Skip to main content
The Markets by Proactive
Go to Proactive UK
Proactive UK has moved. Proactive’s coverage of London’s small caps continues on proactiveinvestors.com Go there →
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Coverage of London’s small caps continues on proactiveinvestors.com
Go to Proactive UK
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK

Tech

DoorDash hack leaks customer and payment info

The food delivery giant revealed that hackers used phished credentials from employees of a third-party vendor to gain access to some of DoorDash’s internal tools.

DoorDash Inc (NYSE:DASH) confirmed that a hack on its internal systems has compromised personal identifying information, as well as partial payment card information for a smaller set of customers during the data breach.

The food delivery giant revealed that hackers used phished credentials from employees of a third-party vendor to gain access to some of DoorDash’s internal tools.

DoorDash, in its statement, said: “The phishing campaign did not compromise sensitive information and we have no reason to believe that affected personal information has been misused for fraud or identity theft at this time.”

This isn’t the first time that hackers have stolen customer data from DoorDash’s systems. In 2019, the company reported a data breach affecting 4.9 million customers, delivery workers and merchants who had their information stolen by hackers.

What is breached?

For customers, the information accessed by the hackers primarily included names, email addresses, delivery addresses and phone numbers.

For a smaller set of customers, basic order information and partial payment card information (i.e., the card type and last four digits of the card number) were also accessed.

For delivery agents (Dashers), the information breached included the name and phone number or email address. The information affected for each impacted individual may vary.

DoorDash confirms that the hack did not compromise passwords, full payment card numbers, bank account numbers, or social security or social insurance numbers based on its information to date.

Does it affect me?

DoorDash says that a “small percentage” of users were affected by the incident but declined to clarify the scale of the attack.

The company says that it has notified the affected users where required, published information about the incident on its website, and set up a dedicated call centre to answer questions from users.

It also warns the customers to be cautious of unsolicited communications that ask for your personal information or refer you to a web page asking for personal information and to avoid clicking on links or downloading attachments from suspicious emails.

Who did it?

DoorDash has not named the third-party vendor which was compromised in the attack.

However, the company has engaged a leading cybersecurity expert to provide additional expertise and support to the vendor.

Door Dash spokesperson Justin Crowley confirmed to TechCrunch that the vendor breach is linked to the phishing campaign that compromised SMS and messaging giant Twilio on August 4.

Researchers linked these attacks to a wider phishing campaign by the same hacking group, dubbed "0ktapus", which has stolen close to 10,000 employee credentials from at least 130 organisations, including Twilio, Signal and other internet companies and outsourced customer service providers, since March.

Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK