SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Domino's resets customer accounts that attackers opened with reused passwords
Domino's has reset a "very small number" of customer accounts that attackers opened with passwords leaked in breaches at other sites. The company says its own systems held, but a correct stolen password was all an attacker needed to get in.
The Watch · Security desk

What happened
- Customers told Malwarebytes they had received emails from Domino's saying a third party had accessed their accounts.
- Domino's says it does not store any payment details, so no financial information was accessed.
- Affected customers can still place orders but must set a new password through the 'Forgotten password' link the next time they log in.
- The company has reported the incident to the Information Commissioner's Office, according to its email.
Why it matters
- constraint A stuffed login carries the correct password, so Domino's could only contain it afterwards, by resetting accounts strangers had already opened.
- exposure A genuine Domino's reset email now sits in inboxes beside the fake 'update your account' messages in its name that Malwarebytes says are frequently phishing.
- cost Domino's reset protects one site; the customer still has to change the leaked password everywhere else it was reused, on Malwarebytes' advice.
- decision Any consumer portal that accepts a correct password on its own faces the same lists, so requiring a second factor or a passkey is a decision for the operator.
An attacker who holds a customer's leaked email and password needs nothing else from Domino's to get into that account [3]. "They don't guess the passwords. They already have them, often millions at a time, from old data breaches, from malware that steals saved logins from people's computers, or from phishing sites," Malwarebytes wrote [9]. Automated tools try each pair against the login page [10]. "To the company, it looks like a normal login with the correct password," Malwarebytes wrote [11].
Domino's notice puts the cause on the customer's reuse. "It appears that you have used a password for your Domino's account which you have used on other sites, which was already out there because of a previous data breach unrelated to Domino's," the email said [6]. The email does not give a count of affected accounts, dates for the logins or a suspect, and it does not say whether Domino's offers customers a second login factor [4].
Malwarebytes' general list of what attackers take from these accounts starts with saved payment cards, loyalty points and gift card balances [1]. Domino's statement on payment data rules out the first [5]. The holder's name, address and phone number are still there [1]. Malwarebytes says criminals use details like these to make later scams more convincing, for example a message that knows what the customer ordered [1]. Malwarebytes says logins that prove to work get sold on to other criminals as well, so a single reused password can keep causing problems well after the breach that first leaked it [1].
Credential stuffing runs on a market for stolen logins. The lists are bought and sold on criminal forums, Malwarebytes said [10]. It said the attack works because so many people reuse the same password on different sites [15]. Its examples of targets are a food delivery app, a web shop and a streaming service [10].
On what Domino's has published, a correct password was enough to enter these accounts [3]. For the account holder, Malwarebytes recommends two-factor authentication where it is offered, either a code from an app or text message or a passkey, "so a stolen password alone isn't enough to login to your account" [12].
What to watch
- Any statement from the Information Commissioner's Office on the incident Domino's says it reported.
- A count of affected accounts from Domino's, or a move to add a second factor or passkeys to customer logins.
- Phishing emails that copy the wording of Domino's genuine reset notice.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Once in, attackers can order goods using a saved payment card, use loyalty points or gift card balances, or collect name, address and phone number for more convincing later scams, such as a message that knows what the customer ordered; accounts confirmed to work are resold to other criminals, so one reused password can cause trouble long after the original breach.
- [2]
Domino's Pizza customers told Malwarebytes they had received emails saying their account had been accessed by a third party.
- [3]
Domino's says its internal systems weren't breached, and that individual accounts were logged into using an email and password combination stolen from another online account owned by the customer, an attack known as credential stuffing.
- [4]
"We're getting in touch to let you know that we believe a very small number of Domino's customer accounts were accessed by an unauthorised third party, and unfortunately your account is one of those affected."
- [5]
"We want to reassure you that our security systems have not been breached. We also don't store any payment details, so no financial information has been accessed."
- [6]
"It appears that you have used a password for your Domino's account which you have used on other sites, which was already out there because of a previous data breach unrelated to Domino's."
- [7]
Domino's reset affected accounts as a precaution; customers can still place orders but must set a new password using the 'Forgotten password' link at their next login, and were told to choose a strong, unique password and avoid reusing their previous one.
- [8]
Domino's says it has reported the incident to the Information Commissioner's Office.
- [9]
"They don't guess the passwords. They already have them, often millions at a time, from old data breaches, from malware that steals saved logins from people's computers, or from phishing sites."
- [10]
Credential lists are bought and sold on criminal forums; attackers use automated tools that try each email and password pair against a login page, such as a food delivery app, a web shop, or a streaming service.
- [11]
"To the company, it looks like a normal login with the correct password."
- [12]
Malwarebytes advises turning on two-factor authentication where offered (a code from an app or text message, or a passkey) "so a stolen password alone isn't enough to login to your account."
- [13]
Unsolicited "update your account" emails claiming to be from Domino's are frequently phishing attempts; Malwarebytes advises not following links in emails and logging in directly on the official website or app.
- [14]
Malwarebytes advises using a different password for every account and, where a password was reused on an affected account, changing it there and on every other site where it was used, starting with accounts that have payment details saved.
- [15]
The attack works because so many people reuse the same password on different sites.
- [16]
A consumer login page that accepts a correct email and password pair on its own is open to the same stolen lists, whoever operates it.
Sources
1 independent publisher whose own reporting we read for this story.
- malwarebytes.comDomino’s customers targeted in credential stuffing attacks
1 article · October 6, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Password securityFollow
- Credential stuffingFollow
- Account TakeoverFollow