CHICK-FIL-A, INC.
bd_ccfa79c0c2c59279 · schema v1 · pii pii-v1
Full breach record for CHICK-FIL-A, INC. →2 incidents on fileChick-fil-A, Inc. notified Nebraska residents of a data security incident involving unauthorized access to Chick-fil-A One accounts. Between June 17 and 19, 2026, attackers used credentials from a third-party source to access customer data, including names, emails, membership numbers, and partial credit card info. Chick-fil-A reset passwords, forced logouts, and restored balances.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 17, 2026
Begins
Jun 17, 2026
Discovered
Jul 20, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Vermont State AGbd_8778e71dddebf90c2026-07-20Verified
- Massachusetts State AGbd_bc7a098ca8f8cb362026-07-20Verified
- Texas State AGbd_fd713c5d5227ef602026-07-21 · +1dCandidate
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.