DoorDash confirms a data breach on May 4 affecting 4.9M customers, workers, and merchants, with last-four digits of payment cards, driver's license info stolen
DoorDash has confirmed a data breach. — The food delivery company said in a blog post Thursday that 4.9 million customers …
TechCrunch Zack Whittaker
Context & Ripple Effects
DoorDash's disclosure closes a five-month gap between the May 4 intrusion and confirmation, and lands on a platform whose business model concentrates identity data on couriers and merchants alongside customers. The food-delivery category had already been shown to be a target when Zomato lost 17 million email addresses and hashed passwords in 2017.
The stakes are sharpened by DoorDash's financial position at the time — reporting later showed the company lost around $450M in 2019 ahead of its IPO push — making trust damage a direct commercial risk rather than an abstract one.
First-order effects
- 4.9 million customers, Dashers, and merchants now hold partially exposed payment card digits and driver's license numbers — a combination tailored for phishing and identity fraud rather than direct card theft.
- DoorDash must fund credit-monitoring-style remediation and breach-response costs while still unprofitable, straight off an operating loss already measured in hundreds of millions.
Second-order effects
- Rival delivery platforms — Uber Eats, Grubhub, Postmates — face renewed scrutiny of their own driver-verification and merchant onboarding data stores, since all hold the same license-and-payment mix.
- Merchants and couriers weighing multi-homing across apps get one more reason to weight platform security posture, nudging loyalty economics toward whichever competitor can demonstrate tighter controls.
Third-order effects
- Gig platforms' consolidation of government-ID and payment fragments into single marketplaces makes them structurally attractive breach targets, pushing identity verification toward tokenized or third-party-held models.
- The recurrence is the telling signal: three years later hackers reached internal tools through a compromised vendor in the Twilio breach (DoorDash disclosed that second incident in August 2022), suggesting per-platform defense gives way to supply-chain and vendor-chain exposure as the sector's systemic weak point.
The trend: On-demand delivery platforms are learning that aggregating customer, courier, and merchant identity makes them recurring breach targets, shifting security spending from perimeter defense toward vendor-chain and identity-data minimization.
Related: DoorDash · Zomato hacked, 17M accounts stolen · DoorDash hit again via Twilio vendor breach · Sources: DoorDash lost around $450M in 2019
Related Coverage
- The Cybersecurity 202: U.S. voting machines vulnerable to hacks in 2020, researchers find Washington Post · Joseph Marks
- Security News This Week: A DoorDash Breach Exposes Data of 4.9 Million Customers Wired
- Important security notice about your DoorDash account DoorDash Engineering Blog
- Top News In Payments: House Committee Holds RTP Hearing; DoorDash Reveals May Data Breach PYMNTS.com
- Doordash's breach is different Boing Boing · Cory Doctorow
- 5M Users' DoorDash Data Dupe'd by Dastardly Deeds Security Boulevard · Richi Jennings
- Doordash's Latest Data Breach: How to Protect Yourself Lifehacker · David Murphy
- DoorDash Data Breach: What to Do If Your Account Was Compromised Fortune · Chris Morris
- DoorDash has five million records swiped in unappetising breach Inquirer · Chris Merriman
- DoorDash Confirms A Data Breach, 4.9 Million Users Affected Android Headlines · Sumit Adhikari
- DoorDash Discloses Data Breach Impacting 4.9 Million People CBS San Francisco
- DoorDash Breach Affects 4.9M Merchants, Customers, Workers Dark Reading
- DoorDash Announces Data Breach Affecting 4.9 Million Accounts iPhone in Canada Blog · Usman Qureshi
- DoorDash slammed with a massive data breach affecting 4.9M customers - were you affected? KnowTechie · Joe Rice-Jones
- DoorDash data breach affects nearly 5 million customers The Daily Dot · Nahila Bonfiglio
- DoorDash leaves door open for data breach, affecting 4.9M people The Next Web · Ravie Lakshmanan
- 4.9 million accounts affected by DoorDash server breach iMore · Stephen Warwick
- DoorDash suffered a data breach in May affecting 4.9 million users Android Police · Manuel Vonau
- DoorDash confirms 4.9M accounts accessed in major server breach AppleInsider · Malcolm Owen
- DoorDash Data Breach Affects 4.9 Million People The Mac Observer · Andrew Orr
- DoorDash reveals third-party data breach hit 4.9 million users IT PRO · Bobby Hellard
- Here's everything you need to know about the DoorDash data breach Fast Company · Michael Grothaus
- DoorDash Breach Exposes 4.9 Million Users' Personal Data The Hacker News · Swati Khandelwal
- DoorDash data breach will literally have customers dashing to lock their doors Android Authority · Adamya Sharma
- DoorDash confirms data breach affecting 4.9m customers and workers Silicon Republic · Kelly Earley
- DoorDash Breach Exposes Data on Nearly Five Million Users infosecurity-magazine.com · Phil Muncaster
- DoorDash Data Breach exposes data of approximately 5 million users Security Affairs · Pierluigi Paganini
- DoorDash Breach Exposes Data of Nearly 5 Mn Users SecurityWeek
- DoorDash hack spills loads of data for 4.9 million people Ars Technica · Dan Goodin
- Hackers stole the data of 4.9 million DoorDash users. Here's how to check if you were affected. Business Insider · Aaron Holmes
- DoorDash doesn't just pick up your food orders, it delivers your data to hackers, too The Register · Shaun Nichols
- Nearly 5 Million DoorDash Food Delivery Accounts Hacked, Private Information Stolen In Data Breach CBS New York
- Companies must focus on growth but avoid neglecting cybersecurity Tech Wire Asia · Soumik Roy
- DoorDash hacked! — Food delivery services are all the rage these days. BetaNews · Brian Fagioli
- DoorDash food delivery company data breach affected 4.9 million users SlashGear · JC Torres
- 4.9M customer and provider records stolen in DoorDash data breach SiliconANGLE · Duncan Riley
- DoorDash says 4.9 million users exposed in privacy breach The Hill · Harper Neidig
- DoorDash security breach affects nearly 5 million users Engadget · AJ Dellinger
- 4.9 million customers, workers, and merchants affected in DoorDash data breach TechSpot · Cal Jeffrey
- DoorDash suffered a data breach that affected 4.9 million people CNN · Ahiza Garcia
- DoorDash announces data breach affecting 4.9 million people The Verge · Jay Peters
- Doordash data breach affects 4.9 million people, divulges physical addresses Digital Trends · Christian de Looper
Discussion
-
@zackwhittaker
Zack Whittaker
on x
You know what's really weird? @DoorDash has no mention of its massive data breach on its homepage. There's nothing on its Twitter or Facebook page, either. What's also weird is DoorDash's robots file hides “/securitynotice” from Google, so people can't even search for it. https:/…
-
@bryanlunduke
Bryan Lunduke
on x
Said it before and I'll say it again: This sort of data breach will increase in frequency. There is no way to stop it. As systems become increasingly complex, they become increasingly vulnerable. As more people use those systems, they become more valuable as a target. https://twi…
-
@williamturton
William Turton
on x
DoorDash just announced a security breach. “Approximately 4.9 million consumers, Dashers, and merchants who joined our platform on or before April 5, 2018, are affected.” Includes the drivers license number of 100K Dashers. https://blog.doordash.com/...
-
@hunterwalk
@hunterwalk
on x
“Encouraging” your users to change their passwords after a hack is the half-pregnant approach to trust & safety. If you believe pw are at risk, force the reset on the customer & take the business hit If not, don't do the CYA “we are encouraging....” https://blog.doordash.com/... …
-
@workingwa
@workingwa
on x
They tried to hide the fact they were stealing tips for about 2 years, so relatively speaking they were quite prompt on this one? 😉 https://twitter.com/...
-
@alt_uscis
ALT-immigration
on x
We ne e to legislate personal data as personal property and flat out prosecute anyone or any company misusing it, losing it, selling it without consent and get a cut every time they sell it https://twitter.com/...
-
@mzbat
@mzbat
on x
Credit card info not accessed. Passwords were salted/hashed. Mostly just data available on public dox sites. May as well just order another cheeseburger and tip your delivery person. 🍔 https://twitter.com/...
-
@oliviasolon
Olivia Solon
on x
If only Doordash looked after customer data as well as it looked after driver tips https://twitter.com/...
-
@lawyerliz
Elizabeth Wharton
on x
#doordash breach (via a #thirdparty) happened May 4th but disclosed today (5 months later). its $600m Series G ($12b valuation) was announced May 24th (3wks after the breach). https://twitter.com/...
-
@skaijackson
Skai
on x
Postmates would never 😴 https://twitter.com/...
-
@dhh
@dhh
on x
DoorDash hid a data breach of 4.9 million customers for almost five months, after previously denying hacks. Delivery addresses, order history, phone numbers, the whole shebang, all breached. For delivery workers, their driver's license was also breached. https://techcrunch.com/..…
-
@r41nm4kr
Andy Thompson
on x
TLDR: “Users who joined the platform before April 5, 2018 had their name, email and delivery addresses, order history, phone numbers, and hashed and salted passwords stolen.” Last 4 of cc taken, but full num & CVV not taken. Hashed & salted at least. /shrug https://twitter.com/..…
-
@chrisalbon
Chris Albon
on x
I look forward to more credit monitoring to add to the pile. https://twitter.com/...
-
@malwarejake
Jake Williams
on x
I think it's time to publish a “before you get on the phone with Zack” guide for breached organizations... https://twitter.com/...
-
@susanthesquark
Susan Fowler
on x
As long as companies keep storing customer data, this will keep happening: https://techcrunch.com/...
-
@zackwhittaker
Zack Whittaker
on x
DoorDash spokesperson declined to say what password hashing algorithm they used, why it took the company nearly five months to disclose the breach, or which third-party was allegedly to blame for the breach. Just like old times. https://techcrunch.com/...
-
@artemr
Artem Russakovskii
on x
DoorDash got breached: - Profile information including names, email addresses, delivery addresses, order history, phone numbers, as well as hashed, salted passwords - For some consumers, the last four digits of consumer payment cards ... https://blog.doordash.com/...