DoorDash has confirmed a new data breach identified on October 25, 2025, after detecting unauthorized access to its internal systems. The company began notifying impacted users across the U.S., Canada, Australia, and New Zealand, explaining that a third party obtained certain customer, Dasher, and merchant contact details. Exposed information may include names, physical addresses, phone numbers, and email addresses. DoorDash attributes the incident to a successful social-engineering scam targeting an employee, which enabled the attacker to access user data before being blocked by the company’s incident response team. Following containment, DoorDash launched a forensic investigation and alerted law enforcement. ? This marks the third major security incident involving DoorDash, following breaches in 2019 and 2022. While the company has not disclosed the number of affected users, notifications sent to DoorDash Canada customers and an advisory mentioning U.S.-specific data types suggest the breach may span multiple regions. The incident has sparked criticism online, with users questioning the 19-day delay between detection and notification. Some recipients argued that the company’s claim of “no sensitive information was accessed” contradicts the exposure of personal contact details, noting possible violations of Canadian privacy regulations. Several impacted individuals have stated they plan to file complaints with privacy authorities or take legal action. DoorDash urges users to remain cautious of phishing attempts or unsolicited communications that appear to come from the company. The firm advises avoiding suspicious links, attachments, or requests for personal information. In response to the breach, DoorDash reports strengthening its security controls, enhancing employee training, and engaging a cybersecurity forensics firm to support its ongoing investigation.
A threat actor identified as UAC-0184 has been linked to targeted cyber espionage campaigns against Ukrainian military and government organizations. The campaign leverages phishing...
Cybersecurity researchers have identified a widespread malware campaign abusing fake Google Chrome update prompts to infect users with malicious payloads. The attack leverages comp...
Microsoft has introduced a significant security enhancement in its Edge browser after security researchers disclosed that the browser was automatically loading all saved passwords ...