Dunkin' Brands
Disclosed Sep 26, 20197 years agoSettled
Credential stuffing hit tens of thousands of accounts; USD 650,000 NY AG settlement
New York sued Dunkin' in 2019 for failing to respond to credential stuffing attacks that compromised tens of thousands of customers' online accounts and stored value cards. The 2020 settlement required notification, password resets, refunds and USD 650,000 in penalties and costs.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 26, 2019 |
| Attack | Credential stuffing |
| Data exposed | Credentials and tokens, Payment cards |
| Sector | Retail · US |
| Status | Settled |
| Lawsuit or fine | USD 650,000 NY AG settlement (Sept 2020) (about $650K) |
Sources
| Source | |
|---|---|
| NY AG: AG James sues Dunkin' Donuts over cyberattacksag.ny.gov · Regulator | Regulator |
| NY AG: Dunkin' to fill holes in security, reimburse hacked customersag.ny.gov · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 26, 2019 |
Other breaches at Dunkin' Brands
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Nov 28, 2018Nov 28, 20187 years ago | Nov 28, 20187 years ago | Not stated | Retail | Confirmed | 175K |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.