DoorDash Data Breach: Phone Numbers & Addresses Exposed

DoorDash Reports Data Breach Affecting Users
DoorDash recently announced a data security incident resulting in the exposure of personal data belonging to an undetermined number of its users.
Compromised information included names, email addresses, phone numbers, and residential addresses.
Limited Scope of Accessed Data
Although phone numbers and physical addresses were obtained by unauthorized actors, DoorDash maintains that no particularly sensitive data was accessed.
Currently, there is no evidence to suggest the stolen data has been utilized for fraudulent activities or identity theft.
Breach Impacting Multiple Groups
The security breach impacted a diverse range of individuals connected to the DoorDash platform.
This includes customers, delivery personnel, and merchants.
Lack of Specifics on User Count
When questioned regarding the precise number of affected users, company representative Michelle Babin declined to provide a concrete figure.
Instead, a statement mirroring the details published in the company’s official blog post was released.
Origin of the Security Incident
The breach was initiated through a successful social engineering attack targeting a DoorDash employee.
Upon detection, the company immediately terminated the attackers’ system access, launched a thorough investigation, and alerted law enforcement authorities.
Data Not Compromised
DoorDash confirmed that sensitive financial and identification details were not part of the stolen data.
Specifically, Social Security numbers, government IDs, driver’s license information, and banking or credit card details remained secure.
Notification of Affected Individuals
The company has taken steps to inform all users believed to be impacted by the data breach.
Past Security Incident
This is not the first time DoorDash has faced a security challenge.
In 2019, a similar incident led to the compromise of data belonging to approximately 5 million customers, delivery workers, and merchants.
Notably, the 2019 breach went undetected for around five months, with the company attributing the delay to a vulnerability within a third-party vendor’s systems.
This report has been updated to reflect a response from a DoorDash spokesperson.
Related Posts

FTC Upholds Ban on Stalkerware Founder Scott Zuckerman

Google Details Chrome Security for Agentic Features

Petco Data Breach: SSNs, Driver's Licenses Exposed

Petco Data Breach: Customer Data Exposed - What You Need to Know

Intellexa Spyware: Direct Access to Government Espionage Victims
