Skip to content

DoorDash

Disclosed Aug 25, 20224 years ago367,476 accountsUnverified

Hackers linked to Twilio breach use vendor credentials to access DoorDash data

DoorDash said attackers used credentials stolen from employees of a third-party vendor to access internal tools, exposing customer names, emails, delivery addresses and phone numbers, plus partial card data for a smaller subset. It did not say how many users were affected.

What is known

People affected367,476 (accounts in the leaked data, per Have I Been Pwned)
DisclosedAug 25, 2022
HappenedAug 2, 2022
AttackVendor breach
Data exposedEmails, Location, Names, Payment cards, Addresses, Phone numbers
SectorRetail · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: DoorDashhaveibeenpwned.com · Aggregator
DoorDash hit by data breach linked to Twilio hackerstechcrunch.com · News
The badly handled data breaches of 2022techcrunch.com · News

Notices filed

WhereFiledPeople
ResearchtotalAug 25, 2022
Have I Been Pwnedaccounts in the dataJan 7, 2023367,476

Other breaches at DoorDash

BreachAffected
Social engineering breach exposes DoorDash users' contact detailsNov 13, 202510 months agoPhishingUnverifiedUnknown
Disclosed Sep 26, 2019Sep 26, 20197 years agoHacking100K
History of this record
  • 2026-09-25 · source_type: aggregator to press · seed source
  • 2026-09-25 · source_url: https://haveibeenpwned.com/Breach/DoorDash to https://techcrunch.com/2022/08/25/doordash-customer-data-breach-twilio/ · seed source
  • 2026-09-25 · country: empty to US · seed source
  • 2026-09-25 · sector: tech to retail · seed source
  • 2026-09-25 · data_types: ["emails","location","names","payment-card"] to ["emails","location","names","payment-card","addresses","phone"] · seed source
  • 2026-09-25 · disclosed: 2023-01-07 to 2022-08-25 · seed source
  • 2026-09-25 · summary: In August 2022, the food ordering and delivery service DoorDash disclosed a data breach that impacted a portion of their customers . DoorDash attributed the breach to an unnamed "third-party vendor" they stated was the victim of a phishing to DoorDash said attackers used credentials stolen from employees of a third-party vendor to access internal tools, exposing customer names, emails, delivery addresses and phone numbers, plus partial card data for a smaller subset. It did not · seed source
  • 2026-09-25 · title: empty to Hackers linked to Twilio breach use vendor credentials to access DoorDash data · seed source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.

Everything about DoorDash

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.