As of July 23, 2026, the procedural posture is the awkward part: there is a new Chick-fil-A credential stuffing breach, firms are already looking for affected customers, but no 2026 class action has been filed yet. The prior consumer litigation over Chick-fil-A’s 2022-2023 incident did produce a federal class action in 2023, then a settlement in principle, then very little public guidance because the settlement terms were not disclosed. That leaves the 2026 incident sitting in a familiar but unsettled place: enough smoke for plaintiff lawyers to investigate, not yet enough record to know which claims will survive.
The comparison matters more than any generic breach checklist. Chick-fil-A’s 2022-2023 incident affected 71,473 accounts and was described as an automated credential stuffing attack using credentials obtained from third-party sources, not a direct intrusion into Chick-fil-A’s own systems.[1] A proposed class action, Stephens et al. v. Chick-fil-A, Inc., was filed on March 6, 2023 in the Northern District of Georgia, alleging negligence, breach of implied contract, breach of confidence, state consumer protection violations, and unjust enrichment; by October 2023, the case had reached a settlement in principle and was administratively closed, with no public settlement terms.[2] The 2026 incident, also described as credential stuffing, reportedly occurred June 17-19, 2026, was discovered July 13, 2026, and triggered state attorney general notifications beginning July 20, 2026.[3]

The Two Incidents Do Not Line Up Neatly, But They Rhyme
| Issue | 2022-2023 incident | 2026 incident |
|---|---|---|
| Attack type | Automated credential stuffing using credentials from third-party sources.[1] | Credential stuffing attack reported by Chick-fil-A and breach coverage.[3] |
| Known timing | Customer complaints surfaced in January 2023; Chick-fil-A confirmed the incident in March 2023.[1] | Attack reported for June 17-19, 2026; discovered July 13; notifications began July 20.[3] |
| Known scope | 71,473 accounts.[1] | Total not publicly known; reported state counts include Texas 2,182, Massachusetts 39, and Vermont 2.[3][4] |
| Litigation status | Federal class action filed March 6, 2023; settlement in principle by October 2023; terms undisclosed.[2] | No filed 2026 class action identified as of July 23, 2026; law firms are investigating potential claims.[5] |
| Affected account features | Customer accounts, stored value, rewards, and linked payment concerns formed part of the public dispute.[1][2] | Notices described data including name, email, loyalty points, and payment methods, but not full credit card PANs.[3] |
That table is the case. One credential stuffing incident lets a defendant say the real breach happened elsewhere, on another site where the consumer reused a password. A second similar incident three years later invites a different question: after the first round of account takeovers, complaints, password resets, and litigation, what did Chick-fil-A know about the risk to its loyalty accounts, and what security measures were reasonable for accounts that can hold rewards, gift card value, and saved payment methods?
That does not make liability automatic. Credential stuffing is not the same as a hacker breaking into a company database and exfiltrating a file of customer records. The contested point is causation. If criminals arrive with usernames and passwords already compromised somewhere else, Chick-fil-A has a straightforward defense: the company did not create the stolen credentials. A plaintiff has to plead around that without pretending the phrase “data breach” answers the Article III injury problem by itself.
Standing Is the First Fight, Not a Technicality
In a consumer data case, standing asks whether the named plaintiff has a concrete injury that is fairly traceable to the defendant and likely redressable by a court. After TransUnion, courts have been more demanding about abstract risk, especially where information was allegedly mishandled but not clearly misused or publicly disclosed. One relevant standing development from the Fourth Circuit in October 2025 required public disclosure of misused information before recognizing injury, the sort of doctrine that makes credential stuffing complaints harder to plead than classic intrusion cases.
For Chick-fil-A consumers, the strongest standing allegations will not be “my information was exposed” in the abstract. They will be account-specific: rewards points disappeared; stored gift card value was drained; an unauthorized order was placed; a saved payment method was used or had to be removed; the consumer spent time recovering the account; the account was locked; or the consumer received notice that their account was among those accessed. Those facts move the case away from speculative future risk and toward actual misuse.
The most useful fact from the 2023 public record is not the 71,473 figure. It is the reported sale of compromised Chick-fil-A accounts on Telegram for $2 to $200, depending on account balance and linked payment methods.[6] That matters because it gives the injury a market. A loyalty account with stored value is not merely a profile page with stale contact information; it can be monetized, priced, transferred, and drained. In a complaint, that fact does work that adjectives cannot.
Chick-fil-A’s remedial conduct also matters, though it should not be overstated. For the 2026 incident, reported measures included forced password resets, removal of saved payment methods, and restoration of stolen rewards or gift card balances.[3] Those steps are not admissions of legal fault. They may reduce out-of-pocket damages if balances are restored. But they also identify the mess that had to be cleaned up: account access was lost, stored payment features were treated as risky enough to remove, and rewards or gift card value had to be put back.
Why Credential Stuffing Makes Causation Harder
Credential stuffing is built on reuse. Attackers take usernames and passwords obtained from other breaches or illicit sources and test them at scale against a target account system. If the consumer reused a password, and if the target site lacks enough friction, the attacker may get in. That mixed causation is what makes the litigation posture uncomfortable.
Chick-fil-A can argue that it did not lose the credentials, did not publish them, and did not cause consumers to reuse passwords. Plaintiffs will answer that account security is not limited to guarding a password database. A company that designs a sticky loyalty account, encourages saved payment methods, permits stored rewards or gift card balances, and knows credential stuffing is a recurrent attack vector may have to adopt reasonable defenses against automated account takeover.
That is where the second incident changes the complexion of the dispute. The 2023 Stephens complaint reportedly alleged that Chick-fil-A failed to implement adequate security measures, including multi-factor authentication, despite known credential stuffing risks.[2] Whether that theory would win is a separate question. But after a prior incident, prior litigation, and prior remediation, a 2026 plaintiff has a clearer notice story than a plaintiff bringing the first credential stuffing case against a company.
The notice story still needs proof. Plaintiffs would want to know what Chick-fil-A changed after 2023, whether optional or required MFA existed for the relevant accounts, what bot detection or rate-limiting controls were in place, whether anomalous login attempts were flagged, how quickly unauthorized access was detected, and whether account value could be spent or transferred without meaningful step-up authentication. None of those facts can be assumed from the notices alone.
The 2023 Complaint Is a Menu, Not a Guarantee
The Stephens theories give 2026 lawyers a starting menu: negligence, implied contract, breach of confidence, consumer protection statutes, and unjust enrichment.[2] The mistake would be to copy them over as if settlement in principle validated each claim. Settlement means pressure, risk, cost, or business judgment. Because the terms were not publicly disclosed, it does not provide a public valuation, a claims rate, an approved damages model, or a ruling that any theory was legally sufficient.
Negligence
Negligence will likely be the central claim if a 2026 class action is filed. The theory would be that Chick-fil-A owed consumers a duty to use reasonable security for loyalty accounts and breached that duty by failing to prevent or limit automated account takeover. The better version of the claim will focus less on a generalized duty to stop all crime and more on known risks tied to specific account features: stored value, rewards balances, linked payment methods, and repeat credential stuffing.
The friction point is foreseeability and causation. If the credentials came from third-party sources, a court may ask whether Chick-fil-A’s conduct caused the injury or merely failed to stop a criminal using information obtained elsewhere. A plaintiff with actual account misuse has a better answer than a plaintiff who only received a notice and fears future harm.
Implied Contract
The implied contract theory is straightforward in outline: consumers created and used Chick-fil-A accounts, provided information, and participated in the loyalty program with the expectation that the company would apply reasonable security. The hard part is showing the promised security term with enough specificity. If the account terms disclaim broad obligations or push security duties back onto users, plaintiffs will need to rely on the structure of the transaction and Chick-fil-A’s own account design rather than a clean written promise.
Breach of Confidence
Breach of confidence is more sensitive to the nature of the information and the relationship. It is easier to understand when a defendant receives sensitive information in a relationship carrying confidentiality expectations. In a restaurant loyalty account case, the claim may have to work harder. Names, emails, loyalty points, and payment-method references are not trivial, but they are not all treated alike by courts. The claim becomes stronger if the plaintiff can tie the account to stored value, purchase history, or other information that made unauthorized access meaningfully invasive.
Consumer Protection Statutes
State consumer protection claims will depend heavily on the state, the named plaintiff, and the challenged statement or omission. Plaintiffs may allege that Chick-fil-A represented or implied that account information and stored value would be reasonably protected, or that it omitted material weaknesses after prior credential stuffing experience. The defense will ask what statement was false when made, whether reliance is required, and whether the alleged injury is economic enough for the statute.
This is also where breach notification law becomes uneven. The Privacy Rights Clearinghouse’s 2026 survey reports that 24 states, or 47%, provide a private right of action for breach notification violations, while 26 do not.[7] That means a late or deficient notice theory may be viable for some consumers and unavailable to others even if they received the same Chick-fil-A notification.
Unjust Enrichment
Unjust enrichment is often pleaded as a fallback: consumers conferred value through their data, purchases, loyalty participation, or saved account features, and Chick-fil-A allegedly retained that value while failing to provide reasonable security. Courts vary in how much patience they have for that theory when an express contract governs the account relationship. It may survive longer where plaintiffs can identify a specific benefit retained by the company and a specific security-related failure, rather than treating all account revenue as unjustly retained.
California and Notice Claims May Matter More Than the Caption Suggests
California consumers sit in a different posture because the CCPA provides a private right of action for certain data breaches, with statutory damages of $100 to $750 per consumer per incident where covered personal information is subject to unauthorized access and exfiltration, theft, or disclosure because of a business’s failure to maintain reasonable security.[7] That is not the same as saying every California Chick-fil-A user has a CCPA claim. The statute has definitions, cure issues, covered-data questions, and a reasonable-security requirement. But it gives California plaintiffs a statutory damages path that many other consumers will not have.
For non-California consumers, state law variation may decide whether the case is mainly about actual account loss, time spent, privacy injury, or notification defects. A Texas consumer whose rewards were drained and restored may have a different damages problem from a Massachusetts consumer whose notice arrived but who cannot identify misuse. A Vermont consumer may have yet another statutory framework. The partial state counts now public — Texas 2,182, Massachusetts 39, Vermont 2 — are useful for venue and notice analysis, but they do not reveal the full national scope of the 2026 incident.[3][4]
Restoration Helps Consumers, But It Does Not End the Legal Analysis
If Chick-fil-A restored rewards or gift card balances, that is practically valuable. Consumers want their account value back, not a lecture about Article III. But restitution can change the damages picture without eliminating every claim. A restored balance may reduce or wipe out a straightforward out-of-pocket loss. It does not necessarily compensate for time spent regaining account control, loss of use, privacy invasion, unauthorized account activity, or statutory damages where a statute supplies them.
The better plaintiff cases will be documented. Screenshots of unauthorized orders, rewards redemptions, account-lock messages, password reset emails, payment-method removal notices, customer service communications, and before-and-after points balances are not busywork. They are the difference between a notice-recipient theory and a misuse theory. In credential stuffing litigation, that difference can decide standing before discovery ever reaches the security controls.

The Undisclosed 2023 Settlement Is Useful, But Only Up to a Point
The 2023 settlement in principle tells plaintiff lawyers that Chick-fil-A chose not to litigate the first class action to a public merits resolution.[2] That is meaningful as background pressure. It is not a public benchmark for the 2026 case. There is no disclosed common fund, no published injunctive relief, no claims process to compare, no class member payment structure, and no judicial opinion blessing a particular theory.
That absence cuts both ways. Plaintiffs cannot point to the 2023 settlement as a valuation anchor. Chick-fil-A cannot point to a public remedial package and say the issue was definitively solved. What remains visible is repetition: same general attack vector, same account ecosystem, and another round of consumers being told that access to loyalty accounts required cleanup.
The broader litigation market explains why firms are watching. More than 3,000 data breach class actions were reportedly filed in 2025, and the top 10 data breach class action settlements that year totaled $515.79 million.[8] Those numbers do not prove Chick-fil-A’s 2026 incident is worth any particular amount. They explain why a repeat account-takeover incident at a national consumer brand will be screened quickly.
What a Strong 2026 Complaint Would Likely Need
A viable 2026 complaint would likely need named plaintiffs with more than anxiety. The best candidates would have documented account takeover, loss or attempted use of rewards or gift card value, unauthorized payment-related activity, forced security changes, or meaningful time spent resolving the incident. If the complaint relies only on notice letters and the possibility of future misuse, Chick-fil-A’s standing motion will write itself.
- Concrete misuse: unauthorized login, order activity, points redemption, gift card depletion, or account lockout.
- Traceability facts: allegations connecting the account takeover to Chick-fil-A’s security choices after the prior incident, not merely to password reuse.
- Security theory: a nonconclusory explanation of what reasonable measures were allegedly missing, such as MFA, bot detection, rate limiting, step-up authentication, or payment-method safeguards.
- Jurisdictional fit: named plaintiffs from states with usable consumer protection, notification, privacy, or statutory damages theories.
- Damages discipline: separate restored balances from unreimbursed loss, time loss, privacy injury, and statutory damages.
The complaint also has to be careful with the 2023 history. The useful allegation is not that the prior settlement proves wrongdoing. It does not. The useful allegation is notice: Chick-fil-A had already experienced credential stuffing against its account system, had already faced consumer litigation over that vector, and had already taken remedial steps. A recurrence may support a reasonable-security theory if plaintiffs can identify what should have changed and how the alleged gap caused their injuries.
Where Consumers Stand Now
Consumers affected by the 2026 incident can preserve evidence, monitor their notices, document account activity, change reused passwords, watch linked payment methods, and consult counsel if they had actual account misuse or meaningful recovery time. Those are practical steps, but the legally meaningful next event is not another investigation page from a law firm. It is the filing of a 2026 complaint, if one comes, and the quality of the named plaintiffs’ injury allegations.
The Chick-fil-A matters are not a clean plaintiff win or a defense throwaway. They sit in the hard middle of modern account-takeover litigation. The credentials allegedly came from elsewhere, which gives Chick-fil-A a causation defense. The accounts were allegedly sold, drained, reset, stripped of payment methods, and restored, which gives consumers concrete injury facts. The 2023 case settled without a public roadmap. The 2026 case has not yet been filed. That is where the record stops.
References
- Chick-fil-A confirms accounts hacked in months-long 'automated' attack, BleepingComputer, March 3, 2023.
- Chick-fil-A Data Breach Affecting Over 71K People Triggers Class Action Lawsuit, ClassAction.org.
- Chick-fil-A discloses data breach after credential stuffing attacks, BleepingComputer, July 13, 2026.
- Chick-fil-A warns customers in 10 states and D.C. after cyberattack, The Washington Times, July 22, 2026.
- Chick-fil-A Data Breach Investigation, Cole Van Note, July 21, 2026.
- Chick-fil-A Customers Have a Bone to Pick After Account Takeovers, Dark Reading.
- Data Breach Notification Laws: A 50-State Survey (2026 Edition), Privacy Rights Clearinghouse, 2026.
- Data breach class action litigation and settlement data, IAPP data cited in source materials, 2025.