Doordash Hit By New Data Breach In October Exposing User Information
DoorDash has disclosed a data breach that hit the food delivery platform this October.
Beginning yesterday evening, DoorDash, which serves millions of customers across the U.S., Canada, Australia, and New Zealand, started emailing those impacted by the newly discovered security incident.
"On October 25, 2025, our team identified a cybersecurity incident that involved an unauthorized third party gaining access to and taking certain user contact information, which varied by individual," states the email notification from DoorDash.
"Our investigation has since confirmed that your personal information was affected."
The incident has been traced to a DoorDash employee falling victim to a social engineering scam. Upon becoming aware, the company's incident response team shut down the unauthorized party's access, started an investigation, and referred the matter to law enforcement.
The disclosure does not specify how many users were affected, though the company says the incident impacted a mix of consumers, Dashers, and merchants.
This marks the third notable security incident suffered by the delivery giant.
In 2019, a data breach at DoorDash had exposed the information of roughly 5 million customers, Dashers and merchants to an unauthorized party.
In August 2022, the company encountered another data breach from threat actors who had also attacked Twilio that year.
What's interesting is that a French translation of the notice is appended to these emails:
Source: BleepingComputer