Dunkin Donuts has agreed to refund customers who were victims of a data breach. The refund is part of a settlement of a lawsuit filed by New York Attorney General Letitia James against the company.

The lawsuit was filed by James against the Canton-based Dunkin' company after hackers breached customers' online accounts with a series of attacks , or repeated, automated attacks to gain access to accounts using stolen usernames and passwords. The breach occurred between 2015 and 2018.
According to James, the attack compromised thousands of customers' DD Perks cards, which were used by the malicious actors to make purchases. The result was thousands of dollars stolen from DD Perks cards.
Dunkin' agreed to notify customers affected by the attacks, reset passwords and provide refunds for unauthorized use of their cards. The company will also pay a $650,000 fine.
"For years Dunkin' hid the truth and failed to protect the safety of its customers, who ended up footing the bill," James said.
However, Dunkin' announced that the incident affected "less than 1%" of members of DD Perks, a Dunkin' rewards program.
The company also said it had taken appropriate security measures "long before" the lawsuit was filed.
The company said it has notified and reset passwords for the "vast majority" of its customers in New York affected by the breach.
The company also stressed that the attackers did not have access to credit card information.
“Dunkin’s digital customers can also rest assured that we have taken steps to ensure that all stored cards associated with Dunkin’ accounts are safe and secure.”
James accused Dunkin of failing to conduct a proper investigation after being “repeatedly warned” that access to customer accounts was inappropriate. She also said Dunkin failed to notify customers of the unauthorized access to their accounts, reset passwords or freeze cards.
