2021 Jubilant FoodWorks / Domino's India — ~22.5M customers in HIBP tally; orders and contact metadata on criminal forums
Data compromised
Names, phones, emails, delivery addresses, and order history per HIBP and Indian broadsheet summaries
Technical writeup
Jubilant FoodWorks, Domino’s master franchisee in India, faced April–May 2021 reporting that a multi-terabyte customer and order datastore had been marketed on hacking forums and indexed by Have I Been Pwned at roughly 22.5 million unique email accounts, with national press citing tens of millions of order rows, addresses, and phones while the company argued payment-card data stayed out of scope.
Root cause
Unauthorized access to internet-exposed or insider-accessible operational databases (specific chain under-reported versus forum narrative)
References
- https://haveibeenpwned.com/Breach/DominosIndia
- https://www.hindustantimes.com/india-news/dominos-pizza-data-breach-company-says-financial-information-safe-as-data-of-180-million-users-compromised-101621855567340.html
- https://timesofindia.indiatimes.com/business/india-business/user-info-linked-to-18-crore-dominos-orders-leaked/articleshow/82898118.cms