Chick-fil-A customers in 10 states may have had data breached – NBC New York


Chick-fil-A is warning customers from 10 states and Washington, D.C., about a data breach last month that potentially exposed sensitive information for loyalty members.
The fast-food chain sent a letter to customers about a cyberattack on the company’s website and mobile app between June 17 and 19. Names, email addresses, loyalty membership numbers, the last four digits in credit and debit card numbers and Chick-fil-A credit are among the information that was accessed.
The state of Massachusetts posted the letter, which indicated that customers were also affected in Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont and Washington, D.C. Separately, the state of Texas said 2,182 of its residents were affected by the breach.
“Based on our investigation, we determined on July 13, 2026 that the unauthorized parties may have accessed information in your Chick-fil-A One account,” the letter said.
The company said it reset impacted customers’ Chick-fil-A passwords, advised them to update their passwords as soon as possible, forced logouts and removed stored payment methods. It said it also restored impacted customers’ Chick-fil-A One account balances and added rewards to their accounts.
Chick-fil-A encouraged customers to remain vigilant against potential identity theft and the review credit reports and account statements to ensure their activity was valid.
The company insisted it “continues to enhance its security, monitoring, and fraud controls as appropriate to minimize the risk of any similar incident in the future.”


