LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › DoorDash Data Breach (2022)

CRITICAL severityConfirmedHow we verify

DoorDash Data Breach (2022): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 2, 2022

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

DoorDash Data Breach (2022)

Reported August 2, 2022. Approximately 367K people affected.

CRITICAL
Severity
367K
People affected
4
Data types exposed
August 2, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The DoorDash Data Breach (2022) (reported August 2, 2022) exposed Email addresses, Geographic locations, Names and Partial credit card data belonging to roughly 367K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Exposes financial data.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the DoorDash Data Breach (2022) breach?
367K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In August 2022, DoorDash disclosed that a data breach had affected a portion of its customers, exposing personal details tied to roughly 367,000 people. For anyone who ordered food through the service around that time, the practical question is straightforward: whether an email address, name, location information, or fragments of payment-card data linked to their account may now sit outside the company’s control.

Public reporting ties the incident to a third-party vendor rather than a direct intrusion into DoorDash systems, and the company stated the vendor had been targeted in a phishing campaign. Exact technical pathways beyond that attribution remain limited in the public record, yet the named data types are concrete enough that affected customers have clear reasons to review their accounts and monitor for misuse.

Breaking down the breach

DoorDash, the food ordering and delivery service, reported the incident on August 02, 2022. According to the company’s disclosure, the breach impacted a portion of its customers and was attributed to an unnamed third-party vendor that DoorDash stated had been the victim of a phishing campaign. The company reported that 367,000 unique personal email addresses were exposed, together with names, post codes, and partial card data—specifically the brand, expiry date, and last four digits of the card.

No further public detail in the available record identifies the vendor by name, the precise duration of unauthorized access, or the full technical method beyond the phishing attribution. Scale is given as 367,000 people affected. Geographic locations are among the data types named as exposed, consistent with the post-code information described in the summary. No dollar amounts, internal file names, or additional counts beyond the 367,000 figure appear in the disclosed facts.

How a breach like this happens

Incidents that begin with a third-party vendor and a phishing campaign typically follow a familiar pattern, described here only as general background and not as a reconstruction of this specific event. Phishing involves messages designed to look legitimate—often emails or related communications—that prompt an employee or contractor to enter credentials, open a malicious attachment, or approve access. Once an attacker obtains usable login details or a foothold inside the vendor’s environment, they may reach customer data that the vendor processes or stores on behalf of a larger company.

Organizations that rely on external providers for support functions, analytics, payments-related services, or customer communications create additional pathways where data can be concentrated. When those pathways are compromised, the downstream company may learn of the exposure only after the vendor detects or reports it. Public detail on timing, dwell time, or exact systems touched is often limited in such cases, and no specific threat group is attributed in the facts of this incident.

Who is DoorDash?

DoorDash is a well-known food ordering and delivery platform that connects customers with restaurants and couriers. Companies in this sector routinely hold account identifiers, contact details, delivery addresses or related location data, order histories, and payment-related information needed to complete transactions. That combination makes a breach consequential: the same data that makes convenient delivery possible can, if exposed, help criminals craft convincing fraud attempts or attempt account takeover elsewhere.

Because delivery services sit between consumers, merchants, and payment flows, even a partial exposure of customer records can affect trust and create follow-on work for both the company and the people whose information appears in the incident. The 2022 disclosure concerned a portion of customers rather than a claim of company-wide compromise, yet the volume reported—hundreds of thousands of unique email addresses—still places a large number of individuals in the position of needing to assess personal risk.

The information in question

The facts name the exposed data types as email addresses, geographic locations, names, and partial credit card data. The reported summary further specifies 367,000 unique personal email addresses alongside names, post codes, and partial card data consisting of the brand, expiry date, and last four digits of the card. Full card numbers are not described as exposed in the available record.

Organizations of this kind typically also hold phone numbers, full delivery addresses, order details, and richer payment tokens or authentication data; whether any of those additional categories were involved here is unconfirmed. Readers should treat only the named categories as established by the disclosure and regard other possibilities as outside the public facts.

What's at stake

For affected individuals, the combination of name, email, location-related data, and partial card details creates several concrete risks without requiring dramatic scenarios:

For DoorDash, the stakes include regulatory and contractual obligations around vendor oversight, the cost of investigation and customer notification, and longer-term reputational pressure common to consumer platforms that handle payment-adjacent data. None of these outcomes depends on proving negligence; they follow from the simple fact that personal and payment-related information left the expected control boundary.

Were you affected?

If you used DoorDash before or around the August 2022 disclosure, treat the possibility of inclusion seriously even if you received no direct notice. Change your DoorDash password and enable multi-factor authentication if available. Monitor bank and card statements for unfamiliar charges, and consider asking your issuer about alerts or a replacement card if you are uneasy about the partial card data described. Be skeptical of unsolicited messages that cite delivery details, post codes, or card fragments.

Where the same email address appears on other services, avoid password reuse and review those accounts for unexpected login activity. You can also run a free exposure scan of your email to check whether your information has surfaced in known breach data, which may help you decide how widely to rotate credentials and heighten monitoring. Public detail on this incident remains bounded by what DoorDash reported; staying practical about the named data types is the most reliable response.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyDoorDash security record
74/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See DoorDash’s full breach history →

More recent breaches

RailYatri Data Breach (2022)December 26, 2022Gemini Data Breach (2022)December 13, 2022SevenRooms Data Breach (2022)December 11, 2022Activision Data Breach (2022)December 4, 2022

Latest breaches

Read GalaxyWarden’s full analysis of the DoorDash Data Breach (2022) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram