DoorDash confirms a data breach on May 4 affecting 4.9M customers, workers, and merchants, with last-four digits of payment cards, driver's license info stolen
DoorDash has confirmed a data breach. — The food delivery company said in a blog post Thursday that 4.9 million customers …
TechCrunchZack Whittaker
Context & Ripple Effects
DoorDash's disclosure lands three years after a rival delivery platform suffered a comparable exposure — Zomato's hack of 17 million email addresses and hashed passwords — confirming that consumer food-delivery databases holding identity documents are a standing target class, not a one-off. The stolen mix here matters more than the count: last-four card digits alone are low-value, but paired with driver's license information they feed convincing targeted fraud against customers, gig workers, and merchant accounts.
The timing compounds the damage: DoorDash was burning cash ahead of its public listing — sources put its 2019 loss around $450M while it lined up convertible debt — so a seven-figure-user breach arrives during the exact window when its security posture gets priced by IPO buyers. The company's later compromise of internal tools through a third-party vendor tied to the Twilio breach suggests the 2019 incident was not an isolated lapse but the first entry in a recurring vendor-and-perimeter problem.
First-order effects
4.9 million customers, Dashers, and merchants must now treat partial card digits plus driver's license data as compromised, making them targets for spear-phishing and account-takeover attempts rather than generic card fraud.
DoorDash absorbs direct response costs — forensics, notification, support — at a moment when its disclosed ~$450M annual loss leaves no cushion for reputational drag ahead of an expected public offering.
Second-order effects
Merchant and Dasher trust becomes a competitive lever rivals can pull: platforms courting the same restaurant and courier supply chains can pitch tighter data handling to partners weighing which marketplace to list on.
If the pattern holds — 2019's direct breach followed by 2022's vendor-mediated intrusion — delivery marketplaces get treated by attackers as durable identity troves, forcing the industry to harden third-party access and credential storage as core infrastructure rather than periodic patchwork.
Repeated mega-breaches across gig platforms raise the likelihood that regulators treat worker and contractor identity data held by marketplaces with the same scrutiny long applied to banks and retailers, adding a compliance layer to gig-economy unit economics already under margin pressure.
The trend: Consumer delivery platforms are consolidating into high-value identity repositories whose recurring breaches — direct and vendor-mediated — are pushing security from back-office cost to a competitive and regulatory battleground.
DoorDash just announced a security breach. “Approximately 4.9 million consumers, Dashers, and merchants who joined our platform on or before April 5, 2018, are affected.” Includes the drivers license number of 100K Dashers. https://blog.doordash.com/...
#doordash breach (via a #thirdparty) happened May 4th but disclosed today (5 months later). its $600m Series G ($12b valuation) was announced May 24th (3wks after the breach). https://twitter.com/...
“Encouraging” your users to change their passwords after a hack is the half-pregnant approach to trust & safety. If you believe pw are at risk, force the reset on the customer & take the business hit If not, don't do the CYA “we are encouraging....” https://blog.doordash.com/... …
Credit card info not accessed. Passwords were salted/hashed. Mostly just data available on public dox sites. May as well just order another cheeseburger and tip your delivery person. 🍔 https://twitter.com/...
DoorDash hid a data breach of 4.9 million customers for almost five months, after previously denying hacks. Delivery addresses, order history, phone numbers, the whole shebang, all breached. For delivery workers, their driver's license was also breached. https://techcrunch.com/..…
TLDR: “Users who joined the platform before April 5, 2018 had their name, email and delivery addresses, order history, phone numbers, and hashed and salted passwords stolen.” Last 4 of cc taken, but full num & CVV not taken. Hashed & salted at least. /shrug https://twitter.com/..…
We ne e to legislate personal data as personal property and flat out prosecute anyone or any company misusing it, losing it, selling it without consent and get a cut every time they sell it https://twitter.com/...
They tried to hide the fact they were stealing tips for about 2 years, so relatively speaking they were quite prompt on this one? 😉 https://twitter.com/...
DoorDash spokesperson declined to say what password hashing algorithm they used, why it took the company nearly five months to disclose the breach, or which third-party was allegedly to blame for the breach. Just like old times. https://techcrunch.com/...
DoorDash got breached: - Profile information including names, email addresses, delivery addresses, order history, phone numbers, as well as hashed, salted passwords - For some consumers, the last four digits of consumer payment cards ... https://blog.doordash.com/...