2
Published signals
currently linked to this company
Company intelligence
doordash.com
This company page brings together public reporting currently associated with Doordash. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
2
currently linked to this company
1
recent published signals
1
recent published signals
1
confidence classifications
July 25, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Doordash. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
DoorDash, the popular food delivery platform, publicly acknowledged a cybersecurity incident that compromised the personal information of an undisclosed number of users. The breach, which occurred on October 25, was a result of a social engineering attack targeting a company employee. This allowed an unauthorized third party to gain access to DoorDash's internal systems. The compromised data varied by individual but potentially included first and last names, phone numbers, email addresses, and physical addresses of customers, Dashers (delivery drivers), and merchants across the United States, Canada, Australia, and New Zealand. DoorDash emphasized that no sensitive financial information, such as Social Security numbers, government-issued IDs, driver's license details, bank information, or payment card data, was accessed. The company's security team identified and shut down the unauthorized access shortly after its detection, launched an internal investigation, and notified law enforcement. DoorDash has also implemented multiple security enhancements, including upgraded security systems and additional employee training programs focused on social engineering awareness. While the company has stated there is no indication the data has been misused for fraud or identity theft, affected users are advised to be cautious of unsolicited communications requesting personal information. This incident marks DoorDash's third known cybersecurity incident in six years, highlighting the persistent threat of social engineering attacks.
Our Response to a Recent Cybersecurity Incident Our team recently identified and shut down a cybersecurity incident that involved an unauthorized third party gaining access to and taking certain user information. Importantly, no sensitive information was accessed by the unauthorized third party and we have no indication the data has been misused for fraud or identity theft at this time. We want to let you know what happened, the type of data that was accessed by the unauthorized party, and how we’re responding. A DoorDash employee was recently targeted in a social engineering scam. The response team identified the incident, shut down the unauthorized party’s access, started an investigation, and referred the matter to law enforcement. Our investigation has determined that some users whose data is maintained by DoorDash were affected in connection with this incident. The personal information accessed varied by individual and may have included: No sensitive information, such as Social Security numbers or other government-issued identification numbers, driver’s license information, or bank or payment card information, was accessed. At DoorDash, we believe in continuous improvement and getting 1% better every day. We are committed to protecting your privacy and have already taken the following steps to help prevent events like this from happening again: Deployed new enhancements to our security systems to help prevent and detect malicious activities of this nature Implemented additional training and awareness for our employees around various social engineering scams Brought in an external firm to assist in our investigation and provide specialized support Referred the matter to law enforcement for ongoing investigation We are grateful to all our users for their trust in our platform and want to earn that trust, every time you choose to use or partner with DoorDash. We apologize for any concern this may cause. Any questions on the matter can be directed to our Support team, available by phone at (855) 431-0459, or through chat directly on your DoorDash app. Q: How do I know if I was affected by this issue? A: We have notified affected DoorDash users where required. Q: I am a Wolt or Deliveroo customer. Was I affected? A: No. Only DoorDash users were affected by this incident. Q: What types of DoorDash users were impacted? A: This incident impacted a mix of consumers, Dashers and merchants. Q: If my information was affected, why didn’t DoorDash notify me directly? A: DoorDash has directly notified affected users where required, published information about the incident on our website, and set up a dedicated call center to answer questions from users. Q: Was my payment card information compromised in connection with this incident? A: No. Based on our investigation, the incident only impacted basic contact information.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Doordash.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.