> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Domino’s customers targeted in credential stuffing attacks

[SOURCE] Malwarebytes [DATE: 06/10/2026 11:16] [LANGUAGE: EN]
Domino’s Pizza customers tell us they have received emails saying they account has been accessed by a third party. Domino’s says its internal systems weren’t breached, but that individual accounts were logged into using a password and email combination stolen from another online account owned by the customer. This is known as credential stuffing.Here’s the email:“We’re getting in touch to let you know that we believe a very small number of Domino’s customer accounts were accessed by an unauthorised third party, and unfortunately your account is one of those affected.We want to reassure you that our security systems have not been breached. We also don’t store any payment details, so no financial information has been accessed.It appears that you have used a password for your Domino’s account which you have used on other sites, which was already out there because of a previous data breach unrelated to Domino’s. An unauthorised third party has used this to obtain access to your account. As a precaution, we’ve reset your account. You can still place orders as normal, but the next time you log in you’ll need to set a new password using the ‘Forgotten password’ link. We recommend choosing a strong, unique password that you haven’t used elsewhere. Please avoid reusing your previous password.Keeping your information safe is really important to us. We’ve reported this incident to the Information Commissioner’s Office and included some FAQs below if you’d like more detail.If you have any questions, our Customer Services team will be happy to help on 0800 640 9071.”Credential stuffing is an attack where criminals take usernames and passwords stolen from one website and try them on many other websites. They don’t guess the passwords. They already have them, often millions at a time, from old data breaches, from malware that steals saved logins from people’s computers, or from phishing sites.These lists are bought and sold on criminal forums. Attackers then use automated tools that run through the list and try each email and password pair against a login page, such as a food delivery app, a web shop, or a streaming service.The attack works because so many people reuse the same password on different sites. If you used the same email and password for a small online forum that was breached years ago and for your pizza ordering account, the criminals don’t need to hack the pizza company at all. They just log in as you. To the company, it looks like a normal login with the correct password. That’s why these attacks often show up as “accounts were accessed” and not “the company was hacked.”Once they’re in, attackers can order food or goods using your saved payment card, use up loyalty points or gift card balances, or collect your name, address, and phone number. They can use those details for more convincing scams later, for example a text or email that seems to come from the company because it knows what you ordered. Accounts that are confirmed to work are also resold to other criminals, so one reused password can cause trouble long after the original breach.How to stay safeUse a different password for every account. That way, a breach at one site stays at that site.Use a password manager to remember those passwords. Nobody can remember dozens of unique passwords, but a password manager can store all these for you.Where it’s offered, turn on two-factor authentication (a code from an app or text message, or a passkey) so a stolen password alone isn’t enough to login to your account.If you’ve reused a password on an account that may have been affected, change it there and on every other site where you used it, starting with accounts that have payment details saved.Don’t follow links in emails or other unsolicited messaging. Log in directly on the official website or in the app.Please note: Unsolicited “update your account” emails claiming to be from Domino’s are frequently phishing attempts designed to steal personal or financial information. When in doubt, Malwarebytes Scam Guard can help you determine whether a message is a scam or not and suggest follow-up steps.What do cybercriminals know about you? Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.SCAN NOW
[messages.read_original_source] →