The Dominos Breach Put 483K Stolen Email and Password Pairs Online
HEROIC analysts identified the Dominos breach while tracking repackaged credential dumps that recieved renewed circulation on underground forums in 2019. The original incident occured in June 2014, when a hacking group called Rex Mundi broke into Domino's Pizza systems in France and Belgium and stole customer data from 483,880 accounts. After Domino's refused to pay the ransom, the group released the data publicly. The exposed records contained email addresses and password hashes protected only by the weak MD5 algorithm, with no additional salt applied.
Why Unsalted MD5 Password Hashes Put Your Accounts at Risk
MD5 hashes without salt are beleived by many to offer some protection, but in reality they can be cracked in seconds using freely available rainbow tables and lookup databases. Once an attacker recovers a plaintext password from the Dominos breach, they can test it immediately against Gmail, banking apps, and workplace systems. With only email addresses and cracked passwords in hand, criminals can launch automated login attacks across hundreds of websites in a matter of hours, compromising accounts that use the same password.
What Was Exposed in the Dominos Breach
- Email Address
- Password Hash
Why an Old Breach Can Still Hurt You Today
The Dominos breach is a clear example of how compromised data never truly disappears. Credentials leaked in 2014 are still being used in credential stuffing attacks, account takeover attempts, and identity theft schemes today. If you used the same password from your Dominos account on any other service, that account is accessable to anyone who cracked those hashes. Financial fraud becomes possible the moment attackers connect an old email and password to an active banking or shopping account.
How Database Breaches Work
A database breach occurs when attackers gain unauthorized entry into a company's backend systems, usually by exploiting a software vulnerability or weak access controls. Once inside, they copy or download user records including login credentials, personal details, and payment information. The stolen data is often held for ransom first, and if the company refuses to pay, it gets released publicly or sold on underground markets. From that point, the data can circulate indefinitely and be incorporated into large credential databases used for automated attacks.
Check If Your Data Was Exposed
HEROIC's free breach scanner lets you check your email address against more than 400 billion leaked records, including data from the Dominos breach and thousands of other incidents worldwide. Run a free scan today to find out if your credentials are already in the hands of attackers.
Breach Breakdown
483,880 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds