NATIONWIDE – DoorDash announced today, November 13, 2025, that it recently identified and contained a cybersecurity incident in which an unauthorized third party gained access to and extracted certain user information.

The company stated that the breach was the result of a social engineering scam targeting a DoorDash employee. The response team quickly shut down the unauthorized access, launched an investigation, and referred the matter to law enforcement.

Data Accessed and Affected Users

DoorDash emphasized that no sensitive information was compromised, and there is currently no indication that the accessed data has been misused for fraud or identity theft.

Data Accessed: The personal information accessed varied by individual and may have included:

First and last name

Phone number

See Full Page