/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

DoorDash says hackers accessed some of its internal tools and customer information after compromising a third-party vendor as part of the recent Twilio breach

Hackers accessed DoorDash customer information and some partial payment data  —  Food delivery giant DoorDash has confirmed …

TechCrunch Carly Page

Context & Ripple Effects

DoorDash had already disclosed a 2019 breach affecting customers, workers and merchants, including payment-card last digits and driver’s-license information. The new incident adds a different exposure path: a third-party compromise connected to Twilio’s SMS-phishing attack reached DoorDash’s internal tools and customer data.

The episode matters because it ties DoorDash’s security posture to the access controls of vendors in its communications stack, rather than to a breach limited to DoorDash’s own systems.

First-order effects

  • DoorDash must assess exposure spanning customer information, partial payment data and internal tools, while affected customers face another data-security incident after the company’s 2019 breach affecting customers, workers and merchants.
  • Twilio’s August 4 staff-phishing incident now has a disclosed downstream impact on DoorDash through a compromised third-party vendor.

Second-order effects

  • DoorDash’s vendor relationships become an immediate security-review priority, because access obtained outside its own systems reached both customer data and internal tooling.
  • Twilio faces greater scrutiny from customers whose vendors and accounts were exposed through the SMS-based phishing attack, putting employee-authentication controls at the center of customer trust.

Third-order effects

  • Repeated DoorDash disclosures show that breach exposure can recur through both a company’s own environment and its supplier network, making third-party access a persistent governance issue for consumer platforms.
  • If incidents tied to communications vendors continue, platform security programs will increasingly be judged by how narrowly partners can reach operational tools and customer data.

The trend: Cybersecurity risk is shifting from isolated company perimeters toward the vendor and integration layers that connect consumer platforms to their operational systems.

Discussion

  • @jbursz Jessica Bursztynsky on x
    DoorDash says it was hit by a data breach that exposed customers' information like name, address & partial payment card info. “The advanced tactics used appear to be connected to a wider phishing campaign that has targeted a number of other companies.” https://doordash.news/...
  • @campuscodi Catalin Cimpanu on x
    Twilio... the hack that keeps on giving https://twitter.com/...
  • @neurovagrant Ian Campbell on x
    Really good data herein relating to a bunch of the okta-targeted activity I've been crowing about for months. https://twitter.com/...
  • @ajvicens AJ Vicens on x
    New look at some technical details, scope and information related to someone possibly involved in the Twilio breach from @GroupIB_GIB https://blog.group-ib.com/0ktapus
  • @campuscodi Catalin Cimpanu on x
    Group-IB report on 0ktapus, a phishing campaign targeting Okta accounts -started in March 2022 -collected creds sent to a Telegram channel -collected almost 10k credentials -from more than 130 orgs https://blog.group-ib.com/0ktapus https://twitter.com/...
  • @groupib_gib @groupib_gib on x
    The Group-IB team found that the threat actor managed to steal 9,931 user credentials, including 3,129 records with emails, and 5,441 records with #MFA codes: https://blog.group-ib.com/0ktapus #phishing #0ktapus https://twitter.com/...
  • @jcybersec_ @jcybersec_ on x
    Group IB analysis of the Okta phishing kits we have been seeing recently🔍 ⚠️This was the group which caused the Twilio breach and caused the Signal alert a week ago https://blog.group-ib.com/0ktapus