1000 Word Essay From Outline Alredy Made
Running Head: DUNKIN DONUTS CREDENTIAL STUFFING 1
Dunkin Donuts Credential Stuffing Outline
Dajon Copes
Stevenson University
Introduction
Hackers gain access to an organization's user accounts with a password stuffing attack.
Some companies have incentive schemes for their loyal customers, who are given points for their
sales that can be exchanged for coupons or products later. Once they get this vital customer
information, they will market it to those who can use the loyalty points instead of the actual
account users' information. In a more serious note, hackers could transfer information to fraudsters
on several levels, including financials, and the information could be used to drain people's bank
accounts. It is critical to ensure that a response is found after a cyber-attack has occurred in a
sector. Primarily, the company must determine and resolve the source of the security violations.
Then they will alter items like passwords and computers that were involved in the original hack.
Credential stuffing is a rising phenomenon as witnessed for Dunkin Donuts in 2018 and 2019.
Body
The first credential stuffing attack was at the end of November 2018 at Dunkin Donuts.
Following another attack, the company began notifying its customers of heightened account
violations. The second incident, which happened in January 2019, was similar to the first, in which
hackers used user credentials stolen from other sites to gain access to Dunkin Donuts perquisites
rewards accounts, which enable loyal customers to earn points and collect free discounts or
products in exchange for their transactions. The rewards account at Dunkin Donuts contains a
wealth of detail. First and last names, email addresses, and account numbers are also used
(Cimpanu, 2019). The catch is that the hackers weren't really searching for sensitive records. They
wanted the perks account so they could market it to their customers on the dark web (Cimpanu,
2019). Credential stuffing had a variety of negative effects. The first is the increased protection
expense. Second, there is the possibility of sales loss due to downtime. The cost and costs involved
with remediation was the next downside. Furthermore, there is often a burden on call centers and
IT. Finally, it can result in customer distrust and increased turnover.
Conclusion
Considering the negative effects of credential stuffing, there needs to be strategies for
preventing the incidence. The first step is to figure out what the problem is and form a task force.
Recognizing that there is a concern is the first step toward seeking alternatives, and pacing is key.
The next move is to determine the extent of the injury. The third stage is to begin the remediation
process. This includes determining the magnitude of the damage and starting the cleaning process.
To determine the extent of the damage and record any results, this should be undertaken in
collaboration with the crisis communication team and IT. Using a need-based format, the teams
will then focus on critical areas. The next step is to devise a negotiation strategy. The bottom line is
the final step. The drive for information and the opportunity to advance beyond technical
boundaries comes at a high cost. As a result, Dunkin Donuts should not be surprised by such
violations all of the time and should make it a priority to develop a strategy.
References
Cimpanu, C. (2019, February 12). Dunkin' donuts accounts compromised in second
CREDENTIAL STUFFING attack in three months. Retrieved March 03, 2021,
from https://www.zdnet.com/article/dunkin-donuts-accounts-compromised-in-second-
credential-
Stuffing-attack-in-three-months/ Dunkin' donuts SETTLES data BREACH lawsuit. (2020,
September 18). Retrieved March 03, 2021,
from https://www.securitymagazine.com/articles/93393-dunkin-donuts-settles-data-
breach-lawsuit