Dunkin' Donuts accounts compromised in second credential stuffing attack in three months

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Hacked Dunkin' Donuts accounts are now being sold on Dark Web forums.

Dunkin' Donuts announced today that it was the victim of a credential stuffing attack during which hackers gained access to customer accounts.

This marks the second time in three months that the coffee shop chain notifies users of account breaches following credential stuffing attacks.

Credentials stuffing is a cyber-security term that describes a type of cyber-attack where hackers take combinations of usernames and passwords leaked at other sites and use them to gain (illegal) access on accounts on new sites.

Dunkin' Donuts reported a first credential stuffing attack at the end of November (the actual attack occurred on October 31). Today, the company reported a second credential stuffing attack (attack happened on January 10).

Just like in the first, hackers used user credentials leaked at other sites to gain entry to DD Perks rewards accounts, which provide repeat customers with a way to earn points and use them to get free beverages or discounts for other Dunkin' Donuts products.
 

plat

Level 29
Top Poster
Sep 13, 2018
1,793
So glad I don't indulge in this fatty, nasty Dunkin crap, just like McDonalds, same kind of hack deal. These outfits rake in huge amounts of money every day, yet don't take the measures to protect their customers from crimes like this. Not like Dunkin wasn't warned already--what, three months ago ?

If you have to indulge in a diabetes-inducing "food" item there, best pay in cash, right?
 

Weebarra

Level 17
Verified
Top Poster
Well-known
Apr 5, 2017
836
Well, pretty soon i hope all these hackers will suffer their own attack........... it's called a heart attack. Considering the McDonalds one posted by @upnorth and now this they must be greedy in more ways than one. (n)

208366
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top