Skip to main content
Back to overview
High

DoorDash Confirms Data Breach After Social Engineering Attack

DoorDash, the popular food delivery platform, publicly acknowledged a cybersecurity incident that compromised the personal information of an undisclosed number of users.

Key points

  • Unauthorized third party accessed user data through a social engineering attack on a DoorDash employee.
  • Incident occurred on October 25, but public disclosure was made in mid-November.
  • Compromised data includes names, phone numbers, email addresses, and physical addresses.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Social, Hacking activity

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Jul 22, 2026
Updated
Jul 25, 2026
Confidence
High
Evidence
6 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Social, Hacking activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: possible insider or internal misuse
  • Source type: supplier or third-party involvement

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

DoordashData DisclosureSocial Engineering Attack DoorDashDoorDashDashersUnited StatesCanadaAustraliaNew Zealand. DoorDashIDs

Quick context

Questions about this signal

What happened in this signal?

DoorDash, the popular food delivery platform, publicly acknowledged a cybersecurity incident that compromised the personal information of an undisclosed number of users. The breach, which occurred on October 25, was a result of a social engineering attack targeting a company employee. This allowed an unauthorized third party to gain access to DoorDash's internal systems. The compromised data varied by individual but potentially included first and last names, phone numbers, email addresses, and physical addresses of customers, Dashers (delivery drivers), and merchants across the United States, Canada, Australia, and New Zealand. DoorDash emphasized that no sensitive financial information, such as Social Security numbers, government-issued IDs, driver's license details, bank information, or payment card data, was accessed. The company's security team identified and shut down the unauthorized access shortly after its detection, launched an internal investigation, and notified law enforcement. DoorDash has also implemented multiple security enhancements, including upgraded security systems and additional employee training programs focused on social engineering awareness. While the company has stated there is no indication the data has been misused for fraud or identity theft, affected users are advised to be cautious of unsolicited communications requesting personal information. This incident marks DoorDash's third known cybersecurity incident in six years, highlighting the persistent threat of social engineering attacks.

When was this signal reported?

Shadow Tier lists Jul 22, 2026 as the signal date.

Which organization is connected to this signal?

Doordash is the organization connected to this public signal.

Explore Doordash
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence