Jason 's Deli, the well-known American restaurant chain, is warning its customers about a data breachin which personal information was exposed.

In a data breach notification sent to customers, Jason's Deli says hackers obtained some member account credentials from other sources and, on December 21, 2023, used them in a credential stuffing against the restaurant's website.
“On December 21, 2023, we learned that an unauthorized party had obtained an unknown number of Deli Dollars and credentials (username and passwords) likely from other data breaches or other sources not involving Jason's Deli,” the statement said.
See also: Trezor: Data breach affects 66,000 customers
“These unauthorized parties apparently used these login credentials to determine if they matched those of our rewards and online accounts.“.
Apparently, some users were using the same credentials on different accounts that had been compromised in the past. The hackers used those credentials and were able to compromise the accounts at Jason's Deli as well.
The data exposed during this credential stuffing attack depends on the type of information a Jason's Deli member has added to their online profiles. Based on this, information that may have been exposed includes:
- Full name
- Address (including all saved delivery addresses)
- Telephone number
- Birthday
- Preferred location Jason's Deli
- Home account number
- Deli Dollar Points
- Redeemable amounts and rewards
- Credit card numbers (only the last four digits are visible)
- Gift card numbers (not fully visible)
Jason's Deli says it can't determine how many accounts have been affected, so it is proactively notifying all customers who could potentially have been compromised by the data breach.
See also: loanDepot: Data breach affects 16.6 million people
According to a filing with the Maine Attorney General's Office, the total number of customers who may be affected is 344,034 people.
People who are certain to have been compromised will receive a password reset notification on their account. If the same password is used on other services, it should be changed there as well. It is also recommended to use 2FA where available.

The company also said that, where applicable, Deli Dollars reward points used without authorization from compromised accounts will be reinstated.
Focus: Best practices for protecting customer data
Although Jason's Deli says the data breach started with credentials that had already been compromised, the restaurant industry needs to take some security measures.
Implementing and maintaining data security standards is vital. This includes protecting data and implementing strict standards to protect their personal and financial information.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Using encryption technology to protect customer data is also important. This means that data transferred to and from the restaurant’s system is encrypted, making it difficult for unauthorized users.
See also: SEC: X account breach was via SIM-swapping attack
It is important to maintain a consistent policy of informing and training staff on data security . Staff must be aware of the risks associated with data breaches and ways to avoid such incidents.
Finally, creating a response plan is essential. This should include immediately notifying customers, investigating the source of the breach, and implementing the necessary steps to restore security.
source: www.bleepingcomputer.com
