1000 Word Essay From Outline Alredy Made

profilevick2234
DunkinDonutsCredentialStuffingOutline1.pdf

Running Head: DUNKIN DONUTS CREDENTIAL STUFFING 1

Dunkin Donuts Credential Stuffing Outline

Dajon Copes

Stevenson University

Introduction

Hackers gain access to an organization's user accounts with a password stuffing attack.

Some companies have incentive schemes for their loyal customers, who are given points for their

sales that can be exchanged for coupons or products later. Once they get this vital customer

information, they will market it to those who can use the loyalty points instead of the actual

account users' information. In a more serious note, hackers could transfer information to fraudsters

on several levels, including financials, and the information could be used to drain people's bank

accounts. It is critical to ensure that a response is found after a cyber-attack has occurred in a

sector. Primarily, the company must determine and resolve the source of the security violations.

Then they will alter items like passwords and computers that were involved in the original hack.

Credential stuffing is a rising phenomenon as witnessed for Dunkin Donuts in 2018 and 2019.

Body

The first credential stuffing attack was at the end of November 2018 at Dunkin Donuts.

Following another attack, the company began notifying its customers of heightened account

violations. The second incident, which happened in January 2019, was similar to the first, in which

hackers used user credentials stolen from other sites to gain access to Dunkin Donuts perquisites

rewards accounts, which enable loyal customers to earn points and collect free discounts or

products in exchange for their transactions. The rewards account at Dunkin Donuts contains a

wealth of detail. First and last names, email addresses, and account numbers are also used

(Cimpanu, 2019). The catch is that the hackers weren't really searching for sensitive records. They

wanted the perks account so they could market it to their customers on the dark web (Cimpanu,

2019). Credential stuffing had a variety of negative effects. The first is the increased protection

expense. Second, there is the possibility of sales loss due to downtime. The cost and costs involved

with remediation was the next downside. Furthermore, there is often a burden on call centers and

IT. Finally, it can result in customer distrust and increased turnover.

Conclusion

Considering the negative effects of credential stuffing, there needs to be strategies for

preventing the incidence. The first step is to figure out what the problem is and form a task force.

Recognizing that there is a concern is the first step toward seeking alternatives, and pacing is key.

The next move is to determine the extent of the injury. The third stage is to begin the remediation

process. This includes determining the magnitude of the damage and starting the cleaning process.

To determine the extent of the damage and record any results, this should be undertaken in

collaboration with the crisis communication team and IT. Using a need-based format, the teams

will then focus on critical areas. The next step is to devise a negotiation strategy. The bottom line is

the final step. The drive for information and the opportunity to advance beyond technical

boundaries comes at a high cost. As a result, Dunkin Donuts should not be surprised by such

violations all of the time and should make it a priority to develop a strategy.

References

Cimpanu, C. (2019, February 12). Dunkin' donuts accounts compromised in second

CREDENTIAL STUFFING attack in three months. Retrieved March 03, 2021,

from https://www.zdnet.com/article/dunkin-donuts-accounts-compromised-in-second-

credential-

Stuffing-attack-in-three-months/ Dunkin' donuts SETTLES data BREACH lawsuit. (2020,

September 18). Retrieved March 03, 2021,

from https://www.securitymagazine.com/articles/93393-dunkin-donuts-settles-data-

breach-lawsuit