Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

DoorDash’s 2025 Data Breach: What Was Exposed and What to Do

By TheFinanceBase Team6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Yes, DoorDash suffered a confirmed cybersecurity incident in 2025. DoorDash said an employee or third-party vendor was targeted through social engineering or phishing, exposing limited information belonging to some consumers, Dashers, and merchants. The potentially exposed data included names, email addresses, phone numbers, and physical or delivery addresses. A separate DoorDash notice says a smaller group of consumers may also have had basic order information and partial card details—card type and last four digits—accessed.

There is no separately verified 2026 DoorDash breach in the primary evidence cited here. The confirmed incident was identified in October 2025 and publicly disclosed in November 2025.

What happened in the DoorDash breach?

DoorDash’s public descriptions do not use identical wording. Its consumer notice says an employee was targeted in a social-engineering scam. A second DoorDash notice describes a phishing incident involving a third-party vendor whose stolen credentials were used to access some internal tools.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The available public material does not establish whether these were separate incidents, overlapping disclosures, or descriptions of the same campaign. It is therefore more accurate to describe them as DoorDash’s 2025 cybersecurity incidents rather than confidently calling them two unrelated breaches.

DoorDash said it detected suspicious activity, disabled access, investigated with an outside cybersecurity firm, notified affected people where required, and contacted law enforcement. Its annual report identifies October 2025 as the timing of the incident and says it did not materially affect the company’s business, results, or financial condition. Read the SEC filing.

The consumer notice was posted on November 13, 2025, and updated on December 19, 2025.

Who may have been affected?

DoorDash said some of the affected people were:

  • Consumers
  • Dashers
  • Merchants

DoorDash has not publicly provided a confirmed total number of affected individuals in the cited incident notices or annual-report language. Do not assume that every DoorDash user was affected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information may have been exposed?

The information varied by person. Depending on which DoorDash notice applies, it may have included:

  • First and last name
  • Email address
  • Phone number
  • Physical or delivery address
  • Basic order information for a smaller group of consumers
  • Card type and the last four digits of a payment card for a smaller group of consumers

DoorDash’s consumer notice describes the incident more narrowly as involving basic contact information, while its vendor-incident notice includes the additional possibility of order information and partial card data. That distinction matters: saying broadly that “no payment information was exposed” would omit the vendor notice’s reference to card type and last four digits.

What DoorDash says was not accessed

DoorDash says the 2025 incident did not expose passwords, full payment-card numbers, bank-account numbers, Social Security numbers, Social Insurance numbers, driver’s-license information, or other government-issued identification numbers.

The safest summary is: DoorDash says passwords, full card numbers, bank-account numbers, and government identification numbers were not accessed; one notice says a smaller group may have had card type and the last four digits exposed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was this the same as DoorDash’s 2019 breach?

No. The 2019 breach was a separate event. In its historical security notice, DoorDash said an unauthorized third party accessed data belonging to users who joined on or before April 5, 2018. DoorDash said approximately 4.9 million consumers, Dashers, and merchants were affected, and that driver’s-license numbers for approximately 100,000 Dashers were accessed. See DoorDash’s 2019 notice.

The 2025 incidents were described as social engineering or vendor phishing involving limited information. They should not be presented as a continuation of the 2019 database compromise unless a future authoritative investigation establishes that connection.

How to find out whether you were affected

  1. Search the email account connected to DoorDash for an official notification. Search for “DoorDash” and review messages carefully, including the sender address and links.
  2. Check the DoorDash app or type the official DoorDash website address yourself instead of clicking a link in an unsolicited message.
  3. If you remain unsure, contact DoorDash through in-app chat or the official Help Center notice.
  4. Do not provide a password, one-time code, payment details, or identity document to someone who contacts you unexpectedly.

Not receiving a notice means you should not assume you were affected, but it is not proof that no DoorDash-related information has ever been exposed. Notification rules and available remedies also vary by country and jurisdiction.

What consumers and Dashers should do now

1. Change reused passwords

DoorDash says passwords were not accessed, but changing your DoorDash password is still sensible if you reused it elsewhere. Use a unique password that is not used for email, banking, shopping, or social media. Change the same password anywhere else it was reused.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A password manager such as Bitwarden, 1Password, or Proton Pass can generate and store unique passwords. You do not need to buy one to take the essential steps.

2. Review your DoorDash account

Check recent orders, saved payment methods, account details, and unfamiliar activity. DoorDash says it is implementing notifications for logins from new devices; treat unexpected login alerts seriously.

For Dashers who believe an account is compromised, DoorDash’s instructions say to open the app’s Settings tab and change the password, then contact support through chat or phone if necessary. See the account-compromise support page.

3. Monitor payment accounts

Review card and bank statements for unauthorized transactions. If you see one, contact the card issuer using the number on the card or its official app, dispute the transaction, and follow the issuer’s advice.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not automatically cancel every card solely because of this incident. If only the card type and last four digits were exposed, an attacker does not have the full card number. Replacing the card becomes more appropriate if there are suspicious transactions, the issuer recommends it, or the full number may have been exposed through another event.

4. Decide whether credit protection is warranted

Because DoorDash says Social Security numbers, Social Insurance numbers, and government IDs were not accessed, a credit freeze is not automatically necessary for every person affected by the 2025 incident.

  • Credit freeze: Restricts access to your credit file and is generally the strongest protection against new-account fraud.
  • Fraud alert: Asks creditors to take additional steps to verify your identity.
  • Credit monitoring: Alerts you to certain changes but does not prevent all fraud.

A freeze or alert may still make sense if you have broader identity-theft concerns or believe sensitive information was exposed in another incident. Do not assume DoorDash provided identity-theft monitoring unless your individual notification specifically says so.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Watch for follow-up DoorDash scams

Names, addresses, phone numbers, email addresses, and possibly order details can make impersonation attempts sound convincing. Watch for:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Fake DoorDash refund messages
  • Texts about a delivery problem
  • Calls claiming to be DoorDash support
  • Requests for a one-time login or verification code
  • Requests to confirm a card or bank account
  • Counterfeit DoorDash login pages
  • Attachments or links related to the breach

DoorDash specifically advises caution with unsolicited communications, suspicious links, and attachments. A real-looking message is not proof of authenticity. Open the app yourself and use official support channels.

Is a suspicious DoorDash charge proof of the breach?

No. A fraudulent DoorDash charge can result from a stolen card used elsewhere, a reused password, a compromised email account, a device or merchant problem, a payment-processor issue, or an unrelated breach.

Report the charge to your card issuer and DoorDash through official channels, but do not attribute it to the 2025 incident without evidence linking the events.

What remains unknown

  • The total number of affected individuals
  • Whether DoorDash’s employee-social-engineering and vendor-phishing notices describe one event or overlapping events
  • Whether any misuse occurred beyond DoorDash’s statement that it had no indication of fraud or identity theft at the time of its notices

That uncertainty does not eliminate the practical risk: exposed contact and delivery information can support more convincing phishing and account-takeover attempts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Official resources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.