Skip to content

Dunkin' Brands

Disclosed Sep 26, 20197 years agoSettled

Official notice

Credential stuffing hit tens of thousands of accounts; USD 650,000 NY AG settlement

New York sued Dunkin' in 2019 for failing to respond to credential stuffing attacks that compromised tens of thousands of customers' online accounts and stored value cards. The 2020 settlement required notification, password resets, refunds and USD 650,000 in penalties and costs.

What is known

People affectedNot stated in the sources we have
DisclosedSep 26, 2019
AttackCredential stuffing
Data exposedCredentials and tokens, Payment cards
SectorRetail · US
StatusSettled
Lawsuit or fineUSD 650,000 NY AG settlement (Sept 2020) (about $650K)

Sources

Notices filed

WhereFiledPeople
ResearchtotalSep 26, 2019

Other breaches at Dunkin' Brands

BreachAffected
Disclosed Nov 28, 2018Nov 28, 20187 years ago175K
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Dunkin' Brands

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.