Dunkin’ Donuts has issued a security notification alerting users of their DD Perks reward program that their accounts may have been involved in a credential stuffing attack. This attack could have allowed third-parties to gain access to the user accounts and see information that was stored within them. Credential stuffing attacks like this are becoming all-too-frequent due to the increasing amount of data breaches that leak account information such as usernames and passwords. To prevent these types of attacks from affecting you, it is important to create unique and strong passwords at every site an account is created.
Source: https://www.bleepingcomputer.com/news/security/dunkin-donuts-issues-alert-for-credential-stuffing-attack-passwords-reset/

