Back to news
Cybersecurity Alert
July 24, 2026 by EmailMeNow IT Consulting

Chick-fil-A One Accounts Hijacked With Stolen Passwords From Other Sites

Attackers stuffed third-party stolen passwords into Chick-fil-A One from June 17–19, 2026. Notices cite 2,182 Texans. Audits (100% ideal): chick-fil-a.com 42%, chickfila.com 28% — neither near ideal.

Source: Malwarebytes · BleepingComputer

NewsCredential StuffingAccount TakeoverPassword ReuseRetailTexasCybersecurity
Loyalty app on a phone showing an account lock and password reset after credential stuffing

Chick-fil-A One loyalty accounts are being taken over by people using passwords stolen from other websites — not by cracking Chick-fil-A’s own password vault. If you reuse a password on your CFA One account, your points, saved payment details, and account profile can be at risk.

Malwarebytes and BleepingComputer covered July 2026 notices after Chick-fil-A investigated suspicious logins and filed state AG letters. This is not a duplicate of any prior EmailMeNow article — we have no earlier Chick-fil-A One post.

Loyalty app locked after credential stuffing, prompting a password reset

Snapshot

FieldDetail
What happenedCredential stuffing against Chick-fil-A website + mobile app
Attack windowJune 17–19, 2026
Confirmed impactJuly 13, 2026 (company investigation)
NoticesLetters / AG filings ~July 20–22, 2026
Texas AG figure2,182 Texans (per BleepingComputer)
Massachusetts AG39 residents
Other notice jurisdictionsIA, MD, NM, NY, NC, OR, RI, VT + DC
Root cause (company)Credentials from a third-party source — password reuse, not a CFA password dump
Prior similar waveDec 2022–Feb 2023 (~71,000 customers, company-confirmed)

What attackers could see

Chick-fil-A’s notices say unauthorized parties may have accessed a mix of:

CategoryExamples
IdentityName, email
Loyalty / payChick-fil-A One membership #, Mobile Pay #, account QR codes
ValueRewards / Chick-fil-A credit balances
Payment hintLast four digits of stored card
Profile extras (if stored)Birth month/day, phone, address

Chick-fil-A says attackers did not obtain passwords from its systems — they reused emails + passwords stolen elsewhere.

Illustration of reused passwords unlocking a loyalty account after other site breaches

What Chick-fil-A says it did

ActionPurpose
Force logout / kill sessionsCut off active takeovers
Remove stored payment methodsLimit card abuse on compromised accounts
Restore loyalty / credit balancesUndo theft of rewards or gift credit
Add apology rewardsCustomer goodwill
Advise password resetBreak reuse of the stuffed credential

Malwarebytes also notes Chick-fil-A One supports MFA via a verified mobile number — worth enabling if you have not already.

Person enabling multi-factor authentication on a rewards app after account compromise

What customers should do now

  1. Change your Chick-fil-A One password to something unique — never reused on email, banking, or shopping sites.
  2. If the same password was reused elsewhere, rotate those accounts too.
  3. Turn on MFA with a verified mobile number in Chick-fil-A One.
  4. Check Have I Been Pwned for your email; treat any hit as a reason to assume password reuse risk.
  5. Watch for phishing that cites “CFA One security” or asks you to “re-link” payment cards — attackers now have more personal context for scams.
  6. Review recent rewards activity and any unexpected Mobile Pay / QR use.

Why Texas businesses should care

BleepingComputer reports Chick-fil-A told the Texas Attorney General the incident affects 2,182 Texans. Beyond consumer loyalty apps, the same credential-stuffing pattern hits Microsoft 365, VPN portals, billing portals, and POS vendor logins when employees reuse passwords.

Retail and hospitality operators in Texas should treat this as a live reminder: password reuse + no MFA turns someone else’s breach into your account takeover. Pair unique passwords (or a manager) with MFA on every customer-facing and staff-facing login — the same lesson as our Fortinet credential-stuffing alert and password-manager policy phishing coverage.

Independent cybersecurity audits

We audited domains tied to this story on July 24, 2026. 100% is the ideal overall score — none of these hosts reach it. Scores reflect public email / transport / website posture, not whether a loyalty login was breached via stuffing.

OrganizationDomainOverallIdentityTransportWebsitevs 100% ideal
Have I Been Pwnedhaveibeenpwned.com88%90%45%100%−12
Cloudflarecloudflare.com88%90%45%100%−12
Malwarebytesmalwarebytes.com72%90%45%45%−28
BleepingComputerbleepingcomputer.com63%75%15%40%−37
Chick-fil-Achick-fil-a.com42%25%15%37%−58
Chick-fil-A (alt)chickfila.com28%0%15%37%−72

How to read this table

  • chick-fil-a.com at 42% (Identity 25%, Transport 15%) sits far below the 100% ideal — soft public identity and mail-transport signals matter for spoofed “security” emails that follow a real stuffing incident.
  • chickfila.com at 28% (Identity 0%) is weaker still; treat lookalike / adjacent brand domains carefully when clicking reset links.
  • haveibeenpwned.com / cloudflare.com lead this set at 88% — useful for breach checks and edge security context, still −12 from ideal.
  • These audits do not measure app MFA enforcement or anti-automation on the mobile login — stuffing succeeds when users reuse passwords, regardless of corporate DNS hygiene.

Audit links

Website stack note

Passive website-tech probes on July 24, 2026 completed for 4 of 4 story domains (0 notable):

DomainStack signal
chick-fil-a.comWordPress (version hidden)
chickfila.comWordPress (version hidden)
malwarebytes.comWordPress (version hidden)
haveibeenpwned.comNo notable public CMS / PHP / short-horizon TLS flags

Hidden WordPress versions are common on hardened marketing sites and do not prove Core is outdated. They also do not explain June’s credential stuffing — that attack abused reused third-party passwords, not a public CMS fingerprint.

These passive observations are point-in-time public signals. They do not prove exploitability, identify a breach path, or establish that a detected major version is unsupported.

Priority actions for IT teams

  1. Ban password reuse on staff and customer portals — enforce managers + unique vault entries.
  2. Require MFA on loyalty, SSO, VPN, and email — SMS MFA is better than nothing; phishing-resistant MFA is better still.
  3. Rate-limit and detect stuffing on login APIs (velocity, impossible travel, known-bad credential feeds).
  4. Hunt spoofed brand email after public notices — Identity gaps on retail domains make fake “reset your CFA One / rewards” mail more believable.
  5. Educate customers and employees that a company’s systems need not be “hacked” for their account to be emptied — reuse is enough.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for MFA rollout, DMARC / MTA-STS work, and login hardening aimed at the 100% ideal.


Sources: Malwarebytes — Chick-fil-A loyalty accounts hijacked using stolen passwords · BleepingComputer — Chick-fil-A discloses data breach after credential stuffing · TechRepublic — One password mistake helped hackers access Chick-fil-A accounts · USA TODAY — Chick-fil-A cyberattack may have exposed customer data