Domino's Customers Targeted in Credential Stuffing Attacks
Domino's Pizza customers are reporting unauthorized access to their accounts, a result of credential stuffing attacks exploiting reused passwords from unrelated data breaches.

Domino's Pizza customers have recently reported receiving notifications indicating unauthorized access to their accounts. The company has clarified that its internal systems were not breached, but rather that attackers gained access to individual accounts by using email and password combinations stolen from other online services. This tactic, known as credential stuffing, relies on the common practice of users reusing the same login credentials across multiple platforms.
In an email to affected customers, Domino's explained that the compromised accounts were accessed using passwords previously used on other sites that had suffered data breaches. The company emphasized that its own systems remained secure and that no payment information was accessed, as it does not store such sensitive financial data. As a precautionary measure, Domino's has reset the passwords for affected accounts and advised customers to create strong, unique passwords for their accounts to prevent future unauthorized access.
Credential stuffing is a prevalent cyberattack method where threat actors utilize lists of usernames and passwords obtained from previous data breaches, malware infections, or phishing operations. These lists, often containing millions of credentials, are then systematically tested against login portals of various websites and services. Automated tools are employed to rapidly attempt each email-password pair, seeking successful matches.
The effectiveness of credential stuffing hinges on the widespread habit of password reuse. If a user employs the same email address and password for a less secure website that has been breached, and also for their Domino's account, attackers can bypass the need to hack Domino's directly. They simply use the stolen credentials to log in, mimicking a legitimate user.
Once inside an account, attackers can exploit various functionalities. This can include ordering food or goods using saved payment methods, depleting loyalty points or gift card balances, or gathering personal information such as names, addresses, and phone numbers. This stolen data can then be used in more sophisticated phishing attacks or sold to other malicious actors.
To mitigate the risks associated with credential stuffing, cybersecurity experts strongly recommend using a unique password for every online account. Password managers are invaluable tools for securely storing and managing these numerous unique credentials. Additionally, enabling two-factor authentication (2FA) wherever possible adds a critical layer of security, ensuring that a stolen password alone is insufficient for unauthorized access.
Customers who suspect their credentials may have been compromised are advised to change their passwords on the affected service and any other platform where the same credentials were used, prioritizing accounts with stored payment information. It is also crucial to be wary of unsolicited emails or messages requesting account updates, as these are often phishing attempts. Users should always navigate directly to the official website or app to log in.
Domino's has reported the incident to the Information Commissioner's Office and provided additional resources for customers. For those concerned about their digital footprint, tools like Malwarebytes' Digital Footprint scan can help identify if personal information has been exposed in previous breaches.