DoorDash, a major food delivery service, suffered a data breach on October 25, 2025, after an employee was deceived by a social engineering scam. The attacker gained unauthorized access to internal systems, resulting in the exposure of user contact information, including full names, physical addresses, email addresses, and phone numbers. The breach affected customers, delivery drivers, and merchants across the United States, Canada, Australia, and New Zealand. DoorDash's security team detected the incident and responded by shutting down the unauthorized access and launching an investigation, while also notifying law enforcement.
DoorDash has stated that no sensitive financial or government identification data, such as credit card numbers or Social Security numbers, was compromised. However, the combination of names, emails, and phone numbers raises concerns about the potential for targeted phishing or smishing attacks. The company has begun notifying affected users, with reports indicating that Canadian users were among the first to receive alerts. This incident marks the third significant security breach for DoorDash in recent years, following previous incidents in 2019 and 2022.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
By mid-November 2025, DoorDash confirmed the data breach and disclosed that user information had been exposed as a result of the October incident. News coverage on November 13-18 reported the company’s acknowledgment and details of the compromised data.
During the October 2025 incident, attackers accessed DoorDash user information, including names, phone numbers, and physical addresses, with some reports saying millions of users may have been affected. The breach exposed customer data but the exact scope was not consistently reported across sources.
In October 2025, attackers used a social engineering scam against a DoorDash employee to gain unauthorized access to company data. Multiple reports describe the breach as stemming from employee compromise rather than a software exploit.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcetechcrunch.com
Open sourcetechrepublic.com
Open sourcescworld.com
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.