INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Domino's customers targeted in credential stuffing cyber attacks incident
| 2026-10-06 11:16 DATA BREACH
Executive Summary
AI-generated
On October 6, 2026, Domino's Pizza customers reported receiving emails stating that their accounts had been accessed by a third party. The attackers used stolen credentials from another online account owned by the customer, exploiting a previous data breach unrelated to Domino's. A total of an unknown number of affected customers received such notifications. This is known as credential stuffing, where criminals use usernames and passwords stolen from one website and try them on many other websites using automated tools. The attackers took advantage of people reusing the same password across multiple sites, allowing them to log in without breaching Domino's internal systems. As a precaution, Domino's reset affected accounts, advising customers to choose strong, unique passwords for future login attempts.
Technical Mitigations AI-generated
• Password Policies (ATT&CK mitigation for Credential Stuffing): Refer to NIST guidelines when creating password policies.
• User Account Management (ATT&CK mitigation for Credential Stuffing): Proactively reset accounts that are known to be part of breached credentials either immediately, or after detecting bruteforce attempts.
• Network Intrusion Prevention (ATT&CK mitigation for Phishing): Network intrusion prevention systems and systems designed to scan and remove malicious email attachments or links can be used to block activity.
• Restrict Web-Based Content (ATT&CK mitigation for Phishing): Determine if certain websites or attachment types (ex: .scr, .exe, .pif, .cpl, etc.) that can be used for phishing are necessary for business operations and consider bloc
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Intelligence Sources
Malware Bytes
2026-10-06