Tendvane

← All articles

AccountsOctober 6, 2026

Domino's told customers their account was broken into, then explained whose fault it was

The email Domino's sent out this week is unusual mostly for how direct it is. Your account was accessed by an unauthorised third party, it says, and the reason is that the password you used here is one you had used on another site, which had already been breached.

That is credential stuffing, and it needs nobody to hack the company at all. Lists of email addresses and passwords from old breaches get fed through automated tools that try them against hundreds of login pages, and the small share that still work belong to people who reused a password. Domino's says its own systems were not compromised and that it stores no card details, so nothing financial was taken. It has reset the affected accounts, so the next time those customers sign in they have to go through the forgotten password link, and it has reported the incident to the Information Commissioner's Office.

It is tempting to shrug at a pizza account. Don't. The address you have things delivered to, your phone number and your order history all sit in there, which is the raw material for a convincing phone call later, and loyalty balances are spendable. We wrote about the same thing happening to Chick-fil-A customers in July. The companies change, the mechanism does not.

The fix is unglamorous and permanent: a different password on every account, kept in a password manager rather than your head, and a second step switched on anywhere it is offered. Tendvane's privacy and accounts check will show you which sign-ins on your PC still have no second step behind them.

Sources

Download Tendvane