DoorDash
Disclosed Aug 25, 20224 years ago367,476 accountsUnverified
Hackers linked to Twilio breach use vendor credentials to access DoorDash data
DoorDash said attackers used credentials stolen from employees of a third-party vendor to access internal tools, exposing customer names, emails, delivery addresses and phone numbers, plus partial card data for a smaller subset. It did not say how many users were affected.
What is known
| People affected | 367,476 (accounts in the leaked data, per Have I Been Pwned) |
|---|---|
| Disclosed | Aug 25, 2022 |
| Happened | Aug 2, 2022 |
| Attack | Vendor breach |
| Data exposed | Emails, Location, Names, Payment cards, Addresses, Phone numbers |
| Sector | Retail · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| Have I Been Pwned: DoorDashhaveibeenpwned.com · Aggregator | Aggregator |
| DoorDash hit by data breach linked to Twilio hackerstechcrunch.com · News | News |
| The badly handled data breaches of 2022techcrunch.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Aug 25, 2022 | |
| Have I Been Pwnedaccounts in the data | Jan 7, 2023 | 367,476 |
Other breaches at DoorDash
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Social engineering breach exposes DoorDash users' contact detailsNov 13, 202510 months agoPhishingUnverified | Nov 13, 202510 months ago | Phishing | Retail | Unverified | Unknown |
| Disclosed Sep 26, 2019Sep 26, 20197 years agoHacking | Sep 26, 20197 years ago | Hacking | Tech | Confirmed | 100K |
History of this record
- 2026-09-25 · source_type: aggregator to press · seed source
- 2026-09-25 · source_url: https://haveibeenpwned.com/Breach/DoorDash to https://techcrunch.com/2022/08/25/doordash-customer-data-breach-twilio/ · seed source
- 2026-09-25 · country: empty to US · seed source
- 2026-09-25 · sector: tech to retail · seed source
- 2026-09-25 · data_types: ["emails","location","names","payment-card"] to ["emails","location","names","payment-card","addresses","phone"] · seed source
- 2026-09-25 · disclosed: 2023-01-07 to 2022-08-25 · seed source
- 2026-09-25 · summary: In August 2022, the food ordering and delivery service DoorDash disclosed a data breach that impacted a portion of their customers . DoorDash attributed the breach to an unnamed "third-party vendor" they stated was the victim of a phishing to DoorDash said attackers used credentials stolen from employees of a third-party vendor to access internal tools, exposing customer names, emails, delivery addresses and phone numbers, plus partial card data for a smaller subset. It did not · seed source
- 2026-09-25 · title: empty to Hackers linked to Twilio breach use vendor credentials to access DoorDash data · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.