Tendvane

← All articles

AccountsJuly 23, 2026

Chick-fil-A's app just got broken into - and the lesson applies to almost every account you own

Chick-fil-A told customers this week that some of their loyalty accounts were broken into. The interesting part isn't the restaurant - it's how the attackers got in. They didn't crack Chick-fil-A's security. They logged in with real usernames and passwords, using details stolen from other websites and typed into the app by bots.

It's a technique called credential stuffing, and it only works because so many of us reuse the same password everywhere. Between June 17 and 19, automated bots ran millions of stolen email-and-password combinations against Chick-fil-A One. Where the password matched, they got in - and MFA wasn't switched on to stop them. The company began notifying people on July 22. What was exposed varies by account: names, email addresses, membership and mobile-pay numbers, QR codes, your Chick-fil-A credit balance, and the last four digits of a card. State filings so far list a few thousand affected, with the national total undisclosed. This is the chain's second such incident in three years.

If you have a Chick-fil-A account, set a new password there - and here's the key move most people skip: make it one you use nowhere else, then turn on multi-factor authentication, which the app supports. That alone would have blocked this attack cold.

The real fix is to stop reusing passwords across sites, so one leaked login can't unlock the rest. Tendvane's Privacy & accounts check tells you which of your accounts have shown up in known breaches, so you know exactly which passwords to retire first.

Sources

Download Tendvane