Data Breach · Case Dismissed

Chick-fil-A Data Breach Class Action Voluntarily Dismissed Six Weeks After It Was Filed

Published September 10, 2026

Chick-fil-A One members caught in the June 2026 credential-stuffing breach were covered by a proposed class action alleging the chain failed to secure their loyalty accounts — but the named plaintiff withdrew that case without prejudice on September 1, 2026, so no Chick-fil-A breach case is pending and there is nothing to file.

Chick-fil-A data breach class action lawsuit over the June 2026 Chick-fil-A One loyalty account credential stuffing attack
Allegations Only · Never Decided · Case Dismissed

This article describes a class action complaint that was voluntarily withdrawn before Chick-fil-A ever answered it. The statements below are unproven allegations. Chick-fil-A has not been found liable, no court ruled on the merits, there is no certified class, and there is nothing to claim. This page is general information, not legal advice.

Is the Chick-fil-A Data Breach Lawsuit Dismissed?

Yes. The proposed class action over Chick-fil-A's June 2026 loyalty-account breach was voluntarily dismissed on September 1, 2026, and the civil case was terminated the same day. The case is Williams v. Chick-fil-A, Inc., No. 1:26-cv-04160, in the U.S. District Court for the Northern District of Georgia. It lasted about six weeks.

The named plaintiff filed a Notice of Voluntary Dismissal Without Prejudice that morning, and the clerk entered the dismissal that afternoon under Federal Rule of Civil Procedure 41(a)(1)(A)(i) — the provision that lets a plaintiff drop a case as a matter of right, with no court permission needed, so long as the other side has not yet served an answer or a summary judgment motion. Chick-fil-A had not. Its answer was not due until September 17, 2026, so the case ended more than two weeks before the company was ever required to respond to the allegations.

Nothing in the docket explains why the case was withdrawn. A voluntary dismissal at this stage is a procedural exit, not a ruling: no judge evaluated the strength of the claims, and it is not a finding for or against either side.

Status Dismissed Without Prejudice · Case Terminated dismissed September 1, 2026 under Rule 41(a)(1)(A)(i)
Case Williams v. Chick-fil-A, Inc. No. 1:26-cv-04160 (N.D. Ga.) · filed July 23, 2026
Can I Claim? No — there is nothing to claim no settlement, no certified class, no claim form

What Happened in the June 2026 Chick-fil-A Breach?

Chick-fil-A has disclosed that its Chick-fil-A One loyalty program was hit by a credential-stuffing attack running from roughly June 17 through June 19, 2026. Credential stuffing is not a break-in through the company's own systems. Attackers take email and password pairs that leaked somewhere else — an unrelated company's breach, a phishing campaign, or malware that scrapes saved logins — and then run those pairs automatically against a different site, betting that some people reused the same password. On accounts where multifactor authentication was not switched on, those automated login attempts were not challenged.

Chick-fil-A determined on July 13, 2026 that attackers may have reached information inside affected accounts, and began notifying customers about a week later. The data reported as exposed is the contents of the loyalty account itself: names, email addresses, Chick-fil-A One membership and mobile pay numbers, account QR codes, the amount of Chick-fil-A credit on the account, and the last four digits of a stored credit or debit card. For customers who had saved them, the attackers may also have reached a phone number, an address, and the month and day of birth — not the birth year.

Those limits matter for judging the risk. No full payment card numbers and no Social Security numbers have been reported, and a birth month and day without the year is far less useful for opening accounts in someone's name than a complete date of birth would be. Chick-fil-A's stated response was to sign affected customers out, remove stored payment methods, restore Chick-fil-A One balances that had been drained, force password resets, and add rewards to affected accounts for the inconvenience.

How Many People Were Affected?

Chick-fil-A has not published a nationwide total. The two state filings that carry hard numbers account for 2,182 residents of Texas and 39 residents of Massachusetts — but the company filed breach notices in at least ten jurisdictions in all, with reporting also naming Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont. Most of those filings do not publish a resident count.

So 2,182 and 39 are the two states that show their math, not the size of the breach. Anyone adding them together and reporting roughly 2,221 affected customers is counting two states out of ten or more. The national figure is higher and remains unconfirmed; treat any specific total you see until Chick-fil-A or a regulator publishes one as unverified.

This was the second credential-stuffing incident to hit the loyalty program. A similar attack disclosed in 2023 produced its own class action in the same courthouse, Stephens v. Chick-fil-A, Inc., No. 1:23-cv-00964 (N.D. Ga.), which the parties reported settling in principle in October 2023 on terms that were not made public.

What Did the Complaint Allege?

The 47-page class action complaint, filed with a jury demand on July 23, 2026, was docketed as a contract case brought under the federal courts' diversity jurisdiction, with breach of fiduciary duty identified as the cause of action. Reporting on the filing describes claims that Chick-fil-A failed to secure the personal and payment information in Chick-fil-A One accounts and left members exposed to an attack built on passwords stolen elsewhere, alongside breach of implied contract and unjust enrichment theories.

The core theory in cases like this is that a company holding customers' stored payment data and account balances owes a duty to defend those accounts against foreseeable automated attacks — through rate limiting, bot detection, or mandatory multifactor authentication — and that failing to do so is what made the intrusion possible. None of that was tested. Chick-fil-A never filed an answer, never moved to dismiss, and never had to state a position in court on any of it.

Can the Case Come Back?

Yes, in principle. "Without prejudice" means the claims were not decided and were not surrendered. The same plaintiff, or any other Chick-fil-A One member, can file the same allegations again in a new case, subject to the statutes of limitations that apply to each claim. Several plaintiffs' firms publicly announced investigations into the June 2026 breach in July and August 2026, so a refiling by someone is a realistic possibility.

The docket also shows the case was reassigned partway through: Judge Michael L. Brown recused himself on August 10, 2026, and the case went to Judge Eleanor L. Ross. The reassignment came three weeks before the dismissal, and the record does not connect the two.

Until something new is filed, there is no Chick-fil-A breach case pending, no class, and no settlement. We will update this page if a new complaint appears.

Is This the Same as the $4.4M Chick-fil-A Delivery Settlement?

No — and the two get mixed up constantly, because both are "a Chick-fil-A class action." They are different cases about different things, and only one of them ever paid anybody.

The one most people remember is the delivery-pricing case, Mayheu v. Chick-fil-A, Inc., No. 2022CV365400, in the Superior Court of Fulton County, Georgia. It alleged Chick-fil-A advertised low or free delivery while quietly charging higher menu prices on delivery orders. Chick-fil-A denied wrongdoing and settled. Press coverage put that deal at $4.4 million, which is the combined figure — a $1.45 million cash fund plus $2.95 million in gift cards — and approved claimants could take cash or an e-gift card worth up to $29.25. That settlement received final approval in February 2024 and its claim deadline passed on February 15, 2024. It is closed. Our $4.4M Chick-fil-A delivery order settlement page has the full history.

This page is about something else entirely: a 2026 data breach, a different court (federal, not state), a different legal theory, and an outcome that is not a settlement at all. Nobody was paid, because the case was withdrawn before it was ever answered. If you are searching for a Chick-fil-A class action to file a claim in, neither of these is one — the delivery settlement closed more than two years ago, and the breach case no longer exists.

What Should Chick-fil-A One Members Do Now?

There is nothing to file and no claim form to complete. If you received a breach notice, keep it — documentation of the incident is often needed if a case is refiled and eventually settles.

Because this was a credential-stuffing attack, the practical protections are about passwords rather than credit. Change the Chick-fil-A One password, and change it everywhere else the same password was used, since reuse is the whole mechanism these attacks depend on. Turn on multifactor authentication in the account settings. Review the saved payment methods and the stored balance on the account, and watch card statements for charges you do not recognize. Reported exposure was limited to the last four digits of a card rather than a full number, and no Social Security numbers were reported, so this incident is a weaker candidate for new-account identity theft than an SSN breach — but a credit freeze with the three bureaus is free and remains the strongest general protection if you want it.

You can follow other active breach cases on our data breach settlements and investigations tracker, and read how these cases work in our guide to the data breach class action. OpenClassActions.com is a consumer news site, not a law firm; we do not provide legal advice or process claims.

Frequently Asked Questions

Was the Chick-fil-A data breach class action dismissed?

Yes. The named plaintiff filed a Notice of Voluntary Dismissal Without Prejudice on September 1, 2026, the clerk entered the dismissal under Federal Rule of Civil Procedure 41(a)(1)(A)(i) the same afternoon, and the civil case was terminated that day. The case is Williams v. Chick-fil-A, Inc., No. 1:26-cv-04160, in the U.S. District Court for the Northern District of Georgia. Chick-fil-A never filed an answer, and no court ever ruled on the merits of the allegations.

What does dismissed without prejudice mean here?

Without prejudice means the claims were not decided and were not given up. The same plaintiff, or a different Chick-fil-A One member, can bring the same allegations again in a new case, subject to the applicable statutes of limitations. A dismissal with prejudice would have ended those claims permanently. Nothing in the docket explains why the case was withdrawn, and a voluntary dismissal at this stage is not a finding for or against either side.

What happened in the June 2026 Chick-fil-A data breach?

Chick-fil-A has disclosed that between June 17 and June 19, 2026, attackers ran a credential-stuffing campaign against the Chick-fil-A One app and website, using email and password combinations stolen from other sources and testing them on Chick-fil-A accounts. The company determined on July 13, 2026 that account information may have been reached. Reported exposed data is the contents of the loyalty account: names, email addresses, membership and mobile pay numbers, account QR codes, the amount of Chick-fil-A credit on the account, and the last four digits of a stored card. For customers who had saved them, a phone number, an address and the month and day of birth — not the birth year — may also have been reached. No full payment card numbers and no Social Security numbers have been reported.

Is there a Chick-fil-A data breach settlement or claim form?

No. There is no settlement, no certified class and no claim form connected to the June 2026 breach, and the only class action filed over it has been dismissed. Any website inviting you to file a Chick-fil-A breach claim right now is not connected to an approved settlement. If a future case settles, a court-approved notice and an official settlement website would explain who qualifies.

How many people were affected by the Chick-fil-A breach?

Chick-fil-A has not published a nationwide total. The two state filings carrying hard numbers account for 2,182 residents of Texas and 39 residents of Massachusetts, but the company filed breach notices in at least ten jurisdictions in all — reporting also names Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont — and most of those do not publish a resident count. Adding 2,182 and 39 to get roughly 2,221 counts two states out of ten or more, so the national figure is higher and remains unconfirmed.

Is this the same as the $4.4 million Chick-fil-A settlement?

No. That was a separate case about delivery pricing — Mayheu v. Chick-fil-A, Inc., No. 2022CV365400, in the Superior Court of Fulton County, Georgia — which alleged Chick-fil-A advertised low or free delivery while charging higher menu prices on delivery orders. Chick-fil-A denied wrongdoing and settled it for a combined $4.4 million: a $1.45 million cash fund plus $2.95 million in gift cards, with approved claimants taking cash or an e-gift card worth up to $29.25. It received final approval in February 2024 and its claim deadline passed on February 15, 2024, so it is closed. This page is about the 2026 data breach case, which is a different court, a different legal theory, and never produced a settlement at all.

What should Chick-fil-A One members do now?

Keep any breach notice you received, since documentation of the incident is often useful if a case is later refiled and settles. Change the Chick-fil-A One password and change it anywhere else the same password was reused, because credential stuffing works on reused passwords. Turn on multifactor authentication on the account, review the stored payment methods and account balance, and watch card statements for unfamiliar charges. Because only the last four digits of a card were reported exposed, and no Social Security numbers, this incident is a weaker candidate for new-account identity theft than an SSN breach.

Sources

Williams v. Chick-fil-A, Inc., No. 1:26-cv-04160 (N.D. Ga.) — Class Action Complaint filed July 23, 2026; Notice of Voluntary Dismissal Without Prejudice and Clerk's Entry of Dismissal under Fed. R. Civ. P. 41(a)(1)(A)(i), September 1, 2026; Order of Recusal and reassignment, August 10, 2026; Order granting extension of time to answer, August 13, 2026
Stephens v. Chick-fil-A, Inc., No. 1:23-cv-00964 (N.D. Ga.) — prior loyalty-account breach litigation, settled in principle October 2023
• PacerMonitor — docket for Williams v. Chick-fil-A
• BleepingComputer, "Chick-fil-A discloses data breach after credential stuffing attacks" — BleepingComputer
• SecurityWeek, "Chick-fil-A Accounts Get Fried in Credential Stuffing Attack" — SecurityWeek
• The Atlanta Journal-Constitution, "Hackers hit Coca-Cola and Chick-fil-A. Now come the data breach lawsuits." — AJC
• CBS News, "Cyberattack may have exposed Chick-fil-A customer data in 10 states" — CBS News
• Malwarebytes Labs, "Chick-fil-A loyalty accounts hijacked using stolen passwords" — Malwarebytes


For more class actions keep scrolling below.
Status Dismissed without prejudice — case terminated September 1, 2026
Case Title Williams v. Chick-fil-A, Inc.
Case Number 1:26-cv-04160
Court U.S. District Court, Northern District of Georgia
Judge Eleanor L. Ross (reassigned August 10, 2026)
Date Filed July 23, 2026
Date Dismissed September 1, 2026 — Fed. R. Civ. P. 41(a)(1)(A)(i)
Claims Breach of fiduciary duty · breach of implied contract · unjust enrichment
Incident Credential stuffing against Chick-fil-A One, June 17–19, 2026
Data Reported Name · email · membership and mobile pay number · QR code · account credit · last 4 of card; if saved, phone, address and birth month/day (no year)

Related Data Breach Lawsuits & Investigations