Jason's Deli customer accounts breached in credential stuffing attack
- Organization
- Jason's Deli
- Exploit
- Credential Compromise
- Industry
- Restaurants
Jason's Deli, a Beaumont, Texas based fast casual chain with more than 200 locations across the United States, told customers that their online accounts had been accessed in a credential stuffing attack. In that technique, attackers take username and password pairs leaked in unrelated breaches and replay them against another site, relying on people reusing passwords.
The company said it learned of the activity on December 21, 2023, and stressed that its own systems had not been hacked. It did not say when the unauthorized logins took place. In its notification it said it does not store or retain customer login credentials, which it presented as evidence that the credentials came from elsewhere.
A filing with the Maine attorney general's office put the number of potentially affected people at 344,034. Coverage in late January 2024 described the exposed fields as names, addresses, phone numbers, dates of birth, preferred restaurant location, order history, contact lists, house account numbers, Deli Dollars point balances, redeemable rewards, and truncated gift card and payment card numbers showing only the last four digits.
Jason's Deli said it could not determine exactly which accounts had been successfully accessed, so it notified every account holder who might have been affected. It forced password resets on confirmed accounts, imposed stronger password complexity requirements, and said it would restore Deli Dollars balances where applicable. Customers were advised to monitor their accounts and credit reports.