CSIDB logo
Incident

Domino's Pizza India

Incident posture

Attack window
Apr 2021
Location
India
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
Domino's Pizza India
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A threat actor claimed to compromise Domino's India, allegedly stealing 13 terabytes of customer data including personal details from 180 million orders—such as phone numbers, email addresses, and physical locations—along with over one million credit card records. The data was advertised for sale on the dark web, though the company denied financial information was breached, asserting it does not store such data. Cybersecurity researchers publicized the incident and linked the actor to a prior breach involving another Indian firm, while local authorities were alerted about potential data exposure weeks earlier.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In April 2021, a threat actor advertised the alleged theft of 13 terabytes of data from Domino’s Pizza’s Indian operations on the dark web. The actor claimed the dataset included details from 180 million orders, containing customer phone numbers, email addresses, physical addresses, and over one million credit card details. Cybersecurity researcher Rajshekhar Rajaharia had previously alerted India’s Computer Emergency Response Team (CERT-In) about potential data exposure on March 5, 2021, over a month before the dark web advertisement surfaced. Alon Gal, co-founder of threat intelligence firm Hudson Rock, publicly highlighted the breach claim via social media on April 18-20, amplifying awareness of the alleged incident. The threat actor explicitly linked the data to Domino’s India and marketed it for sale, asserting it originated from the company’s systems.

Domino’s India issued a statement denying any compromise of financial data, asserting that the company does not store credit card information. The organization did not confirm or address the alleged theft of non-financial customer data such as order details and contact information. The threat actor’s advertisement suggested possible connections to an earlier breach involving Indian mobile payments platform MobiKwik, though no conclusive evidence substantiated this link. The incident raised concerns about the exposure of personally identifiable information (PII) for millions of customers, including risks of phishing, identity theft, and financial fraud. Rajaharia’s prior alert to CERT-In indicated potential vulnerabilities in Domino’s infrastructure preceding the public disclosure, though the timeline between initial detection and the dark web listing remained unclear.

Sources

Sources available to members: 1 source.

CSIDB