In mid-November 2025, DoorDash disclosed a data breach that resulted from a social engineering attack on an employee on October 25, 2025. This attack led to unauthorized access to DoorDash internal systems.
The compromised information included names, email addresses, phone numbers, and physical delivery addresses. DoorDash has not disclosed the exact number of affected individuals, but estimates suggest millions may be impacted across the United States, Canada, and other countries. DoorDash explicitly stated that no full payment card numbers, Social Security numbers, government IDs, or passwords were accessed.
More details may emerge as the situation evolves, and individuals who may have been affected should monitor for official notices from DoorDash.