HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
CHICK-FIL-A, INC.
bd_bc7a098ca8f8cb36 · schema v1 · pii pii-v1
Full breach record for CHICK-FIL-A, INC. →Chick-fil-A, Inc. notified Massachusetts customers of a data security incident involving unauthorized access to Chick-fil-A One accounts. Between June 17 and 19, 2026, attackers used stolen credentials from a third-party source to access customer data, including names, emails, membership numbers, and partial credit card details. Chick-fil-A reset passwords, removed stored payment methods, and restored account balances.
Massachusetts clock✓ MA AG ≤30d12 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1188-chick-fil-a-inc/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 1, 2026
- Raw hash
- c12ad7cd9642c409733910d4508d4c4e89fd2386821aff4f77d7a101cfa341ff
Reporting entity
- Name
- CHICK-FIL-A, INC.norm: chick fil a
Victim entity
- Name
- CHICK-FIL-A, INC.norm: chick fil a
Incident
- Discovered
- Jun 19, 2026
- Materiality determined
- —
- Notification sent
- Jul 20, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 12 days(12 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.