Post

Domino's Customers Targeted in Credential Stuffing Attacks

Domino's Customers Targeted in Credential Stuffing Attacks

Domino’s Customers Targeted in Credential Stuffing Attacks 🚨

Domino’s Pizza customers have reported receiving alarming emails indicating that their accounts have been accessed by unauthorized third parties. Domino’s has clarified that their internal systems were not breached; rather, individual accounts were compromised through a password and email combination stolen from other online accounts owned by the customers. This method is known as credential stuffing.

In an email to affected customers, Domino’s stated:

“We believe a very small number of Domino’s customer accounts were accessed by an unauthorized third party. Our security systems have not been breached, and we do not store any payment details, so no financial information has been accessed.”

The email further explained that customers may have reused passwords from other sites that were compromised in previous data breaches. Credential stuffing attacks occur when criminals use stolen usernames and passwords from one website to attempt logins on various other sites, exploiting the common practice of password reuse.

How Credential Stuffing Works 🔍

Criminals often obtain lists of stolen credentials from data breaches, malware, or phishing sites. They then use automated tools to test these credentials across multiple platforms, making it appear as though legitimate logins are taking place. This is why many incidents are reported as accounts being accessed rather than a company being hacked.

Once attackers gain access, they can misuse accounts to order food, redeem loyalty points, or collect personal information. Domino’s has taken precautionary measures by resetting affected accounts. Customers can continue to place orders, but they must set a new password using the ‘Forgotten password’ link upon their next login.

Stay Safe! 🛡️

To protect your accounts, it is crucial to:

  • Use a strong, unique password for each account.
  • Consider using a password manager to keep track of your passwords.
  • Enable two-factor authentication wherever possible.
  • Change any reused passwords on affected accounts and others where they may have been used.

For more information, read the complete article here: Read full article

This post is licensed under CC BY 4.0 by the author.