Skip to content
NetarxImpact Database
Vendor / Supply Chain ImpersonationNo AI reportedConfirmed

DoorDash customer data exposed through phished third-party vendor employees

DoorDash · Transportation & Logistics · United States · August 25, 2022

What happened

DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.

How the deception worked

The attackers ran their SMS credential-harvesting kit against staff at a vendor that DoorDash used, capturing sign-in details for the vendor's systems. Because the vendor held delegated access to DoorDash's internal tools, those stolen credentials translated directly into access to DoorDash customer records. The intruder queried and exported profile and order data before the activity was detected. DoorDash disabled the vendor's access, brought in outside forensics and notified affected users. The pattern illustrates how a single phishing kit run against one supplier cascades into named-brand consumer breaches downstream.

AI involvement · No AI reported

No AI element reported.

The control that would have caught it· our reading, not a claim from the sources

Vendor access should be least-privilege, time-bound and separately monitored, and third parties handling customer data should be contractually required to use phishing-resistant MFA.

Sources (3)

  1. DoorDash hit by data breach linked to Twilio hackers
    TechCrunch·techcrunch.comOpen ↗
  2. DoorDash discloses new data breach tied to Twilio hackers
    BleepingComputer·bleepingcomputer.comOpen ↗
  3. DoorDash Discloses Data Breach Related to Attack That Hit Twilio, Others
    SecurityWeek·securityweek.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.