Skip to content
Residential technology help and small-business ITOwner-led. Clearly scoped. Salem County based. 609-202-2208
Cyber News

Domino’s customers warned after reused passwords enabled account access

Malwarebytes reports that a very small number of Domino’s accounts were accessed with passwords exposed elsewhere. Check for reuse and reset those passwords through the official site or app.

Published October 6, 2026 Updated October 6, 2026 6 min read
Domino’s customers warned after reused passwords enabled account access

Malwarebytes reports that a very small number of Domino’s accounts were accessed with passwords exposed elsewhere. Check for reuse and reset those passwords through the official site or app.

In 60 seconds

  • Domino’s customers should check whether their account password was reused on another website.
  • Open the official Domino’s site or app directly and look for a password-reset request.
  • Change the old password everywhere it was reused, starting with email and payment-related accounts.
  • Do not click links or call numbers in unexpected messages claiming to be from Domino’s.

Who should care and what to do today

This concerns Domino’s customers, especially people who used the same email address and password on Domino’s and another website. Anyone who receives an unexpected Domino’s account message should also treat it carefully.

Malwarebytes reports that Domino’s warned a very small number of customers that an unauthorized third party had accessed their accounts. Domino’s said its internal systems were not breached and that it does not store payment details. The reported access used an email address and password combination exposed through another service.

Open the official Domino’s website or app yourself. If it asks you to reset your password, use the “Forgotten password” option. If you used that password elsewhere, change it on those accounts too.

Do not click an unsolicited account-update link or call a number supplied in a suspicious message. Malwarebytes says unsolicited messages claiming to be from Domino’s are frequently phishing attempts designed to steal personal or financial information.

What credential stuffing means

Credential stuffing is when attackers try stolen email addresses and passwords on many websites. The term describes password reuse: a password exposed at one service may also open an account somewhere else.

Malwarebytes says attackers use automated tools to test large lists of stolen login details. The lists may come from earlier data breaches, malware that steals saved logins, or fake login pages. If a customer reused one of those passwords, attackers may not need to break into Domino’s systems.

A successful login can give access to the account itself. Malwarebytes lists possible consequences such as placing orders, using loyalty points or gift-card balances, and collecting names, addresses, or phone numbers. The report describes these as possible effects of this type of attack; it does not say each occurred in the Domino’s incident.

How to check safely

Check for a Domino’s account warning, but do not assume an unexpected message is genuine. Type the official website address yourself or use the known app. Use the service’s own password-reset option rather than a message link.

List other accounts where you used the same password. General safety guidance is to use a different password for every account. A password manager can store those passwords so you do not have to remember them all.

If the reused password protects email or an account with saved payment details, change it promptly. Where available, turn on two-factor authentication, which adds a code, approval, or passkey after the password.

The Domino’s notice quoted by Malwarebytes said affected accounts had been reset and that customers could place orders as normal but would need to create a new password at the next login. Reach the official service directly before taking that step.

What the report does and does not say

The reported issue concerns access to individual customer accounts using previously exposed credentials. It is not described as a software flaw in a Domino’s product, so there is no product patch identified in the supplied evidence.

The Domino’s notice said the company’s internal systems had not been breached and that payment details were not stored. According to that notice, no financial information was accessed through the affected accounts.

That does not remove the need to check reused passwords. One exposed password can give attackers more places to try it, and account details may be useful in later scam attempts. Change the old password anywhere it appears, using each service’s official website or app.

Does this affect me?

Who may be affected
Domino’s customers, especially those who reused the same email-and-password combination on another website. People who receive unexpected Domino’s account messages should also take care because Malwarebytes describes frequent phishing attempts using the brand.
How to check
Open the official Domino’s website or app directly and check whether it requests a password reset. Then identify other accounts where the same password was used.
What to do
Change that password everywhere it was reused, starting with email and accounts that store payment details, and use a different password for each account.
What to avoid
Avoid links, phone numbers, and attachments in unsolicited account messages. Do not reuse the old password.

Common questions

Was Domino’s internal system breached?

According to the customer notice reported by Malwarebytes, Domino’s said its internal systems were not breached. The reported account access used an email address and password combination exposed through another service.

Could payment card details be exposed through this incident?

The Domino’s notice said the company does not store payment details, so no financial information was accessed through the affected accounts, according to the report. If the same password protected another account with payment details, change it there.

What if I did not receive a Domino’s warning?

You can still check whether your Domino’s password was reused elsewhere. Open the official website or app directly, change the password if needed, and avoid acting on unexpected messages that ask you to update the account.

What is the safest way to change the password?

Type the official Domino’s website address yourself or open the known app. Use its password-reset option instead of a link or phone number from an unsolicited email or text.

Primary source

This article is based on Malwarebytes, “Domino’s customers targeted in credential stuffing attacks,” published October 6, 2026: https://www.malwarebytes.com/blog/news/2026/10/dominos-customers-targeted-in-credential-stuffing-attacks. The report quotes a Domino’s customer notice and describes the reported account access. Read the complete original source.

Get the important updates without the noise

Choose the devices and topics you care about in Cyber Alerts.

Choose my alerts

Article history: Published Oct 6, 2026 at 7:59 am EDT. Updates and corrections are noted here when material facts change.