1
1In June 2024, Chick-fil-A experienced a cyberattack that exposed information from some customers’ Chick-fil-A One loyalty accounts. A law firm called Dapeer Law, P.A. is now investigating whether a class action lawsuit should be filed on behalf of affected customers in Texas and Massachusetts.
Key Timeline
- June 17–19: Attackers tried to access accounts
- July 13: Chick-fil-A confirmed attackers may have accessed account info
- July 20: Company began notifying affected customers
Imagine you use the same key for your house, your car, and your office. If a thief steals that key from your office, they can now unlock your house and car too.
That’s basically what happened here. Hackers took usernames and passwords stolen from OTHER websites and tried them on Chick-fil-A accounts. This is called a "credential stuffing attack."
According to state filings obtained by the law firm:
| State | Number of People Affected |
|---|---|
| Texas | 2,182 |
| Massachusetts | 39 |
| Total | 2,221 |
The investigation currently focuses on customers in Texas and Massachusetts who received breach notification letters.
The data accessed varied by person, but could include:
Important: Full credit card numbers were NOT exposed—only the last 4 digits.
Dapeer Law, P.A. is investigating whether Chick-fil-A’s security measures met legal standards during this attack.
Chick-fil-A released a statement saying they:
Chick-fil-A recommends taking these steps right away:
Pro Tip: Use a password manager (like Bitwarden, 1Password, or your phone’s built-in one) to create and remember strong, unique passwords for every site.
CALL OUT: DON’T PANIC — TAKE ACTION
- This was a limited breach (2,221 accounts out of millions)
- No full credit card numbers were stolen
- Chick-fil-A acted quickly to secure accounts
- You have control: Change your password, use unique ones, monitor statements
- The investigation is early stage — no lawsuit filed, no liability determined
In June 2024, hackers used passwords stolen from other websites to break into 2,221 Chick-fil-A One loyalty accounts (mostly in Texas). They may have seen names, emails, partial payment info, and — for some — addresses and birthdays. Chick-fil-A secured the accounts, notified customers, and reset balances. A law firm is now checking if Chick-fil-A’s security was legally sufficient. No lawsuit has been filed yet. If you got a notification letter, change your password now and use a unique one going forward.
No. Only the last 4 digits of payment cards were potentially exposed. Full card numbers were not stored in the loyalty accounts.
Chick-fil-A sent notification letters to all 2,221 affected customers in July 2024. If you didn’t get a letter, you likely weren’t impacted.
It’s when hackers take username/password combos leaked from one site and try them on other sites — hoping people reused the same password. It works because many people use the same password everywhere.
Too early to say. The law firm is only investigating right now. No lawsuit has been filed. If you’re in Texas or Massachusetts and got a notification letter, you can contact Dapeer Law to stay informed.
Yes. Chick-fil-A has secured the affected accounts, forced password resets, removed stored payment methods, and restored balances. Just make sure you’ve updated your password to a unique one!
Stay safe online — and enjoy that chicken sandwich!