DoorDash hit by network compromise
Incident
Summary
Hide ▲
Show ▼
DoorDash disclosed a cybersecurity incident that exposed user contact information after an unauthorized third party gained access to account-linked data. The affected information may include names, physical addresses, phone numbers, and email addresses, and DoorDash says the incident was identified on October 25, 2025. The company says it shut down the unauthorized access, started an investigation, and notified law enforcement while the full scope remains under review.
Related Happenings
Chinese state-sponsored campaign to hijack Notepad++ update traffic
Campaign
H score32
First: 02.02.2026 16:53
Last: 02.02.2026 16:53
Sources 1
About this happening:
A months-long campaign hijacked Notepad++ update traffic, selectively sending some users to malicious servers and threatening the integrity of software updates. The operat...
Chinese state-sponsored campaign to hijack Notepad++ update traffic
CampaignAbout this happening: A months-long campaign hijacked Notepad++ update traffic, selectively sending some users to malicious servers and threatening the integrity of software updates. The operat...
ShinyHunters Salesforce extortion campaign against global companies in 2025
Campaign
H score84
First: 15.01.2026 17:45
Last: 15.01.2026 17:45
Sources 1
About this happening:
The ShinyHunters campaign now includes a Qantas breach disclosed after the airline found a June 30, 2025 intrusion in a third-party platform used by one customer s...
ShinyHunters Salesforce extortion campaign against global companies in 2025
CampaignAbout this happening: The ShinyHunters campaign now includes a Qantas breach disclosed after the airline found a June 30, 2025 intrusion in a third-party platform used by one customer s...
Almaviva hit by data theft breach
Incident
H score62
First: 20.11.2025 20:54
Last: 20.11.2025 20:54
Sources 1
About this happening:
The Almaviva confirmed a cyberattack on its corporate systems that resulted in the theft of some data. The breach was detected by security monitoring and isolated afte...
Almaviva hit by data theft breach
IncidentAbout this happening: The Almaviva confirmed a cyberattack on its corporate systems that resulted in the theft of some data. The breach was detected by security monitoring and isolated afte...
DoorDash Business stored HTML injection email spoofing security flaw
Vulnerability
H score26
First: 17.11.2025 18:32
Last: 17.11.2025 18:32
Sources 1
About this happening:
A DoorDash for Business stored HTML injection flaw let attackers send official-branded emails from [email protected], creating a near-perfect phishing channel. The...
DoorDash Business stored HTML injection email spoofing security flaw
VulnerabilityAbout this happening: A DoorDash for Business stored HTML injection flaw let attackers send official-branded emails from [email protected], creating a near-perfect phishing channel. The...
DoorDash user contact information leak
Data Leak
H score64
First: 14.11.2025 06:38
Last: 14.11.2025 06:38
Sources 1
About this happening:
DoorDash disclosed that user contact information was taken in an unauthorized access incident identified on October 25, 2025, creating a risk of phishing and account-f...
DoorDash user contact information leak
Data LeakAbout this happening: DoorDash disclosed that user contact information was taken in an unauthorized access incident identified on October 25, 2025, creating a risk of phishing and account-f...
Timeline
-
14.11.2025 06:38 1 articles · 8mo ago
DoorDash unauthorized access after employee social engineering
Exploitation ObservedAn unauthorized third party gained access to DoorDash user contact information after a DoorDash employee fell victim to a social engineering scam, with the compromised data varying by individual and including names, physical addresses, phone numbers, and email addresses.
Show sources
- DoorDash hit by yet another data breach this October — www.bleepingcomputer.com — 14.11.2025 06:38
-
14.11.2025 06:38 3 articles · 8mo ago
DoorDash discloses the breach and notifies impacted users
Initial DisclosureDoorDash began emailing impacted users about the cybersecurity incident, confirmed that personal information was affected, and said it had deployed additional security enhancements, added employee training, brought in a cybersecurity forensic firm, and notified law enforcement while the investigation continued.
Show sources
- DoorDash hit by yet another data breach this October — www.bleepingcomputer.com — 14.11.2025 06:38
- DoorDash hit by yet another data breach this October — www.bleepingcomputer.com — 14.11.2025 06:38
- DoorDash Confirms Data Breach Exposing Customer Personal Information — www.infosecurity-magazine.com — 18.11.2025 16:01