{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ"},"incident":{"title":"DoorDash customer data exposed through phished third-party vendor employees","date":"2022-08-25","date_precision":"day","victim_org":"DoorDash","sector":"Transportation & Logistics","country":"United States","primary_vector":"Vendor / Supply Chain Impersonation","secondary_vectors":["Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss disclosed.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (the campaign that also hit Twilio)","summary":"DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.","how_it_worked":"The attackers ran their SMS credential-harvesting kit against staff at a vendor that DoorDash used, capturing sign-in details for the vendor's systems. Because the vendor held delegated access to DoorDash's internal tools, those stolen credentials translated directly into access to DoorDash customer records. The intruder queried and exported profile and order data before the activity was detected. DoorDash disabled the vendor's access, brought in outside forensics and notified affected users. The pattern illustrates how a single phishing kit run against one supplier cascades into named-brand consumer breaches downstream.","lessons":"Vendor access should be least-privilege, time-bound and separately monitored, and third parties handling customer data should be contractually required to use phishing-resistant MFA.","confidence":"Confirmed","sources":[{"title":"DoorDash hit by data breach linked to Twilio hackers","url":"https://techcrunch.com/2022/08/25/doordash-customer-data-breach-twilio/","publisher":"TechCrunch"},{"title":"DoorDash discloses new data breach tied to Twilio hackers","url":"https://www.bleepingcomputer.com/news/security/doordash-discloses-new-data-breach-tied-to-twilio-hackers/","publisher":"BleepingComputer"},{"title":"DoorDash Discloses Data Breach Related to Attack That Hit Twilio, Others","url":"https://www.securityweek.com/doordash-data-compromised-following-twilio-hack/","publisher":"SecurityWeek"}],"entry_type":"incident","slug":"2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-doordash-customer-data-exposed-through-phished-third-party-vendor-employ"}}