Get 40% Off
🚨 Volatile Markets? Find Hidden Gems for Serious Outperformance
Find Stocks Now

Dunkin' Donuts parent settles New York cyberattack lawsuit, is fined

Published 09/15/2020, 12:18 PM
Updated 09/15/2020, 06:25 PM
© Reuters. FILE PHOTO: The sign of a Dunkin' store, the first since a rebranding by the Dunkin' Donuts chain, is pictured ahead of its opening in Pasadena

By Jonathan Stempel

NEW YORK (Reuters) - The parent of Dunkin' Donuts on Tuesday agreed to upgrade its security protocols and pay $650,000 in fines and costs to settle a lawsuit by New York's attorney general claiming it ignored cyberattacks that compromised the online accounts of tens of thousands of customers.

Attorney General Letitia James said Dunkin' Brands (NASDAQ:DNKN) Group Inc will notify customers affected by the attacks between 2015 and 2018, reset their passwords, and provide refunds for unauthorized use of their Dunkin'-branded stored value cards.

The settlement resolves a civil lawsuit filed last Sept. 26 in a New York state court in Manhattan, and requires a judge's approval.

Dunkin' did not admit or deny wrongdoing.

The case arose after hackers began in early 2015 using previously stolen user names and passwords to conduct automated "brute force" and "credential stuffing" attacks, and steal tens of thousands of dollars from accounts created through Dunkin's website or free mobile app.

James said the Canton, Massachusetts-based company did nothing for years to address the compromised accounts despite repeated alerts from its own app developer, including when it identified 19,715 customers targeted over a five-day period.

The attorney general also said Dunkin' failed to adopt safeguards against future attacks despite reports of continuing fraud. She said that came to roost in late 2018, when more than 300,000 customer accounts were accessed in new attacks.

"For years, Dunkin' hid the truth and failed to protect the security of its customers, who were left paying the bill," James said. "It's time to make amends and finally fill the holes in Dunkin's' cybersecurity."

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

In a separate statement, Dunkin' said the cyberattacks potentially affected less than 1% of its Perks Loyalty members, and the hackers had no access to credit card information.

"We have taken steps to make sure that any stored value cards associated with [digital customers'] accounts are protected and secure," it added.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.