Chick-fil-A, Inc. notified Massachusetts customers of a data security incident involving unauthorized access to Chick-fil-A One accounts. Between June 17 and 19, 2026, attackers used stolen credentials from a third-party source to access customer data, including names, emails, membership numbers, and partial credit card details. Chick-fil-A reset passwords, removed stored payment methods, and restored account balances.