Life

Chick-fil-A Security Breach: Were Your Rewards Hacked?

Hackers slipped into Chick-fil-A One loyalty accounts across several states — see what data may have been exposed and if your rewards were hit too.

Chick-fil-A Customers May Have Been Subjected to a Security Breach
Photo Illustration by Timon Schneider/SOPA Images/LightRocket via Getty Images

Key Takeaways

  • Chick-fil-A says a June 17–19 security incident let outsiders into a limited number of Chick-fil-A One accounts using login credentials stolen from a third party.
  • Exposed data may include names, emails, loyalty numbers, mobile payment numbers, last four digits of linked cards, and stored Chick-fil-A credit for customers in several states and Washington, D.C.
  • The chain reset affected passwords, restored loyalty balances, added rewards, and publicly apologized, while declining to say how many accounts were hit, as it simultaneously promotes the return of Cow Appreciation Day.

Chick-fil-A customers have a new reason to check their accounts. The fast-food giant confirmed on Wednesday, July 22, that unauthorized parties accessed a limited number of Chick-fil-A One loyalty accounts, potentially exposing customers’ personal and payment-related information.

According to Fox Business, the attackers reportedly targeted Chick-fil-A’s website and mobile app between June 17 and June 19. According to a notice sent to affected customers, they used login credentials obtained from a “third-party source” to break into the accounts. Chick-fil-A detected the suspicious activity and began notifying potentially affected customers.

“We recently identified a security incident that may have affected a limited number of Chick-fil-A One Loyalty accounts,” a company spokesperson told Fox Business. “Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted.”

The information that may have been exposed includes customers’ names, email addresses, Chick-fil-A One membership numbers, mobile payment numbers, the last four digits of linked payment cards, and stored Chick-fil-A credit balances.

Customers in Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont and Washington, D.C., were reportedly affected.

Chick-fil-A reset passwords for the compromised accounts, restored affected loyalty balances and added rewards for impacted customers. A spokesperson “sincerely apologize[d] for any inconvenience or concern” and said the chain remains “committed” to maintaining customer trust. The company has not disclosed exactly how many accounts were accessed.

The security scare comes shortly after Chick-fil-A brought back Cow Appreciation Day for its 80th anniversary. On July 14, customers who showed up dressed like cows received free entrées at participating restaurants, marking the promotion’s first appearance since 2019. The company paused the annual event in 2020 because of the COVID-19 pandemic.

Chick-fil-A’s famous cows have urged customers to “Eat Mor Chikin” since the deliberately misspelled slogan hit an Atlanta billboard in 1995. The campaign has since expanded into commercials, merchandise, games, and the Chick-fil-A Play app.

Related Stories

Chick-fil-A Sued by U.S. Government for Religious Discrimination
Life

The U.S. Government is Suing a Texas Chick-fil-A for Religious Discrimination

The EEOC says a Texas franchise fired a Sabbath-observing manager. Inside the clash between Chick-fil-A’s Christian branding and federal law.

Chick-fil-A is Breaking a Food Promise It Made a Decade Ago—And Bird Flu is to Blame
Life

Chick-fil-A Says Bird Flu Could Derail Its Cage-Free Egg Promise

Bird flu has disrupted egg supply nationwide, but is that the whole story behind Chick-fil-A’s cage-free timeline? Inside the pressure from shifting laws and supply challenges.

Chick-fil-A Employee Arrested After $80K of Mac & Cheese Fraud
Life

Ex–Chick-fil-A Worker Accused of $80K Fraud Scheme Using Mac and Cheese

Authorities say the former employee slipped back behind the counter, ran roughly 800 fraudulent mac and cheese orders, and funneled about $80,000 to his own accounts.

Stay ahead on Exclusives

Download the Complex App