicating directly with all customers who may have been impacted,” the company informed USA Today.
Because the attack affected customer-facing services but not the restaurant’s internal systems, the company was able to forcibly log every customer out of their accounts, effectively revoking unauthorized access. It also says Chick-fil-A One account balances were restored, with rewards added to impacted customers’ accounts as a thank-you gift.
Customers are advised to change their passwords and update payment information.
Preventing credential stuffing attacks
The Chick-fil-A incident is another reminder that organizations can do many things right and still face account takeover attacks if customers maintain bad password hygiene. Unlike attacks that exploit software vulnerabilities, credential stuffing succeeds by leveraging credentials already circulating elsewhere, making it one of the most persistent threats facing online services.
For businesses, defending against these attacks means looking beyond passwords by deploying measures such as multi-factor authentication (MFA), bot detection, rate limiting, and monitoring for abnormal login behavior.
For users, the simplest defense remains using a unique password for every account, ensuring that a breach at one service does not become a gateway into another.
Another effective credential login method we would recommend that users implement is passkeys. A passkey bypasses passwords by binding authentication IDs to a user’s device, significantly limiting the scale of credential-based attacks. Although that depends on whether a platform makes such available, where available, users should not hesitate to use it.
For affected customers, we recommend adhering to instructions contained in the breach notification letters and staying vigilant for impersonation or phishing attempts going forward.
Other News: New breach data shows more than 55 million Suno accounts were affected in a 2025 cyberattack, exposing contact details, purchase records, and partial payment card information that users were never individually notified about.