Skip to main content
Back to overview
Medium

DoorDash Data Breach Exposes Customer, Dasher, and Merchant Information via Social Engineering

Our Response to a Recent Cybersecurity Incident Our team recently identified and shut down a cybersecurity incident that involved an unauthorized third party gaining access to and taking certain user information.

Key points

  • Employee-targeted social engineering attack.
  • Exposed names, phone numbers, email addresses, and physical addresses.
  • Affected customers, Dashers (delivery workers), and merchants.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Phishing Social Engineering

Social activity

03

Potential impact

Potential fraud or account takeover risk

Confidentiality

Published
Nov 13, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Social activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: possible insider or internal misuse
  • Source type: supplier or third-party involvement

Business impact

Potential fraud or account takeover risk
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

DoordashData DisclosureDasherMerchant InformationSocial Engineering Our ResponseImportantlyA DoorDashOurDoorDashAt DoorDash

Quick context

Questions about this signal

What happened in this signal?

Our Response to a Recent Cybersecurity Incident Our team recently identified and shut down a cybersecurity incident that involved an unauthorized third party gaining access to and taking certain user information. Importantly, no sensitive information was accessed by the unauthorized third party and we have no indication the data has been misused for fraud or identity theft at this time. We want to let you know what happened, the type of data that was accessed by the unauthorized party, and how we’re responding. A DoorDash employee was recently targeted in a social engineering scam. The response team identified the incident, shut down the unauthorized party’s access, started an investigation, and referred the matter to law enforcement. Our investigation has determined that some users whose data is maintained by DoorDash were affected in connection with this incident. The personal information accessed varied by individual and may have included: No sensitive information, such as Social Security numbers or other government-issued identification numbers, driver’s license information, or bank or payment card information, was accessed. At DoorDash, we believe in continuous improvement and getting 1% better every day. We are committed to protecting your privacy and have already taken the following steps to help prevent events like this from happening again: Deployed new enhancements to our security systems to help prevent and detect malicious activities of this nature Implemented additional training and awareness for our employees around various social engineering scams Brought in an external firm to assist in our investigation and provide specialized support Referred the matter to law enforcement for ongoing investigation ​​We are grateful to all our users for their trust in our platform and want to earn that trust, every time you choose to use or partner with DoorDash. We apologize for any concern this may cause. Any questions on the matter can be directed to our Support team, available by phone at (855) 431-0459, or through chat directly on your DoorDash app. Q: How do I know if I was affected by this issue? A: We have notified affected DoorDash users where required. Q: I am a Wolt or Deliveroo customer. Was I affected? A: No. Only DoorDash users were affected by this incident. Q: What types of DoorDash users were impacted? A: This incident impacted a mix of consumers, Dashers and merchants. Q: If my information was affected, why didn’t DoorDash notify me directly? A: DoorDash has directly notified affected users where required, published information about the incident on our website, and set up a dedicated call center to answer questions from users. Q: Was my payment card information compromised in connection with this incident? A: No. Based on our investigation, the incident only impacted basic contact information.

When was this signal reported?

Shadow Tier lists Nov 13, 2025 as the signal date.

Which organization is connected to this signal?

Doordash is the organization connected to this public signal.

Explore Doordash
Which attack pattern is relevant?

This signal is connected to phishing and social-engineering intelligence based on its reported incident context.

Explore phishing and social-engineering intelligence