/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

DoorDash confirms a data breach on May 4 affecting 4.9M customers, workers, and merchants, with last-four digits of payment cards, driver's license info stolen

DoorDash has confirmed a data breach.  —  The food delivery company said in a blog post Thursday that 4.9 million customers …

TechCrunch Zack Whittaker

Context & Ripple Effects

DoorDash's disclosure closes a five-month gap between the May 4 intrusion and confirmation, and lands on a platform whose business model concentrates identity data on couriers and merchants alongside customers. The food-delivery category had already been shown to be a target when Zomato lost 17 million email addresses and hashed passwords in 2017.

The stakes are sharpened by DoorDash's financial position at the time — reporting later showed the company lost around $450M in 2019 ahead of its IPO push — making trust damage a direct commercial risk rather than an abstract one.

First-order effects

  • 4.9 million customers, Dashers, and merchants now hold partially exposed payment card digits and driver's license numbers — a combination tailored for phishing and identity fraud rather than direct card theft.
  • DoorDash must fund credit-monitoring-style remediation and breach-response costs while still unprofitable, straight off an operating loss already measured in hundreds of millions.

Second-order effects

  • Rival delivery platforms — Uber Eats, Grubhub, Postmates — face renewed scrutiny of their own driver-verification and merchant onboarding data stores, since all hold the same license-and-payment mix.
  • Merchants and couriers weighing multi-homing across apps get one more reason to weight platform security posture, nudging loyalty economics toward whichever competitor can demonstrate tighter controls.

Third-order effects

  • Gig platforms' consolidation of government-ID and payment fragments into single marketplaces makes them structurally attractive breach targets, pushing identity verification toward tokenized or third-party-held models.
  • The recurrence is the telling signal: three years later hackers reached internal tools through a compromised vendor in the Twilio breach (DoorDash disclosed that second incident in August 2022), suggesting per-platform defense gives way to supply-chain and vendor-chain exposure as the sector's systemic weak point.

The trend: On-demand delivery platforms are learning that aggregating customer, courier, and merchant identity makes them recurring breach targets, shifting security spending from perimeter defense toward vendor-chain and identity-data minimization.

Discussion

  • @zackwhittaker Zack Whittaker on x
    You know what's really weird? @DoorDash has no mention of its massive data breach on its homepage. There's nothing on its Twitter or Facebook page, either. What's also weird is DoorDash's robots file hides “/securitynotice” from Google, so people can't even search for it. https:/…
  • @bryanlunduke Bryan Lunduke on x
    Said it before and I'll say it again: This sort of data breach will increase in frequency. There is no way to stop it. As systems become increasingly complex, they become increasingly vulnerable. As more people use those systems, they become more valuable as a target. https://twi…
  • @williamturton William Turton on x
    DoorDash just announced a security breach. “Approximately 4.9 million consumers, Dashers, and merchants who joined our platform on or before April 5, 2018, are affected.” Includes the drivers license number of 100K Dashers. https://blog.doordash.com/...
  • @hunterwalk @hunterwalk on x
    “Encouraging” your users to change their passwords after a hack is the half-pregnant approach to trust & safety. If you believe pw are at risk, force the reset on the customer & take the business hit If not, don't do the CYA “we are encouraging....” https://blog.doordash.com/... …
  • @workingwa @workingwa on x
    They tried to hide the fact they were stealing tips for about 2 years, so relatively speaking they were quite prompt on this one? 😉 https://twitter.com/...
  • @alt_uscis ALT-immigration on x
    We ne e to legislate personal data as personal property and flat out prosecute anyone or any company misusing it, losing it, selling it without consent and get a cut every time they sell it https://twitter.com/...
  • @mzbat @mzbat on x
    Credit card info not accessed. Passwords were salted/hashed. Mostly just data available on public dox sites. May as well just order another cheeseburger and tip your delivery person. 🍔 https://twitter.com/...
  • @oliviasolon Olivia Solon on x
    If only Doordash looked after customer data as well as it looked after driver tips https://twitter.com/...
  • @lawyerliz Elizabeth Wharton on x
    #doordash breach (via a #thirdparty) happened May 4th but disclosed today (5 months later). its $600m Series G ($12b valuation) was announced May 24th (3wks after the breach). https://twitter.com/...
  • @skaijackson Skai on x
    Postmates would never 😴 https://twitter.com/...
  • @dhh @dhh on x
    DoorDash hid a data breach of 4.9 million customers for almost five months, after previously denying hacks. Delivery addresses, order history, phone numbers, the whole shebang, all breached. For delivery workers, their driver's license was also breached. https://techcrunch.com/..…
  • @r41nm4kr Andy Thompson on x
    TLDR: “Users who joined the platform before April 5, 2018 had their name, email and delivery addresses, order history, phone numbers, and hashed and salted passwords stolen.” Last 4 of cc taken, but full num & CVV not taken. Hashed & salted at least. /shrug https://twitter.com/..…
  • @chrisalbon Chris Albon on x
    I look forward to more credit monitoring to add to the pile. https://twitter.com/...
  • @malwarejake Jake Williams on x
    I think it's time to publish a “before you get on the phone with Zack” guide for breached organizations... https://twitter.com/...
  • @susanthesquark Susan Fowler on x
    As long as companies keep storing customer data, this will keep happening: https://techcrunch.com/...
  • @zackwhittaker Zack Whittaker on x
    DoorDash spokesperson declined to say what password hashing algorithm they used, why it took the company nearly five months to disclose the breach, or which third-party was allegedly to blame for the breach. Just like old times. https://techcrunch.com/...
  • @artemr Artem Russakovskii on x
    DoorDash got breached: - Profile information including names, email addresses, delivery addresses, order history, phone numbers, as well as hashed, salted passwords - For some consumers, the last four digits of consumer payment cards ... https://blog.doordash.com/...