DOMINO’S Pizza has confirmed that a small number of customer accounts were accessed not through a breach of its own systems, but via credential stuffing. In these cases, criminals used email addresses and passwords stolen from other sites to log into Domino’s accounts. The company states that it does not store payment details and that payments could still be made using saved methods, but the incident allowed unauthorised access to some accounts.
Affected customers reportedly received emails explaining that a third party had used a previously breached password from another site to access their Domino’s account, and that Domino’s had reset those accounts. The firm has advised customers to create new passwords at login and to ensure passwords are unique across sites. Domino’s says it has reported the incident to the Information Commissioner’s Office.
Credential stuffing relies on attackers possessing large dumps of stolen credentials and testing them across multiple services with automated tools. The risk is amplified where users reuse the same password across sites, enabling “log in as you” scenarios without breaching the targeted service directly. Once inside, attackers may place orders, deplete loyalty or gift balances, or harvest personal details that can fuel further scams.
The article notes that users should employ unique passwords for every account, consider a password manager, enable two‑factor authentication where offered, and treat unsolicited account‑update emails with suspicion, since phishing messages frequently mimic legitimate notifications from brands like Domino’s.