HomeSecurityJason’s Deli: Customer data breach via credential stuffing

Jason's Deli: Customer data breach via credential stuffing

Jason 's Deli, the well-known American restaurant chain, is warning its customers about a data breachin which personal information was exposed.

Jason's Deli Data Breach

In a data breach notification sent to customers, Jason's Deli says hackers obtained some member account credentials from other sources and, on December 21, 2023, used them in a credential stuffing against the restaurant's website.

“On December 21, 2023, we learned that an unauthorized party had obtained an unknown number of Deli Dollars and credentials (username and passwords) likely from other data breaches or other sources not involving Jason's Deli,” the statement said.

See also: Trezor: Data breach affects 66,000 customers

“These unauthorized parties apparently used these login credentials to determine if they matched those of our rewards and online accounts.“.

Apparently, some users were using the same credentials on different accounts that had been compromised in the past. The hackers used those credentials and were able to compromise the accounts at Jason's Deli as well.

The data exposed during this credential stuffing attack depends on the type of information a Jason's Deli member has added to their online profiles. Based on this, information that may have been exposed includes:

  • Full name
  • Address (including all saved delivery addresses)
  • Telephone number
  • Birthday
  • Preferred location Jason's Deli
  • Home account number
  • Deli Dollar Points
  • Redeemable amounts and rewards
  • Credit card numbers (only the last four digits are visible)
  • Gift card numbers (not fully visible)

Jason's Deli says it can't determine how many accounts have been affected, so it is proactively notifying all customers who could potentially have been compromised by the data breach.

See also: loanDepot: Data breach affects 16.6 million people

According to a filing with the Maine Attorney General's Office, the total number of customers who may be affected is 344,034 people.

People who are certain to have been compromised will receive a password reset notification on their account. If the same password is used on other services, it should be changed there as well. It is also recommended to use 2FA where available.

Jason's Deli credential stuffing
Jason's Deli: Customer data breach via credential stuffing

The company also said that, where applicable, Deli Dollars reward points used without authorization from compromised accounts will be reinstated.

Focus: Best practices for protecting customer data

Although Jason's Deli says the data breach started with credentials that had already been compromised, the restaurant industry needs to take some security measures.

Implementing and maintaining data security standards is vital. This includes protecting data and implementing strict standards to protect their personal and financial information.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Using encryption technology to protect customer data is also important. This means that data transferred to and from the restaurant’s system is encrypted, making it difficult for unauthorized users.

See also: SEC: X account breach was via SIM-swapping attack

It is important to maintain a consistent policy of informing and training staff on data security . Staff must be aware of the risks associated with data breaches and ways to avoid such incidents.

Finally, creating a response plan is essential. This should include immediately notifying customers, investigating the source of the breach, and implementing the necessary steps to restore security.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS