[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1q0flwtdbfxv7":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda4882518d","door-dash","DoorDash Data Breach","doordash","doordash.com","2022-08-02T00:00:00.000Z","2023-01-07T03:59:32.000Z","2026-07-09T21:27:45.470Z","2026-07-18T23:49:43.181Z","Third party breach","https:\u002F\u002Fhelp.doordash.com\u002Fen-us\u002Fdashers\u002Farticle\u002Fhow-we-re-responding-to-a-third-party-vendor-phishing-incident-dx",[16,18,19],"https:\u002F\u002Fwww.bitdefender.com\u002Fen-us\u002Fblog\u002Fhotforsecurity\u002Fdoordash-says-data-breach-at-third-party-vendor-exposes-personal-data-of-customers-and-employees","https:\u002F\u002Fwww.genovaburns.com\u002Fnews\u002Ffirm-news\u002F2022-10-03-doordash-hacker-incident-illustrates-third-party-vendor-risks-and-potential-vulnerabilities",367476,"known",null,"unknown","High",[26,27,28,29,30,31,32],"Email addresses","Names","Phone numbers","Physical addresses","Geographic locations","Partial credit card data","Purchases","\u003Cp>The DoorDash data breach is a security incident originating from a third-party supplier, which the food ordering and delivery platform disclosed in August 2022. The record is associated with 367,476 unique personal email addresses. The company stated that after a phishing campaign occurred on the supplier side, an unauthorized person accessed some internal tools, the access was stopped, and the incident affected certain personal information held by DoorDash. This record should not be confused with the 2019 DoorDash incident or later different disclosures; the incident described here is the 2022 supplier-sourced event.\u003C\u002Fp>\n\u003Cp>The verified data fields are names, email addresses, phone numbers, delivery addresses or postal codes, basic order information for a smaller consumer group, and partial payment card information. Partial card information is described with limited fields such as card type, last four digits, and in some records, expiration information. Full card numbers, bank accounts, passwords, Social Security numbers, or Social Insurance numbers were not reported among the data fields accessed in this incident. Therefore, the risk lies more in targeted phishing, delivery fraud, and fake support scenarios that build trust using partial card data, rather than full financial account compromise.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The types of data verified in the DoorDash record are email addresses, names, phone numbers, delivery addresses or postal codes, basic order information, and partial payment card data. When email, name, and phone number are together, fake support messages, delivery issue notifications, or account verification requests become more convincing. The delivery address and postal code provide context about the area where the person lives or frequently orders. While this context alone does not constitute full identity theft, it facilitates the personalization of fraudulent messages.\u003C\u002Fp>\n\u003Cp>Although partial card information is limited, it is not completely meaningless. The card type and the last four digits can be misused in a fake customer service conversation to gain the user's trust. Since the full card number or bank account is not provided, the risk of direct withdrawal from the card cannot be established through this record; however, messages trying to persuade the user to provide additional information can be expected. If basic order information has been accessed for a smaller group, fake return, missing delivery, coupon, or fee adjustment scenarios may appear more realistic.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified incident belongs to the August 2022 period and is linked to a phishing campaign that started through the supplier network. DoorDash stated that after noticing unusual activity, it disabled the supplier's access and contained the incident. The number of affected individuals is recorded in this report as 367,476 unique personal email addresses. The official statement does not say that all DoorDash users were affected; it indicates that data belonging to a small percentage was affected. The affected data fields may also vary from person to person.\u003C\u002Fp>\n\u003Cp>Boundaries are especially important. In this incident, passwords, full payment card numbers, bank account numbers, Social Security numbers, and Social Insurance numbers were not reported among the accessed areas. Therefore, the user should not be treated as if there is a password leak or full card data leak. Partial card data only refers to limited card identifiers. In addition, this record is not the same as DoorDash's approximately 4.9 million-person incident in 2019; the 2022 vendor incident is smaller in scope but requires attention due to the delivery and partial payment context as a separate breach.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group consists of consumers whose information was held by DoorDash in 2022 and who received a notification in connection with the incident. Individuals with a phone number and delivery address may be targeted with fake delivery driver, fake customer service, or order refund messages. For users in the smaller partial card or basic order information group, messages may be more convincing; because the attacker can try to add credibility to the conversation by using details such as the last four digits of the card or the context of past orders.\u003C\u002Fp>\n\u003Cp>Delivery workers known as Dashers may also be part of the incident. The official statement indicated that the name, phone number, or email address of this group may have been affected. These individuals could be targeted with fake payment, earnings transfer, account verification, or support representative calls. Restaurant and vendor side data is not the main focus for this record; however, due to the different roles within the DoorDash ecosystem, users should carefully check which account type the message is addressing. The DoorDash data breach particularly increases the risk of social engineering conducted via phone and text messages.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Unexpected emails, text messages, or phone calls regarding DoorDash should not be clicked on, and one-time codes should not be shared. Messages claiming to be about delivery address, order returns, account verification, or payment corrections should be checked directly through the official app or web account. The person calling should not be trusted just because partial card information is known; real support teams should not ask for the full card number, bank account, password, or one-time verification code.\u003C\u002Fp>\n\u003Cp>Using a strong and unique password on your DoorDash account is still a good security step; however, in this incident, since password access was not reported, the main urgent measure is to be cautious against social engineering risk. If there is an increase in spam on the phone line, filters should be used at the device and operator level. Tracking unusual transactions on card statements should be maintained as a general security habit; however, the verified scope of this record does not include full card numbers or bank accounts. Requests for earnings transfers, bank account changes, or support calls for Dashers should be additionally verified.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In the long term, the address, phone number, and payment method information kept in delivery and shopping accounts should be regularly reviewed. Addresses that are no longer used should be deleted, unnecessary payment methods should be removed, and separate addresses other than the main email should be preferred for campaign accounts. Users should not use the same password pattern on different delivery platforms. The email account should be strongly protected, as recovery links for delivery accounts often come via email.\u003C\u002Fp>\n\u003Cp>From a corporate perspective, the DoorDash incident shows that third-party supplier access poses a direct risk to customer data. For suppliers, the principle of least privilege, temporary access, strong authentication, unusual access alerts, and phishing-resistant employee verification are required. Delivery platforms must protect user data not only within their own systems but also through the suppliers they use. Even if partial card and order data appear limited, the impact on customer trust and fraud risk is significant.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you see a match in this record, your email address may have been found among the 367,476 unique emails associated with the DoorDash 2022 data breach. A match does not mean that your password or full card number has been leaked. However, it indicates that fields such as your name, email, phone, delivery address, or basic order and partial card information for a smaller group could pose a risk. The first step is to check your DoorDash account through the official channel and approach unexpected messages with suspicion.\u003C\u002Fp>\n\u003Cp>It is possible for your delivery address, phone number, or partial payment context to be used in a scam message. Therefore, one-time codes, full card numbers, bank information, or passwords should not be given to anyone claiming to be a support representative. Earnings transfer and account verification requests for Dashers should be verified directly from the official app. The correct response to a DoorDash data breach is to acknowledge that verified vendor-source data fields can be used in social engineering without exaggerating the incident as a full financial leak, and to strengthen account and communication security.\u003C\u002Fp>","","DoorDash Data Breach (367.5 Thousand Reported Records)","DoorDash Data Breach. 367.5 Thousand reported records were reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fdoordash_com.webp",false,{"name":40,"sector":41,"country":42,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":22},"DoorDash","Technology","United States"]