Dunkin

Dunkin' Donuts Reward Program Users' Data Made Vulnerable

The coffee chain says hackers might have accessed customer info through a data breach.

Users of Dunkin' Donuts' rewards program might have had their data made vulnerable after the coffee chain's security vendors discovered a potential breach on Oct. 31. 

In a letter to rewards program users, Dunkin' explained that its own systems had not been compromised, but rather hackers targeted other companies using the usernames and passwords they obtained to try to break into various online accounts across the internet. 

 Dunkin' security stopped most of the attempt, but customers who used their DD Perks username and password for other accounts unrelated to Dunkin' were vulnerable as the hackers were using these credentials to access several different accounts.

While the coffee company says they are unsure of what data might have been made vulnerable, the accounts held information such as customers' first and last names, email addresses and 16-digit DD Perks account number and DD Perks QR code.

Paul Bischoff, a privacy advocate from Comparitech.com, explained that most people don't understand that the information they give one company becomes the information owned by several companies.

“DD Perks account holders might assume they were only handing over personal details to Dunkin Donuts, but this breach and the company's privacy policy proves otherwise," Bischoff said. "Dunkin Donuts shares customers' personal info with service providers, affiliate companies, franchisees, business partners, and other third parties. In this case, a security vendor used by Dunkin Donuts was breached by hackers."

Those affected by the breach might be wondering what they should do to move forward. Bischoff said your best bet is to change your passwords.

"We do not yet know how many customers were affected by the breach," Bischoff said. "DD Perks account holders who receive the notification should change their password immediately. If you use the same password on any other accounts, those should be changed as well. Be on the lookout for phishing emails pretending to be from Dunkin Donuts.

About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • AI Is Now the Leading Cybersecurity Concern for Security, IT Leaders

    Arctic Wolf recently published findings from its State of Cybersecurity: 2025 Trends Report, offering insights from a global survey of more than 1,200 senior IT and cybersecurity decision-makers across 15 countries. Conducted by Sapio Research, the report captures the realities, risks, and readiness strategies shaping the modern security landscape. Read Now

  • Analysis of AI Tools Shows 85 Percent Have Been Breached

    AI tools are becoming essential to modern work, but their fast, unmonitored adoption is creating a new kind of security risk. Recent surveys reveal a clear trend – employees are rapidly adopting consumer-facing AI tools without employer approval, IT oversight, or any clear security policies. According to Cybernews Business Digital Index, nearly 90% of analyzed AI tools have been exposed to data breaches, putting businesses at severe risk. Read Now

  • Software Vulnerabilities Surged 61 Percent in 2024, According to New Report

    Action1, a provider of autonomous endpoint management (AEM) solutions, today released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024, amid an increasingly aggressive threat landscape. Read Now

  • Motorola Solutions Named Official Safety Technology Supplier of the Ryder Cup through 2027

    Motorola Solutions has today been named the Official Safety Technology Supplier of the 2025 and 2027 Ryder Cup, professional golf’s renowned biennial team competition between the United States and Europe. Read Now

  • Evolving Cybersecurity Strategies

    Organizations are increasingly turning their attention to human-focused security approaches, as two out of three (68%) cybersecurity incidents involve people. Threat actors are shifting from targeting networks and systems to hacking humans via social engineering methods, living off human errors as their most prevalent attack vector. Whether manipulated or not, human cyber behavior is leveraged to gain backdoor access into systems. This mainly results from a lack of employee training and awareness about evolving attack techniques employed by malign actors. Read Now

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.