the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

DoorDash Hit by Data Breach Exposing User Phone Numbers and Addresses

ArticlesNewsletters
ArticlesNewsletters
Security

DoorDash Hit by Data Breach Exposing User Phone Numbers and Addresses

Delivery giant confirms breach after social engineering attack compromised customer data

by The Tech Buzz

PUBLISHED: Mon, Nov 17, 2025, 3:48 PM UTC | UPDATED: Fri, Sep 4, 2026, 7:05 AM UTC

Add as a preferred source on Google
DoorDash Hit by Data Breach Exposing User Phone Numbers and Addresses

DoorDash just confirmed a data breach that exposed phone numbers, addresses, and email data for an undisclosed number of users across its platform. The breach, stemming from a social engineering attack that fooled an employee, impacted customers, delivery workers, and merchants - though the company insists no "sensitive information" was accessed and won't say how many people were affected.

DoorDash is dealing with another cybersecurity headache after confirming hackers accessed user data including phone numbers and physical addresses. The delivery giant disclosed the breach in a security notice last week, but it's raising more questions than answers about the scope and impact.

The attack started with what security experts call a classic social engineering play - hackers convinced a DoorDash employee to hand over access to internal systems. It's the same playbook we've seen work against everyone from Uber to Twitter, where human psychology becomes the weakest link in otherwise solid defenses.

What's concerning is DoorDash's refusal to specify exactly how many users got caught up in this mess. The company only says the breach "impacted a mix of customers, delivery workers, and merchants" - which could mean thousands or millions of people. When TechCrunch pressed for specifics, DoorDash went silent.

The stolen data includes names, email addresses, phone numbers, and physical addresses. For a delivery platform, that's basically the crown jewels of customer information. Yet DoorDash maintains that "no sensitive information was accessed" - a statement that feels like corporate doublespeak when your home address is literally where food gets delivered.

Advertisement

To DoorDash's credit, they moved quickly once they spotted the intrusion. The company says it immediately cut off hackers' access, launched an internal investigation, and reported the incident to law enforcement. They're also claiming no financial data got compromised - no Social Security numbers, driver's licenses, or payment card information made it out the door.

But this isn't DoorDash's first rodeo with data breaches. The company has faced multiple security incidents over the years, including a 2019 breach that affected nearly 5 million users. Each incident chips away at user trust in an industry where personal data is everything.

The timing couldn't be worse for the food delivery sector. With Uber Eats and Grubhub all fighting for market share, security incidents become competitive disadvantages. Users might think twice about ordering if they're worried about their data getting leaked.

Social engineering attacks are becoming the go-to method for cybercriminals because they work. Instead of trying to crack complex security systems, they just trick employees into opening the door. Recent high-profile attacks on companies like Okta and LastPass followed similar patterns.

Advertisement

What makes this particularly frustrating is that social engineering is largely preventable with proper training and protocols. But even the most security-conscious companies struggle when determined attackers target the human element.

DoorDash says they've notified affected users, though it's unclear what specific steps they're taking to protect people whose addresses and phone numbers are now floating around the dark web. The company also hasn't said whether they're offering credit monitoring or other protective services.

The incident highlights a broader problem in the gig economy where platforms collect massive amounts of personal data from both customers and workers. When that data gets breached, the ripple effects touch everyone from hungry customers to drivers trying to make ends meet.

DoorDash's latest breach serves as another reminder that even major tech platforms remain vulnerable to basic social engineering tactics. While the company insists no "sensitive" data was stolen, having your phone number and address in hackers' hands feels pretty sensitive to affected users. The real test will be whether DoorDash can rebuild trust and prevent future incidents - because in the competitive food delivery market, customers have plenty of other options if they lose confidence in your security.

Advertisement

Advertisement

Trending Now

1

GoPro CEO Vows Cameras Stay Core After Starman Deal

2

Judge Splits Ruling in X vs. Twitter Rival Fight

3

Tim Cook Steps Down, Ternus Takes Apple's Helm

4

Google's Lyria 3.5 Brings AI Music to Gemini

5

Google Translate Gets Listening Mode, Live Background Mode

People Also Ask

The DoorDash breach exposed names, email addresses, phone numbers, and physical addresses of customers, delivery workers, and merchants. However, no financial data, Social Security numbers, driver's licenses, or payment card information was compromised according to the company.

Hackers used a social engineering attack to trick a DoorDash employee into providing access to internal systems. This technique involves manipulating human psychology rather than breaking through technical security measures, making employees the weakest link in cybersecurity defenses.

DoorDash has not disclosed the exact number of affected users. The company only states the breach "impacted a mix of customers, delivery workers, and merchants" but refused to provide specific numbers when pressed by media outlets like TechCrunch.

No, DoorDash has experienced multiple security incidents over the years. The company previously faced a major breach in 2019 that affected nearly 5 million users, making this the latest in a series of cybersecurity challenges for the delivery platform.

DoorDash immediately cut off hackers' access to their systems, launched an internal investigation, and reported the incident to law enforcement. The company also notified affected users, though specific protective measures or services offered haven't been detailed publicly.

Social engineering attacks work because they target human psychology rather than technical systems. Instead of breaking through complex security defenses, cybercriminals simply trick employees into providing access. Recent attacks on companies like Uber, Okta, and LastPass used similar tactics successfully.

More in Security

ClarityCheck Exposes 9M+ Facial Images in Database Breach

ClarityCheck Exposes 9M+ Facial Images in Database Breach

Apple spyware alerts hit 'unprecedented' number of users

Apple spyware alerts hit 'unprecedented' number of users

Military Apps Expose US Troops to Foreign Code From China, Russia

Military Apps Expose US Troops to Foreign Code From China, Russia

Russia Used Cellebrite Tools After Promised Cutoff

Russia Used Cellebrite Tools After Promised Cutoff

Spotify Exploited: Fake Podcasts Boost Illegal Drug Sites

Spotify Exploited: Fake Podcasts Boost Illegal Drug Sites

7-Eleven data breach affects over 185,000 people’s personal data

7-Eleven data breach affects over 185,000 people’s personal data

More Articles

These special phone and app features can help protect you from spyware

These special phone and app features can help protect you from spyware

May 23

Adobe patches PDF zero-day exploited since November

Adobe patches PDF zero-day exploited since November

Apr 14

Hack-for-hire group exposed targeting Android and iCloud users

Hack-for-hire group exposed targeting Android and iCloud users

Apr 8

Money Transfer App Duc Exposes Thousands of IDs on Open Server

Money Transfer App Duc Exposes Thousands of IDs on Open Server

Apr 2

WhatsApp Alerts 200 Users Hit by Italian Government Spyware

WhatsApp Alerts 200 Users Hit by Italian Government Spyware

Apr 1

Iranian Hackers Breach FBI Director Kash Patel's Gmail Account

Iranian Hackers Breach FBI Director Kash Patel's Gmail Account

Mar 27