What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
This was a June 2014 incident affecting Domino’s franchise operations in France and Belgium—not a new breach or an attack on every Domino’s market. A group using the name Rex Mundi claimed it had taken roughly 600,000 customer records and demanded €30,000 to keep them from being published. Domino’s refused to pay. Contemporary reports said the affected ordering system did not accept or store card payments, but the exposed contact details and passwords still created risks for customers.
What happened in the 2014 Domino’s data-extortion incident?
In June 2014, Rex Mundi claimed to have stolen customer information from Domino’s online-ordering systems serving France and Belgium. The group threatened to publish the data unless Domino’s paid €30,000. Contemporary coverage put the reported total at more than 600,000 customers; one account gave a breakdown of about 592,000 in France and 58,000 in Belgium. Those figures and the precise contents of the claimed dataset were not identical across reports, so they are best treated as reported estimates rather than a definitive count. SecurityWeek’s contemporary report and CBS News’ account describe the markets and reported scale.
Timeline
- June 13, 2014: Contemporary accounts reported that Domino’s notified customers of an intrusion and Rex Mundi publicized its claim and demand.
- June 16, 2014: The reported deadline for payment was Monday evening—described in accounts as approximately 18:00 GMT or 20:00 local time.
- June 16–17, 2014: Reports said Domino’s would not pay. The company secured the affected site and cooperated with French law enforcement.
The dates and deadline were reported at the time by NDTV and SecurityWeek.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteWho was Rex Mundi?
Rex Mundi was the name used by a cybercriminal group or operator associated in contemporary reporting with stealing organizations’ data and threatening to disclose it. Reports linked the name to other alleged targets, including Belgian businesses and financial-service firms. The group’s exact membership, location and structure were not clearly established; the name should not be mistaken for a publicly identified organization with a verified roster. See Europe 1’s contemporary background.
#1 Best Overall
What information was reportedly taken?
The attackers claimed possession of customer records. Contemporary reports attributed the following types of information to the affected data, but did not establish that every record contained every field:
- Names, email addresses and telephone or mobile numbers.
- Delivery addresses, with some accounts also mentioning access or delivery instructions such as door codes.
- Passwords, described in some reporting as passwords for customer accounts.
- Order-related details; one account referred to favorite toppings and delivery information.
The field lists varied among accounts, including CBS News, NDTV and SecurityWeek. The reporting supports describing these as claimed or reported categories, not as a field-by-field forensic inventory.
Was credit-card information involved?
Domino’s said the affected France and Belgium ordering system did not accept or store credit-card orders. Contemporary reports consequently said payment-card or banking information was not compromised in this incident. That is a statement about the reported system and breach, not a guarantee that no customer could have experienced financial fraud from any cause. Names, contact information, delivery details and passwords can enable convincing phishing, account impersonation or password-reuse attacks even when card numbers are absent.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Why did Domino’s refuse to pay?
Domino’s’ reported position was that it would not yield to criminal blackmail. The demand was for nonpublication of data the attackers said they had already copied—not for a decryption key to restore encrypted systems. That makes the incident an example of data-theft extortion rather than a documented encrypt-and-lock ransomware attack. Le Vif’s report described the company’s refusal, while SecurityWeek covered the company response.
There is also a broader practical reason organizations may reject data-extortion demands: payment cannot reliably prove that criminals have deleted every copy, and it may encourage further demands. That is general risk analysis, not a claim that Domino’s stated those specific reasons. Reporting at the time noted that there was no way to ensure criminals would destroy the data after receiving money.
What did Domino’s do after the attack?
Contemporary reports said Domino’s secured the affected site, worked with French law enforcement, notified affected French and Belgian customers by email, and reported the attack to French and Belgian data-protection authorities. Reports also said the company was replacing or moving away from the older ordering platform. These actions describe the reported response in 2014, not current procedures or guarantees about Domino’s systems today. SecurityWeek, Le Vif and NDTV covered the response.
Was the Domino’s data ever published?
The available contemporary reports establish the theft claim and extortion demand, but do not conclusively document a full public release of the Domino’s dataset. Domino’s reportedly said it had no information at the time that the data had appeared online. Accounts that Rex Mundi had published data from other targets do not prove what happened to these records. Nor does the absence of a confirmed public release establish that no copies were retained, privately shared or otherwise misused. See Le Vif and NDTV.
Free tools Windows power users keep installed
One-click scans. No signup required.
What should affected customers have done—and what remains sensible now?
Because reports included passwords among the potentially exposed information, password reuse was a particular concern. The following steps are useful for anyone responding to a similar exposure:
Best Value
- Change the Domino’s password. If the account is still in use, set a new, unique password rather than a minor variation of the old one.
- Change reused passwords elsewhere. Prioritize email and financial accounts, since access to an email account can help attackers reset other passwords.
- Be skeptical of targeted messages. A message that cites a real delivery address, order or refund can still be fraudulent. Do not follow links in unexpected texts or emails to enter credentials or payment details; navigate to the service directly.
- Review important accounts. Watch email, mobile, banking and shopping accounts for unfamiliar logins, password-reset notices, messages or transactions.
- Use unique passwords and multifactor authentication. These measures reduce the value of a password exposed in one service. Keep recovery options secure as well.
- Preserve and report suspicious contact. Save messages and report impersonation or fraud to the relevant service or authority.
A password manager can help generate and store unique passwords, but it cannot retract information already copied. A breach-notification lookup can also miss private or unpublished data, so an absence of a match is not proof that an account was unaffected.
Quick Recap
What the incident does—and does not—establish
- Scope: Reports identified Domino’s operations in France and Belgium, not the U.S. market or every market using the Domino’s brand.
- Impact: The incident involved a threat to disclose copied data; reports do not establish that Domino’s systems were encrypted or that ordering operations were shut down.
- Customer risk: The reported absence of stored card data reduced one direct exposure, but contact and password information still carried fraud and account-security risks.
- Unknowns: The cited contemporary accounts do not conclusively establish whether every claimed record was genuine, whether all reported fields were present, whether the dataset was later published or resold, what precise vulnerability was used, or whether later fraud was directly traced to this incident.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

