Chick-fil-A data breach: What customers need to know
ATLANTA, Ga. (Atlanta News First) — Chick-fil-A’s website and app were targeted in an attack last week, putting some customers’ personal information at risk, according to the company.
In a letter to affected customers, the Atlanta-based fast food restaurant said “unauthorized parties” used email addresses and passwords from a third-party source to log into Chick-fil-A One accounts between June 17-19.
Read the letter:
The following information could have been accessed:
- Your name
- Your email address
- Your Chick-fil-A One membership number and mobile pay number
- Your QR code
- The last four digits of your credit/debit card number
- Any credit on your account
- Your birthday, phone number and address, if you saved that information to your account
In response, Chick-fil-A said it has forced logouts and removed stored payment methods. Customers may be tapped to reset their passwords and re-enter payment information. Chick-fil-A said it has also added rewards to people’s accounts.
In a statement, Chick-fil-A said the breach affected “a limited number” of accounts.
“We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day,” the company continued.
Customers are now asked to scan their financial accounts for any unauthorized transactions. If you find any, notify your financial institution. You can also report identity theft or fraud to the Federal Trade Commission and the state Attorney General’s office.
This is a developing story. Check back with Atlanta News First as we learn more.
Copyright 2026 WANF. All rights reserved.














