[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3rj93e9hb8di0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda4882518c","DominosIndia","Domino's India Data Breach","dominos-india","dominos.co.in","2021-03-24T00:00:00.000Z","2021-06-03T02:18:39.000Z","2026-07-27T16:11:12.777Z","Verified Indian food-delivery customer data breach","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fdominos-india-discloses-data-breach-after-hackers-sell-data-online\u002F",[15,17,18,19],"https:\u002F\u002Fwww.medianama.com\u002F2021\u002F05\u002F223-dominos-data-leak\u002F","https:\u002F\u002Fwww.hindustantimes.com\u002Findia-news\u002Fdominos-pizza-data-breach-company-says-financial-information-safe-as-data-of-180-million-users-compromised-101621855567340.html","https:\u002F\u002Fwww.dominos.co.in\u002Fprivacy-policy",22527655,"known",null,"unknown","Critical",[26,27,28,29,30,31],"Email addresses","Names","Phone numbers","Physical addresses","Geographic locations","Purchases","\u003Cp>\u003Cstrong>The Domino's India data breach\u003C\u002Fstrong> affected customer and order data associated with 22,527,655 unique email addresses.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The confirmed data types are email addresses, names, phone numbers, physical delivery addresses, GPS or geographic location data, and purchase histories. Order records could include contextual details such as products, order time, spend, a payment-method label, and delivery point, allowing one record to reveal useful clues about a person's routines and location. The 22,527,655 figure represents unique email addresses; the roughly 180 million order rows connected with the incident are a different measure and should not be reported as the number of affected people. Not every field should be assumed to appear for every customer. \u003Cstrong>Passwords, full payment-card numbers, and financial account details were not confirmed as exposed data.\u003C\u002Fstrong> The company said it did not store customers' card or financial details in its systems and therefore those details were not compromised in this incident.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>Jubilant FoodWorks, the operator of the Domino's India brand, told customers that the unauthorized access occurred on March 24, 2021. In April, an actor offered what they claimed was roughly 13 TB of customer, order, and company data for sale on a criminal forum; in May, a dark-web service appeared that allowed searches by phone number or email address. Independent checks found genuine customer and order data in those results. The company said operations were unaffected, specialists were investigating, and containment steps had been taken. The actor's claim about card data was not reliably substantiated and was rejected by the company. The record is therefore limited to corroborated customer and order fields, and the actor's broader claims about volume or content are not presented as established facts.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People who ordered through the Domino's India website or mobile channels before the 2021 incident face the clearest risk. Combining an email address and phone number with a name, delivery address, and past orders can make phishing highly convincing when it imitates a delivery update, refund, coupon, loyalty offer, or payment problem. Delivery addresses and GPS data provide sensitive context about a home or workplace; recurring order times and locations may also reveal routines. Purchase history does not by itself provide access to a financial account, but it can expose preferences, spending patterns, and useful timing for a scam. This record concerns the dominos.co.in incident in India. The 2014 breach affecting European customers at pizza.dominos.be has a different domain, date, and dataset, so the shared brand does not make the records duplicates.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Anyone who sees a match should review the name, phone number, email address, and saved delivery addresses in the Domino's India account, removing obsolete addresses and unused accounts where possible. Messages claiming to come from Domino's, a courier, a payment provider, or a promotion team should be verified through the known application or official site instead of an inbound link. Treat unexpected delivery fees, refunds, coupon activations, and account-verification requests as suspicious, especially when they create urgency. \u003Cstrong>If the same password is used elsewhere, replace it with a unique password immediately and enable multifactor authentication wherever available.\u003C\u002Fstrong> This is a precaution because exposed email and personal context can support account-recovery attacks, not evidence that passwords were taken. Card activity may still be monitored for unfamiliar transactions, but the confirmed scope does not include card numbers and should not be described as a proven financial-data leak.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Email addresses and phone numbers can change, but historic delivery locations, geographic data, and ordering habits may remain useful to targeted scammers for years. Regularly remove old addresses from food-delivery and shopping accounts, close accounts that are no longer used, and review notification preferences so legitimate transaction messages are easier to distinguish from marketing or fraud. When account recovery relies on a phone number, consider an additional carrier PIN or protection against unauthorized SIM changes. Service providers can reduce lasting exposure by limiting customer-data retention, separating older order records, requiring strong administrator authentication, monitoring unusual database queries, and restricting bulk exports. Delivery addresses and precise location data should be retained only as long as necessary, while incident reporting should clearly distinguish unique people or identifiers from transaction-row volume.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>A match indicates that the searched email address may be one of the unique addresses found in the Domino's India breach; it does not by itself prove that every order or every listed field for that person was exposed. Check whether the matched address was used for Domino's India orders before 2021, then scrutinize delivery, coupon, refund, and payment-themed messages sent to that email or associated phone number. Interpret 22,527,655 as the count of unique email addresses and keep the roughly 180 million order rows as a separate volume measure. Do not assume a password or card-number leak, but recognize that delivery address, location, and purchase history can make social engineering unusually credible. If a message requests an authentication code, password, or payment detail, stop and open the official application independently. Report and document any unauthorized account change through the service's verified support channel.\u003C\u002Fp>","","Domino's India Data Breach (22.5 Million Reported Records)","Domino's India Data Breach. 22.5 Million reported records were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fdominos_co_in.webp",false,{"name":39,"sector":40,"country":41,"website":10,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":22},"Jubilant FoodWorks Limited (Domino's India)","Food Delivery","India"]