DoorDash Confirms Massive Data Breach Affecting Nearly 5 Million Users

DoorDash reveals that hackers stole the personal information of 4.9 million customers, workers, and merchants through a third-party service provider. The company faces questions over a five-month detection delay and previous unexplained account compromises.

DoorDash confirms that a massive data breach exposes the personal information of 4.9 million customers, delivery workers, and merchants. The incident occurs on May 4 through a third-party service provider, but the company takes almost five months to detect the intrusion. Customers who join the platform after April 5, 2018 remain unaffected by this security incident.

Impacted users have their names, email and delivery addresses, phone numbers, order histories, and hashed passwords stolen. The breach also exposes the last four digits of payment cards for consumers and bank account numbers for workers and merchants. Additionally, around 100,000 delivery workers have their driver’s license information compromised in the attack.

This announcement arrives exactly one year after customers complain about their accounts being hacked, a situation DoorDash previously denies by blaming credential stuffing attacks. Many affected users at the time claim their passwords are unique to DoorDash, which contradicts the company's explanation. The delayed disclosure of this breach now raises renewed concerns about the platform's overall security practices.

Read More at the original source →