DoorDash Confirms Customer Data Breach Tied to Twilio Phishing Campaign

DoorDash reveals that hackers accessed customer and driver personal information by stealing credentials from a third-party vendor linked to the recent Twilio breach.

DoorDash confirms that malicious hackers expose the personal information of its customers and delivery drivers through a compromised third-party vendor. The attackers use stolen employee credentials to access internal tools, which allows them to view names, email addresses, delivery addresses, and phone numbers. A smaller subset of affected users also has partial payment card details exposed, though the exact number of impacted individuals remains undisclosed.

The company links this security incident directly to the recent phishing campaign that compromised the messaging giant Twilio. Researchers connect both breaches to a hacking group known as "0ktapus," which successfully steals close to 10,000 employee credentials from over 130 organizations since March. DoorDash quickly cuts off the vendor's access upon detecting the suspicious activity and brings in an unnamed cybersecurity expert to assist with the ongoing investigation.

Users of Wolt, a delivery company recently acquired by DoorDash, are not affected by this specific breach. This incident marks the second major compromise for DoorDash, following a massive 2019 data breach that impacted nearly five million customers, merchants, and delivery workers. The company states that it is taking steps to further enhance its existing security systems to prevent future unauthorized access.

Read More at the original source →