CHICK-FIL-A, INC.
ent_019e22fc94bdc2407b2b2bc6fcf125cf
Disclosures
10
State AG · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
71,473
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CHICK-FIL-A, INC.
- Normalized
- chick fil a— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300BY26GXF5YHV453
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- Texas State AGas victim2026-07-21
Chick-fil-A, Inc. based in Atlanta, Georgia, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-07-13 and reported on 2026-07-21. 2,182 Texas residents were affected. 13,322 individuals affected in total. Types of information involved: Name of individual;Address;Financial Information (e.g. account number, credit or debit card number). Consumers were notified via Email.
- Vermont State AGas victim2026-07-20
Chick-fil-A, Inc. reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-20. The reporting organization type is Other Commercial. 2 Vermont residents were affected. Categories of data breached: Financial Account Codes, Credit and Debit Account Info.
- Massachusetts State AGas victim2026-07-20
Chick-fil-A, Inc. notified Massachusetts customers of a data security incident involving unauthorized access to Chick-fil-A One accounts. Between June 17 and 19, 2026, attackers used stolen credentials from a third-party source to access customer data, including names, emails, membership numbers, and partial credit card details. Chick-fil-A reset passwords, removed stored payment methods, and restored account balances.
- Nebraska State AGas victim2026-07-20
Chick-fil-A, Inc. notified Nebraska residents of a data security incident involving unauthorized access to Chick-fil-A One accounts. Between June 17 and 19, 2026, attackers used credentials from a third-party source to access customer data, including names, emails, membership numbers, and partial credit card info. Chick-fil-A reset passwords, forced logouts, and restored balances.
- South Carolina State AGas victim2023-03-03
Chick-fil-A, Inc. notified customers of a supplemental data security incident involving unauthorized access to Chick-fil-A One accounts. Attackers used credentials from a third-party source to access accounts between Dec 18, 2022 and Feb 12, 2023. Data accessed included names, emails, membership numbers, and masked payment card info. Chick-fil-A engaged forensic investigators, reset passwords, and froze accounts.
- Massachusetts State AGas victim2023-03-02
Chick-fil-A, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-03-02. 524 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2023-03-02
Chick-fil-A, Inc. issued a supplemental notification regarding a data security incident involving Chick-fil-A One accounts. Unauthorized parties used stolen credentials to access customer data between December 18, 2022, and February 12, 2023. Affected data included names, emails, membership numbers, and masked payment card details. Chick-fil-A engaged forensic investigators, reset passwords, and froze accounts.
- California State AGas victim2023-03-02
Chick-fil-A, Inc. disclosed that unauthorized parties launched an automated attack against its website and mobile application between December 18, 2022, and February 12, 2023. The attackers used account credentials (email addresses and passwords) obtained from a third-party source to access Chick-fil-A One accounts. Affected data included names, email addresses, membership numbers, masked payment card numbers, and potentially phone numbers and addresses. Chick-fil-A responded by resetting passwords, removing stored payment methods, and freezing account funds.
- New Hampshire State AGas victim2023-03-02
Chick-fil-A, Inc. notified the NH Attorney General of a data security incident involving unauthorized access to Chick-fil-A One accounts. Attackers used stolen credentials from a third-party source to access customer data between Dec 18, 2022 and Feb 12, 2023. 82 NH residents were affected. Data included credentials, payment info, and account balances. Chick-fil-A engaged forensic investigators, reset passwords, and froze funds.
- Maine State AGas victim2023-03-02
Chick-fil-A, Inc. disclosed a data breach affecting 61 Maine residents. The breach, which occurred between December 18, 2022, and February 12, 2023, was discovered on February 12, 2023. The incident was categorized as an external system breach or hacking, resulting in the compromise of customers' names and financial account information, including credit/debit card numbers along with their security codes or PINs. Affected individuals were notified electronically on March 2, 2023.