ATLANTA, July 23 (Nationwide Times) — Chick-fil-A says a recent security incident may have exposed personal information tied to a limited number of Chick-fil-A One loyalty accounts.
Here is what the company has said, what information may have been involved, and why the notices matter.
What Chick-fil-A said happened
Chick-fil-A said it found suspicious login activity involving certain Chick-fil-A One accounts. In the later incident described by the company, unauthorized parties targeted Chick-fil-A’s website and mobile app between June 17 and June 19, according to a company notice described by FOX Business.
The company said the attackers used account credentials obtained from a third-party source. Chick-fil-A also said it moved quickly to secure the affected accounts and notify customers who may have been impacted.
The company said the incident affected customers in Iowa, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island, Vermont, and Washington, D.C.
A separate notice Chick-fil-A filed with Massachusetts described earlier suspicious login activity to certain Chick-fil-A One accounts between Dec. 18, 2022, and Feb. 12, 2023. In that notice, Chick-fil-A said it determined on Feb. 12, 2023, that unauthorized parties had accessed information in affected accounts.
The available records do not make it clear whether those notices describe separate incidents or a broader pattern of account access.
What information may have been exposed
For the later incident, Chick-fil-A said the information that may have been compromised included names, email addresses, Chick-fil-A One membership and mobile payment numbers, the last four digits of payment cards, and the amount of Chick-fil-A credit stored in accounts.
In the Massachusetts notice from March 2, 2023, Chick-fil-A said the information may have included names, email addresses, membership numbers, mobile pay numbers, QR codes, masked credit or debit card numbers, and Chick-fil-A credit balances. It also said saved birthday month and day, phone numbers, and addresses may have been included.
In both notices, Chick-fil-A said unauthorized parties could only view the last four digits of a payment card number.
What Chick-fil-A says it did
Chick-fil-A said it reset passwords for affected accounts. In the later incident, the company said it restored impacted loyalty balances and added rewards to customer accounts.
In the earlier Massachusetts notice, Chick-fil-A said it required password resets, removed stored credit and debit card payment methods, temporarily froze funds loaded onto Chick-fil-A One accounts, restored account balances, and added rewards.
How many people were affected?
Chick-fil-A has not publicly identified the exact number of affected accounts in the sources reviewed.
MarketWatch reported that Chick-fil-A said fewer than 2% of Chick-fil-A One loyalty-program participants were affected.
What this means for customers
Chick-fil-A One is the company’s loyalty program. Based on the company’s notices, the concern was not a full website shutdown or a broad public leak, but account access tied to a limited number of loyalty accounts.
The company said it was contacting customers who may have been impacted. The notices do not say that customer information was misused, only that it may have been exposed.
They also do not explain how the third-party credentials were obtained or by whom.
For customers, the key point is that Chick-fil-A treated the event as an account-security issue and said it took steps to secure the accounts, restore balances, and warn affected members.
