Your support helps us to tell the story
From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.
At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.
The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.
Your support makes all the difference.
Read more
Chick-fil-A is notifying customers across the country that unauthorized parties may have accessed their personal and account information following an automated cyberattack on its website and mobile application last month.
The fast-food chain discovered suspicious login activity targeting certain Chick-fil-A One accounts, according to a data breach notification letter dated July 20 sent to affected consumers and state officials.
In the letter, the company explained that “unauthorized parties launched an automated attack against our website and mobile application between June 17 and June 19, 2026 using account credentials” obtained from an outside source.
An internal investigation completed July 13 confirmed that hackers spent those three days attempting to break into accounts using passwords exposed in a separate third-party breach.
The exposed data included customer names, email and home addresses, phone numbers and birth dates, as well as Chick-fil-A One account details such as membership numbers, mobile pay IDs and QR codes. Hackers may also have seen account reward balances, gift card credits and the last four digits of saved payment cards.
Chick-fil-A is notifying customers across the country that unauthorized parties may have accessed their personal information following a cyberattack in June (Getty/iStock)
The total number of affected customers nationally has not been released by the company. However, state filings indicate the breach affected 2,182 residents in Texas and 39 in Massachusetts, as was first reported by the technology news outlet BleepingComputer.
Notification letters were also submitted to regulators in Washington, D.C., Maryland, New York, North Carolina, Oregon, Vermont and several other states.
To secure compromised accounts, Chick-fil-A forced log-outs, reset customer passwords and removed saved payment methods. The company also restored stolen account balances and added bonus rewards to affected accounts.
“Chick-fil-A takes the protection of personal information seriously,” the company stated in its customer letter. “We regret that this incident occurred and apologize for any inconvenience it may cause you.”
The company advised customers to create unique passwords that are not shared with other online services. Customers seeking assistance can contact Chick-fil-A’s dedicated support line at 888-201-5329 between 9 a.m. and 9 p.m. ET, Monday through Friday.