Chick-fil-A One loyalty accounts are being taken over by people using passwords stolen from other websites — not by cracking Chick-fil-A’s own password vault. If you reuse a password on your CFA One account, your points, saved payment details, and account profile can be at risk.
Malwarebytes and BleepingComputer covered July 2026 notices after Chick-fil-A investigated suspicious logins and filed state AG letters. This is not a duplicate of any prior EmailMeNow article — we have no earlier Chick-fil-A One post.

Snapshot
| Field | Detail |
|---|---|
| What happened | Credential stuffing against Chick-fil-A website + mobile app |
| Attack window | June 17–19, 2026 |
| Confirmed impact | July 13, 2026 (company investigation) |
| Notices | Letters / AG filings ~July 20–22, 2026 |
| Texas AG figure | 2,182 Texans (per BleepingComputer) |
| Massachusetts AG | 39 residents |
| Other notice jurisdictions | IA, MD, NM, NY, NC, OR, RI, VT + DC |
| Root cause (company) | Credentials from a third-party source — password reuse, not a CFA password dump |
| Prior similar wave | Dec 2022–Feb 2023 (~71,000 customers, company-confirmed) |
What attackers could see
Chick-fil-A’s notices say unauthorized parties may have accessed a mix of:
| Category | Examples |
|---|---|
| Identity | Name, email |
| Loyalty / pay | Chick-fil-A One membership #, Mobile Pay #, account QR codes |
| Value | Rewards / Chick-fil-A credit balances |
| Payment hint | Last four digits of stored card |
| Profile extras (if stored) | Birth month/day, phone, address |
Chick-fil-A says attackers did not obtain passwords from its systems — they reused emails + passwords stolen elsewhere.

What Chick-fil-A says it did
| Action | Purpose |
|---|---|
| Force logout / kill sessions | Cut off active takeovers |
| Remove stored payment methods | Limit card abuse on compromised accounts |
| Restore loyalty / credit balances | Undo theft of rewards or gift credit |
| Add apology rewards | Customer goodwill |
| Advise password reset | Break reuse of the stuffed credential |
Malwarebytes also notes Chick-fil-A One supports MFA via a verified mobile number — worth enabling if you have not already.

What customers should do now
- Change your Chick-fil-A One password to something unique — never reused on email, banking, or shopping sites.
- If the same password was reused elsewhere, rotate those accounts too.
- Turn on MFA with a verified mobile number in Chick-fil-A One.
- Check Have I Been Pwned for your email; treat any hit as a reason to assume password reuse risk.
- Watch for phishing that cites “CFA One security” or asks you to “re-link” payment cards — attackers now have more personal context for scams.
- Review recent rewards activity and any unexpected Mobile Pay / QR use.
Why Texas businesses should care
BleepingComputer reports Chick-fil-A told the Texas Attorney General the incident affects 2,182 Texans. Beyond consumer loyalty apps, the same credential-stuffing pattern hits Microsoft 365, VPN portals, billing portals, and POS vendor logins when employees reuse passwords.
Retail and hospitality operators in Texas should treat this as a live reminder: password reuse + no MFA turns someone else’s breach into your account takeover. Pair unique passwords (or a manager) with MFA on every customer-facing and staff-facing login — the same lesson as our Fortinet credential-stuffing alert and password-manager policy phishing coverage.
Independent cybersecurity audits
We audited domains tied to this story on July 24, 2026. 100% is the ideal overall score — none of these hosts reach it. Scores reflect public email / transport / website posture, not whether a loyalty login was breached via stuffing.
| Organization | Domain | Overall | Identity | Transport | Website | vs 100% ideal |
|---|---|---|---|---|---|---|
| Have I Been Pwned | haveibeenpwned.com | 88% | 90% | 45% | 100% | −12 |
| Cloudflare | cloudflare.com | 88% | 90% | 45% | 100% | −12 |
| Malwarebytes | malwarebytes.com | 72% | 90% | 45% | 45% | −28 |
| BleepingComputer | bleepingcomputer.com | 63% | 75% | 15% | 40% | −37 |
| Chick-fil-A | chick-fil-a.com | 42% | 25% | 15% | 37% | −58 |
| Chick-fil-A (alt) | chickfila.com | 28% | 0% | 15% | 37% | −72 |
How to read this table
- chick-fil-a.com at 42% (Identity 25%, Transport 15%) sits far below the 100% ideal — soft public identity and mail-transport signals matter for spoofed “security” emails that follow a real stuffing incident.
- chickfila.com at 28% (Identity 0%) is weaker still; treat lookalike / adjacent brand domains carefully when clicking reset links.
- haveibeenpwned.com / cloudflare.com lead this set at 88% — useful for breach checks and edge security context, still −12 from ideal.
- These audits do not measure app MFA enforcement or anti-automation on the mobile login — stuffing succeeds when users reuse passwords, regardless of corporate DNS hygiene.
Audit links
- chick-fil-a.com
- chickfila.com
- malwarebytes.com
- haveibeenpwned.com
- bleepingcomputer.com
- cloudflare.com
Website stack note
Passive website-tech probes on July 24, 2026 completed for 4 of 4 story domains (0 notable):
| Domain | Stack signal |
|---|---|
| chick-fil-a.com | WordPress (version hidden) |
| chickfila.com | WordPress (version hidden) |
| malwarebytes.com | WordPress (version hidden) |
| haveibeenpwned.com | No notable public CMS / PHP / short-horizon TLS flags |
Hidden WordPress versions are common on hardened marketing sites and do not prove Core is outdated. They also do not explain June’s credential stuffing — that attack abused reused third-party passwords, not a public CMS fingerprint.
These passive observations are point-in-time public signals. They do not prove exploitability, identify a breach path, or establish that a detected major version is unsupported.
Priority actions for IT teams
- Ban password reuse on staff and customer portals — enforce managers + unique vault entries.
- Require MFA on loyalty, SSO, VPN, and email — SMS MFA is better than nothing; phishing-resistant MFA is better still.
- Rate-limit and detect stuffing on login APIs (velocity, impossible travel, known-bad credential feeds).
- Hunt spoofed brand email after public notices — Identity gaps on retail domains make fake “reset your CFA One / rewards” mail more believable.
- Educate customers and employees that a company’s systems need not be “hacked” for their account to be emptied — reuse is enough.
Related trackers
- NCSC Fortinet credential-stuffing alert
- LastPass / Bitwarden policy phishing
- Breach monitoring resources
- Texas OAG breach reports tracker
Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for MFA rollout, DMARC / MTA-STS work, and login hardening aimed at the 100% ideal.
Sources: Malwarebytes — Chick-fil-A loyalty accounts hijacked using stolen passwords · BleepingComputer — Chick-fil-A discloses data breach after credential stuffing · TechRepublic — One password mistake helped hackers access Chick-fil-A accounts · USA TODAY — Chick-fil-A cyberattack may have exposed customer data