▼
Allegations Only · Never Decided · Case Dismissed
This article describes a class action complaint that was voluntarily withdrawn before
Chick-fil-A ever answered it. The statements below are unproven allegations. Chick-fil-A
has not been found liable, no court ruled on the merits, there is no certified class, and
there is nothing to claim. This page is general information, not legal advice.
Yes. The proposed class action over Chick-fil-A's June 2026 loyalty-account breach was voluntarily
dismissed on September 1, 2026, and the civil case was terminated the same day. The case is
Williams v. Chick-fil-A, Inc., No. 1:26-cv-04160, in the U.S. District Court for the Northern
District of Georgia. It lasted about six weeks.
The named plaintiff filed a Notice of Voluntary Dismissal Without Prejudice that morning, and the
clerk entered the dismissal that afternoon under Federal Rule of Civil Procedure 41(a)(1)(A)(i) —
the provision that lets a plaintiff drop a case as a matter of right, with no court permission
needed, so long as the other side has not yet served an answer or a summary judgment motion.
Chick-fil-A had not. Its answer was not due until September 17, 2026, so the case ended more than
two weeks before the company was ever required to respond to the allegations.
Nothing in the docket explains why the case was withdrawn. A voluntary dismissal at this stage is a
procedural exit, not a ruling: no judge evaluated the strength of the claims, and it is not a
finding for or against either side.
Status
Dismissed Without Prejudice · Case Terminated
dismissed September 1, 2026 under Rule 41(a)(1)(A)(i)
Case
Williams v. Chick-fil-A, Inc.
No. 1:26-cv-04160 (N.D. Ga.) · filed July 23, 2026
Can I Claim?
No — there is nothing to claim
no settlement, no certified class, no claim form
Chick-fil-A has disclosed that its Chick-fil-A One loyalty program was hit by a credential-stuffing
attack running from roughly June 17 through June 19, 2026. Credential stuffing is not a break-in
through the company's own systems. Attackers take email and password pairs that leaked somewhere
else — an unrelated company's breach, a phishing campaign, or malware that scrapes saved logins —
and then run those pairs automatically against a different site, betting that some people reused
the same password. On accounts where multifactor authentication was not switched on, those
automated login attempts were not challenged.
Chick-fil-A determined on July 13, 2026 that attackers may have reached information inside affected
accounts, and began notifying customers about a week later. The data reported as exposed is the
contents of the loyalty account itself: names, email addresses, Chick-fil-A One membership and
mobile pay numbers, account QR codes, the amount of Chick-fil-A credit on the account, and the
last four digits of a stored credit or debit card. For customers who had saved them, the
attackers may also have reached a phone number, an address, and the month and day of birth —
not the birth year.
Those limits matter for judging the risk. No full payment card numbers and no Social Security
numbers have been reported, and a birth month and day without the year is far less useful for
opening accounts in someone's name than a complete date of birth would be. Chick-fil-A's stated
response was to sign affected customers out, remove stored payment methods, restore Chick-fil-A One
balances that had been drained, force password resets, and add rewards to affected accounts for the
inconvenience.
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Chick-fil-A has not published a nationwide total. The two state filings that carry hard numbers
account for 2,182 residents of Texas and 39 residents of Massachusetts — but the company filed
breach notices in at least ten jurisdictions in all, with reporting also naming Iowa, the District
of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont.
Most of those filings do not publish a resident count.
So 2,182 and 39 are the two states that show their math, not the size of the breach. Anyone adding
them together and reporting roughly 2,221 affected customers is counting two states out of ten or
more. The national figure is higher and remains unconfirmed; treat any specific total you see until
Chick-fil-A or a regulator publishes one as unverified.
This was the second credential-stuffing incident to hit the loyalty program. A similar attack
disclosed in 2023 produced its own class action in the same courthouse, Stephens v.
Chick-fil-A, Inc., No. 1:23-cv-00964 (N.D. Ga.), which the parties reported settling in
principle in October 2023 on terms that were not made public.
The 47-page class action complaint, filed with a jury demand on July 23, 2026, was docketed as a
contract case brought under the federal courts' diversity jurisdiction, with breach of fiduciary
duty identified as the cause of action. Reporting on the filing describes claims that Chick-fil-A
failed to secure the personal and payment information in Chick-fil-A One accounts and left members
exposed to an attack built on passwords stolen elsewhere, alongside breach of implied contract and
unjust enrichment theories.
The core theory in cases like this is that a company holding customers' stored payment data and
account balances owes a duty to defend those accounts against foreseeable automated attacks —
through rate limiting, bot detection, or mandatory multifactor authentication — and that failing to
do so is what made the intrusion possible. None of that was tested. Chick-fil-A never filed an
answer, never moved to dismiss, and never had to state a position in court on any of it.
Yes, in principle. "Without prejudice" means the claims were not decided and were not surrendered.
The same plaintiff, or any other Chick-fil-A One member, can file the same allegations again in a
new case, subject to the statutes of limitations that apply to each claim. Several plaintiffs'
firms publicly announced investigations into the June 2026 breach in July and August 2026, so a
refiling by someone is a realistic possibility.
The docket also shows the case was reassigned partway through: Judge Michael L. Brown recused
himself on August 10, 2026, and the case went to Judge Eleanor L. Ross. The reassignment came three
weeks before the dismissal, and the record does not connect the two.
Until something new is filed, there is no Chick-fil-A breach case pending, no class, and no
settlement. We will update this page if a new complaint appears.
No — and the two get mixed up constantly, because both are "a Chick-fil-A class action." They are
different cases about different things, and only one of them ever paid anybody.
The one most people remember is the delivery-pricing case, Mayheu v. Chick-fil-A, Inc.,
No. 2022CV365400, in the Superior Court of Fulton County, Georgia. It alleged Chick-fil-A advertised
low or free delivery while quietly charging higher menu prices on delivery orders. Chick-fil-A denied
wrongdoing and settled. Press coverage put that deal at $4.4 million, which is the combined figure —
a $1.45 million cash fund plus $2.95 million in gift cards — and approved claimants could take cash
or an e-gift card worth up to $29.25. That settlement received final approval in February 2024 and
its claim deadline passed on February 15, 2024. It is closed. Our
$4.4M Chick-fil-A delivery order settlement
page has the full history.
This page is about something else entirely: a 2026 data breach, a different court (federal, not
state), a different legal theory, and an outcome that is not a settlement at all. Nobody was paid,
because the case was withdrawn before it was ever answered. If you are searching for a Chick-fil-A
class action to file a claim in, neither of these is one — the delivery settlement closed more than
two years ago, and the breach case no longer exists.
There is nothing to file and no claim form to complete. If you received a breach notice, keep it —
documentation of the incident is often needed if a case is refiled and eventually settles.
Because this was a credential-stuffing attack, the practical protections are about passwords rather
than credit. Change the Chick-fil-A One password, and change it everywhere else the same password
was used, since reuse is the whole mechanism these attacks depend on. Turn on multifactor
authentication in the account settings. Review the saved payment methods and the stored balance on
the account, and watch card statements for charges you do not recognize. Reported exposure was
limited to the last four digits of a card rather than a full number, and no Social Security numbers
were reported, so this incident is a weaker candidate for new-account identity theft than an SSN
breach — but a credit freeze with the three bureaus is free and remains the strongest general
protection if you want it.
You can follow other active breach cases on our
data breach settlements and investigations tracker,
and read how these cases work in our guide to the
data breach class action.
OpenClassActions.com is a consumer news site, not a law firm; we do not provide legal
advice or process claims.
Was the Chick-fil-A data breach class action dismissed?
Yes. The named plaintiff filed a Notice of Voluntary Dismissal Without Prejudice on September 1, 2026, the clerk entered the dismissal under Federal Rule of Civil Procedure 41(a)(1)(A)(i) the same afternoon, and the civil case was terminated that day. The case is Williams v. Chick-fil-A, Inc., No. 1:26-cv-04160, in the U.S. District Court for the Northern District of Georgia. Chick-fil-A never filed an answer, and no court ever ruled on the merits of the allegations.
What does dismissed without prejudice mean here?
Without prejudice means the claims were not decided and were not given up. The same plaintiff, or a different Chick-fil-A One member, can bring the same allegations again in a new case, subject to the applicable statutes of limitations. A dismissal with prejudice would have ended those claims permanently. Nothing in the docket explains why the case was withdrawn, and a voluntary dismissal at this stage is not a finding for or against either side.
What happened in the June 2026 Chick-fil-A data breach?
Chick-fil-A has disclosed that between June 17 and June 19, 2026, attackers ran a credential-stuffing campaign against the Chick-fil-A One app and website, using email and password combinations stolen from other sources and testing them on Chick-fil-A accounts. The company determined on July 13, 2026 that account information may have been reached. Reported exposed data is the contents of the loyalty account: names, email addresses, membership and mobile pay numbers, account QR codes, the amount of Chick-fil-A credit on the account, and the last four digits of a stored card. For customers who had saved them, a phone number, an address and the month and day of birth — not the birth year — may also have been reached. No full payment card numbers and no Social Security numbers have been reported.
Is there a Chick-fil-A data breach settlement or claim form?
No. There is no settlement, no certified class and no claim form connected to the June 2026 breach, and the only class action filed over it has been dismissed. Any website inviting you to file a Chick-fil-A breach claim right now is not connected to an approved settlement. If a future case settles, a court-approved notice and an official settlement website would explain who qualifies.
How many people were affected by the Chick-fil-A breach?
Chick-fil-A has not published a nationwide total. The two state filings carrying hard numbers account for 2,182 residents of Texas and 39 residents of Massachusetts, but the company filed breach notices in at least ten jurisdictions in all — reporting also names Iowa, the District of Columbia, Maryland, New Mexico, New York, North Carolina, Oregon, Rhode Island and Vermont — and most of those do not publish a resident count. Adding 2,182 and 39 to get roughly 2,221 counts two states out of ten or more, so the national figure is higher and remains unconfirmed.
Is this the same as the $4.4 million Chick-fil-A settlement?
No. That was a separate case about delivery pricing — Mayheu v. Chick-fil-A, Inc., No. 2022CV365400, in the Superior Court of Fulton County, Georgia — which alleged Chick-fil-A advertised low or free delivery while charging higher menu prices on delivery orders. Chick-fil-A denied wrongdoing and settled it for a combined $4.4 million: a $1.45 million cash fund plus $2.95 million in gift cards, with approved claimants taking cash or an e-gift card worth up to $29.25. It received final approval in February 2024 and its claim deadline passed on February 15, 2024, so it is closed. This page is about the 2026 data breach case, which is a different court, a different legal theory, and never produced a settlement at all.
What should Chick-fil-A One members do now?
Keep any breach notice you received, since documentation of the incident is often useful if a case is later refiled and settles. Change the Chick-fil-A One password and change it anywhere else the same password was reused, because credential stuffing works on reused passwords. Turn on multifactor authentication on the account, review the stored payment methods and account balance, and watch card statements for unfamiliar charges. Because only the last four digits of a card were reported exposed, and no Social Security numbers, this incident is a weaker candidate for new-account identity theft than an SSN breach.
• Williams v. Chick-fil-A, Inc., No. 1:26-cv-04160 (N.D. Ga.) — Class Action Complaint filed July 23, 2026; Notice of Voluntary Dismissal Without Prejudice and Clerk's Entry of Dismissal under Fed. R. Civ. P. 41(a)(1)(A)(i), September 1, 2026; Order of Recusal and reassignment, August 10, 2026; Order granting extension of time to answer, August 13, 2026
• Stephens v. Chick-fil-A, Inc., No. 1:23-cv-00964 (N.D. Ga.) — prior loyalty-account breach litigation, settled in principle October 2023
• PacerMonitor — docket for Williams v. Chick-fil-A
• BleepingComputer, "Chick-fil-A discloses data breach after credential stuffing attacks" — BleepingComputer
• SecurityWeek, "Chick-fil-A Accounts Get Fried in Credential Stuffing Attack" — SecurityWeek
• The Atlanta Journal-Constitution, "Hackers hit Coca-Cola and Chick-fil-A. Now come the data breach lawsuits." — AJC
• CBS News, "Cyberattack may have exposed Chick-fil-A customer data in 10 states" — CBS News
• Malwarebytes Labs, "Chick-fil-A loyalty accounts hijacked using stolen passwords" — Malwarebytes
For more class actions keep scrolling below.
Status
Dismissed without prejudice — case terminated September 1, 2026
Case Title
Williams v. Chick-fil-A, Inc.
Case Number
1:26-cv-04160
Court
U.S. District Court, Northern District of Georgia
Judge
Eleanor L. Ross (reassigned August 10, 2026)
Date Filed
July 23, 2026
Date Dismissed
September 1, 2026 — Fed. R. Civ. P. 41(a)(1)(A)(i)
Claims
Breach of fiduciary duty · breach of implied contract · unjust enrichment
Incident
Credential stuffing against Chick-fil-A One, June 17–19, 2026
Data Reported
Name · email · membership and mobile pay number · QR code · account credit · last 4 of card; if saved, phone, address and birth month/day (no year)