- The Washington Times - Thursday, July 23, 2026

Chick-fil-A is sending out a letter warning certain customers in the District of Columbia, Maryland and eight other states about a recent data breach.

In the letter uploaded online by Massachusetts officials, Chick-fil-A said that from June 17-19 “unauthorized parties” using the restaurant’s loyalty account credentials acquired from a third party attacked the company’s website and app and got access to customer data.

Chick-fil-A said it figured out by July 13 which loyalty accounts were affected and that stolen information could include names, email addresses, Chick-fil-A loyalty account and mobile pay numbers, Chick-fil-A credit that customers had on their accounts, and the last four digits of credit and debit cards.



Once the company learned what happened, it forcibly logged the affected accounts out of its website and app, cleared the stored payment methods on those accounts and restored the credit balances to any customers whose balance was affected. Chick-fil-A also said it added free rewards to the affected accounts.

In addition to the District and Maryland, affected customers are in Iowa, Massachusetts, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont, per the letter.

“Upon discovering the issue, we took steps to immediately address, secure and restore accounts, and we are communicating directly with all customers who may have been impacted. We sincerely apologize for any inconvenience or concern this situation may have caused and remain committed to maintaining the trust our guests place in us every day,” a Chick-fil-A spokesperson told The Atlanta Journal-Constitution.

Contact the author

Copyright © 2026 The Washington Times, LLC. Click here for reprint permission.

Please read our comment policy before commenting.