Some Chick-fil-A accounts were hacked last month, exposing the personal information of an undisclosed number of customers, the company said this week.
The data potentially accessed in the hack included customers’ names, email addresses, last four digits of stored credit/debit cards, month and day of their birthdays, phone numbers and addresses, according to a letter sent to the Massachusetts attorney general dated Monday.
A Chick-fil-A spokesperson said the security incident affected “a limited number” of Chick-fil-A One accounts, according to a statement provided to The Atlanta Journal-Constitution. Chick-fil-A One is the company’s loyalty program, which launched in 2016.
“Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted,” the spokesperson said. “We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day.”
Chick-fil-A said in the letter to the Massachusetts AG that between June 17 and 19, “unauthorized parties launched an automated attack against our website and mobile application” using account credentials the hackers had gotten from third-party sources.
The company conducted an investigation and “immediately took action to protect customers’ accounts, which included forcing log-outs of affected accounts and removing any stored payment methods,” the company said.
It also reset the affected accounts’ passwords, restored any account balances and added a reward for the impacted customers. Cybernews site BleepingComputer first reported the breach.
It’s unclear if any Georgia residents were part of the breach.
In Massachusetts, 39 residents were impacted, according to a state data breach report. In Texas 2,182 residents were hacked, the company told the state.
States have different requirements when it comes to disclosures of data breaches. Georgia law requires that residents whose information may have been exposed be notified “in the most expedient time possible and without unreasonable delay,” without setting a deadline or requiring companies to also inform any state agency.
But some states have a specific disclosure process, typically through their attorney general’s office.
In its letter to the Massachusetts AG, Chick-fil-A detailed ways residents of the District of Columbia, Iowa, Maryland, Massachusetts, New Mexico, North Carolina, Oregon, Rhode Island and Vermont could fight identity theft, though it’s unclear if customers in all those states were impacted.
College Park-based Chick-fil-A is the third-largest fast-food chain in the U.S. in terms of sales. Last year, the company grew its system-wide sales to nearly $24 billion. Chick-fil-A operates more than 3,000 restaurants in the U.S. and Canada and has also expanded internationally.
The company has previously reported security issues. In early 2023, Chick-fil-A reported “suspicious activity” on some Chick-fil-A One accounts.
The company months later pinpointed the source of a security breach on its website and mobile app, saying unauthorized parties launched an “automated attack” using email addresses and passwords from a third-party source. Chick-fil-A said at the time that fewer than 2% of app users were affected by the data breach.
Chick-fil-A is the second major Georgia company in the last week to disclose a security breach. Late last week, Coca-Cola announced it was suspending the U.S. production of its dairy brand Fairlife after it was hit a ransomware attack. It is unclear when production will resume.
Keep Reading
The Latest
Featured





