What happened
DoorDash disclosed in August 2022 that an unauthorised party had accessed customer and delivery-worker data after compromising employees of a third-party vendor through the same phishing campaign that breached Twilio. Exposed data included names, email addresses, delivery addresses and order history for consumers, and names plus partial payment card numbers for some records, with phone numbers and email addresses for Dashers.
How the deception worked
The attackers ran their SMS credential-harvesting kit against staff at a vendor that DoorDash used, capturing sign-in details for the vendor's systems. Because the vendor held delegated access to DoorDash's internal tools, those stolen credentials translated directly into access to DoorDash customer records. The intruder queried and exported profile and order data before the activity was detected. DoorDash disabled the vendor's access, brought in outside forensics and notified affected users. The pattern illustrates how a single phishing kit run against one supplier cascades into named-brand consumer breaches downstream.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
Vendor access should be least-privilege, time-bound and separately monitored, and third parties handling customer data should be contractually required to use phishing-resistant MFA.
Sources (3)
- DoorDash hit by data breach linked to Twilio hackersTechCrunch·techcrunch.comOpen ↗
- DoorDash discloses new data breach tied to Twilio hackersBleepingComputer·bleepingcomputer.comOpen ↗
- DoorDash Discloses Data Breach Related to Attack That Hit Twilio, OthersSecurityWeek·securityweek.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.