Massive DoorDash hack exposes millions of customers' personal data

Whoops.
By Jack Morse  on 
Massive DoorDash hack exposes millions of customers' personal data
Refund, please. Credit: Tibrina Hobson / getty

All they wanted was a quick delivery.

Instead, millions of DoorDash customers now find themselves the victims of a massive hack that exposed personal details such as delivery addresses, emails, and more. Oh, and it's not just those who ordered food on the receiving end of this security nightmare. Those using the platform to deliver food, known as "Dashers," as well as some merchants, also had their data accessed by hackers.

DoorDash says that 4.9 million merchants, dashers, and customers were affected by the breach. Specifically, those who began using the service before April 5 of 2018. If you joined after, you're allegedly in the clear.

DoorDash announced the breach in a Thursday press release, taking pains to insist that it "[takes] the security of our community very seriously."

When a company opens a press release with that sentence, you know you're truly screwed.

"We deeply regret the frustration and inconvenience that this may cause you," insists the company.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

The company says it discovered the breach earlier this month, and determined that an "unauthorized third party" got access to DoorDash data on May 4 of this year.

According to DoorDash, that data includes "names, email addresses, delivery addresses, order history, phone numbers, as well as hashed, salted passwords."

But wait, that's not all that was accessed.

"For some consumers, the last four digits of consumer payment cards," explained the company in the aforementioned press release. "For some Dashers and merchants, the last four digits of their bank account number."

Approximately 100,000 Dashers also had their drivers license numbers "accessed."

So, how do you know if you're one of the unlucky ones? DoorDash says it's notifying those affected by the hack "over the coming days." It also encourages all those concerned to change their password to something unique to DoorDash.

You could also, of course, delete your DoorDash account. But that's just a little bonus tip because the damage is already done.

Topics Cybersecurity

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.


Recommended For You



TikTok for Business: Everything you need to know
TikTok for Business


Trending on Mashable
NYT Connections today: See hints and answers for April 25
A phone displaying the New York Times game 'Connections.'

Wordle today: Here's the answer and hints for April 25
a phone displaying Wordle

NYT's The Mini crossword answers for April 25
Closeup view of crossword puzzle clues

NYT Connections today: See hints and answers for April 24
A phone displaying the New York Times game 'Connections.'

The 12-foot Home Depot skeleton's new pet dog sold out in less than an hour
decorations from home depot's 2024 halloween collection
The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!