Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
DoorDash

DoorDash Vendor Cyber Rating & Cyber Score

careersatdoordash.com

At DoorDash, our mission to empower local economies shapes how our team members move quickly and always learn and reiterate to support merchants, Dashers and the communities we serve. We are a technology and logistics company that started with door-to-door delivery, and we are looking for team members who can help us go from a company that is known for delivering food to a company that people turn to for any and all goods. DoorDash is growing rapidly and changing constantly, which gives our team members the opportunity to share their unique perspectives, solve new challenges, and own their careers. Our leaders seek the truth and welcome big, hairy, audacious questions. We are grounded in our company values, and we make intentional


DoorDash A.I CyberSecurity Scoring

DoorDash
Company Information
Website:https://careersatdoordash.com/
Employees number:76,630
Number of followers:1,438,241
NAICS:5112
Industry Type:Software Development
Homepage:careersatdoordash.com
DoorDash Risk Score (AI oriented)
Between 600 and 649
logo
DoorDashSoftware Development
Updated:
11/06/2026
609/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
DoorDash Global Score (TPRM)
xxxx
logo
DoorDashSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

DoorDash
DoorDashPoor
Current Score
609Caa (POOR)
01000
10 incidents
-41.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
609Before Incident
MAY 2026
611Before Incident
APRIL 2026
611Before Incident
MARCH 2026
647Before Incident
Breach
05 Mar 2026DoorDash
DoorDash, Walmart, Woflow and Uber: ShinyHunters Claims Woflow Breach: What It Means for SaaS Supply Chain Security

ShinyHunters Allegedly Breaches Woflow, Highlighting Growing SaaS Supply Chain Risks

608After Incident
CRITICAL-39
WOFAUBWALDOO1772749980
ShinyHunters Allegedly Breaches Woflow, Highlighting Growing SaaS Supply Chain Risks The threat group ShinyHunters (tracked as UNC6040) has claimed responsibility for breaching Woflow, a third-party SaaS provider with reported customers including Uber, DoorDash, and Walmart. The attackers allege they exfiltrated hundreds of millions of records, though no public data sample has been released as of March 14, 2026, and Woflow has not issued a public response. This incident underscores a broader shift in SaaS attacks, where threat actors increasingly target integration-heavy vendors to gain downstream access to multiple enterprises. Rather than breaching organizations individually, attackers exploit OAuth tokens, API connections, and non-human identities to move laterally across interconnected SaaS ecosystems. Similar tactics were observed in previous breaches, such as the Salesloft/Drift and Salesforce attacks, reflecting a structural evolution in SaaS-focused cybercrime. ShinyHunters has refined a financially motivated playbook, leveraging trusted third-party integrations to compromise data at scale before publicly naming victims. In extortion-driven campaigns, attackers often provide proof of compromise directly to victims before releasing data, with delays potentially indicating ongoing negotiations. The group has previously set deadlines for data leaks, mirroring its 2025 Salesforce breach tactics claiming the breach, issuing ultimatums, and releasing data in waves to pressure targets. The attack surface for SaaS supply chain threats has expanded due to widespread reliance on OAuth permissions, API tokens, and service accounts. These integrations often operate with elevated privileges, creating persistent vulnerabilities. Over-permissioned OAuth scopes, long-lived tokens, and inherited permissions from privileged users further exacerbate risks, as traditional security controls like MFA and SSE solutions fail to address application-layer threats. A key challenge is the visibility gap in SaaS security. Many organizations assume sanctioned applications are secure after initial compliance audits, but dynamic SaaS environments where configurations, integrations, and permissions frequently change require continuous monitoring. Research indicates that 89% of compromised organizations believed they had adequate visibility at the time of an incident, highlighting the limitations of periodic audits. Integration-rich vendors are prime targets because a single compromise can provide access to multiple downstream enterprises. These vendors often aggregate sensitive data, maintain API access across tenants, and operate standardized integration models, making them efficient vectors for large-scale attacks. ShinyHunters has claimed over 1.5 billion records across hundreds of companies in past campaigns, demonstrating the financial incentive behind this approach. To mitigate such risks, security strategies must prioritize continuous SaaS posture management, strict governance of third-party OAuth permissions, and least-privilege enforcement for non-human identities. Short token lifetimes, rapid revocation mechanisms, and behavioral monitoring for anomalous activity are critical to detecting and preventing API-level breaches. As SaaS ecosystems grow more complex, organizations must shift from static compliance checks to operational, identity-centric security practices to address evolving supply chain threats.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain
IMPACT
Data Compromised: Hundreds of millions of records allegedly exfiltratedSystems Affected: SaaS supply chain integrations
DATA BREACH
Number Of Records Exposed: Hundreds of millions
FEBRUARY 2026
652Before Incident
JANUARY 2026
652Before Incident
DECEMBER 2025
649Before Incident
NOVEMBER 2025
696Before Incident
Breach
17 Nov 2025DoorDash
DoorDash

DoorDash Data Breach Affecting 4.9 Million Users

647After Incident
CRITICAL-49
DOO5993759111725
DoorDash experienced a data breach affecting 4.9 million customers, drivers (Dashers), and merchants after an attacker exploited credentials from a third-party vendor to gain unauthorized access. Exposed data included names, email addresses, phone numbers, delivery addresses, order history hashes, and the last four digits of payment cards for Dashers. While no full financial details, SSNs, or government IDs were compromised, the leaked contact information heightens risks of targeted phishing, smishing (SMS scams), and vishing (voice fraud), with attackers potentially impersonating DoorDash support or merchants. The breach originated from social engineering, tricking an employee into divulging access credentials. DoorDash blocked the intrusion, engaged law enforcement, and began notifying affected users, though no direct fraud or identity theft has been confirmed yet. The incident underscores vulnerabilities in supply chain attacks and the persistent threat of human manipulation in breaches.
INCIDENT DETAILS -
TYPE
Data BreachSupply Chain AttackSocial Engineering
MOTIVATION
Data TheftPotential Fraud Enablement
IMPACT
NamesEmail AddressesPhone NumbersPhysical AddressesOrder History HashesLast Four Digits of Payment Cards (Dashers only)Operational Impact: Increased risk of phishing/smishing/vishing attacks; reputational harm; customer notification effortsCustomer Complaints: Expected increase due to phishing risksBrand Reputation Impact: Moderate (trust erosion, media coverage)Identity Theft Risk: Low (no SSNs, full payment cards, or government IDs exposed)Payment Information Risk: Low (only last four digits of payment cards for Dashers)
DATA BREACH
Personal Identifiable Information (PII)Contact InformationPartial Payment DataNumber Of Records Exposed: 4.9 millionSensitivity Of Data: Moderate (no full financial or government ID data)NamesEmail AddressesPhone NumbersPhysical Addresses
OCTOBER 2025
732Before Incident
Breach
25 Oct 2025DoorDash
DoorDash

DoorDash Social Engineering Data Breach (2025)

695After Incident
CRITICAL-37
DOO4104241112725
In November 2025, DoorDash confirmed a data breach resulting from a social engineering attack targeting an employee. The attacker successfully manipulated the employee into divulging legitimate credentials, granting unauthorized access to internal systems. While DoorDash detected and contained the intrusion on October 25, the attackers had already exfiltrated personal contact information of customers, Dashers, and merchants—including names, physical addresses, email addresses, and phone numbers. Although no highly sensitive data (e.g., Social Security numbers, driver’s licenses, or payment card details) was compromised, the stolen information poses a significant risk for follow-on attacks such as spear phishing and vishing. The breach underscores the vulnerability of human elements in cybersecurity, emphasizing the need for AI-driven threat detection to mitigate dwell time and prevent data theft from compromised identities.
INCIDENT DETAILS -
TYPE
Data BreachSocial EngineeringCredential Compromise
MOTIVATION
Data Theft for Follow-on Attacks (e.g., Spear Phishing, Vishing)Potential Financial Gain via Stolen Data
IMPACT
NamesPhysical AddressesEmail AddressesPhone NumbersOperational Impact: Potential Increased Risk of Follow-on Attacks (Spear Phishing/Vishing)Brand Reputation Impact: High (High-Visibility Breach Undermining Trust in Security Posture)Identity Theft Risk: Moderate (Exposed PII Could Enable Targeted Scams)Payment Information Risk: None (Confirmed Not Accessed)
DATA BREACH
Personal Identifiable Information (PII)Sensitivity Of Data: Moderate (No Financial/Payment Data or Government IDs)NamesPhysical AddressesEmail AddressesPhone Numbers
SEPTEMBER 2025
730Before Incident
AUGUST 2025
729Before Incident
JULY 2025
727Before Incident
MAY 2025
758Before Incident
Breach
01 May 2025DoorDash
DoorDash

DoorDash Employee Falls Victim to Social Engineering Scam, Exposing Customer Data

721After Incident
CRITICAL-37
DOO4293042111925
A DoorDash employee was targeted in a social engineering scam, leading to unauthorized access to some customer data. While the breach exposed personal information, officials confirmed that no ID numbers (e.g., Social Security numbers) or payment details were compromised. The incident highlights vulnerabilities in employee training and susceptibility to phishing or manipulation tactics, which allowed threat actors to bypass security measures. The exposed data may include names, email addresses, or delivery-related information, but the lack of financial or highly sensitive identifiers reduces the immediate risk of identity theft or fraud. However, the breach still poses reputational harm and potential follow-on attacks, such as targeted phishing campaigns against affected customers. DoorDash has not disclosed the exact number of impacted users, but the incident underscores the ongoing risks of human error in cybersecurity defenses.
INCIDENT DETAILS -
TYPE
Data Breach (Social Engineering)
IMPACT
Customer Personal Information (Non-Sensitive)Brand Reputation Impact: Potential Negative Impact (Public Disclosure of Breach)Identity Theft Risk: Low (No ID Numbers or Payment Information Compromised)Payment Information Risk: None (Officials Confirmed No Payment Information Exposed)
DATA BREACH
Personal Information (Non-Sensitive)Sensitivity Of Data: Low (No ID Numbers or Payment Information)Data Exfiltration: Yes (Some Customer Data Accessed)Personally Identifiable Information: Partial (Excluding ID Numbers and Payment Information)
JULY 2023
725Before Incident
Vulnerability
01 Jul 2023DoorDash
DoorDash

DoorDash Email Spoofing Vulnerability Enabling Phishing Campaigns

722After Incident
MEDIUM-3
DOO2492524111725
A vulnerability in DoorDash’s systems allowed threat actors to exploit an unpatched flaw in the DoorDash for Business platform, enabling them to send fully branded, official-looking emails from [email protected] by injecting arbitrary HTML into the 'Budget name' input field. This created a highly convincing phishing channel, as emails bypassed spam filters and appeared legitimate. The flaw, reported by a researcher in July 2023, remained unpatched for over 15 months due to disputes over disclosure ethics and financial demands. While no direct data breach or internal system access occurred, the vulnerability posed a significant reputational and financial risk by facilitating large-scale phishing attacks targeting customers, merchants, or arbitrary recipients. The company eventually patched the issue in November 2024 after public pressure, but the researcher was banned from DoorDash’s bug bounty program amid accusations of extortion. The incident highlights tensions between responsible disclosure and corporate response protocols in cybersecurity.
INCIDENT DETAILS -
TYPE
Email SpoofingHTML InjectionPhishing Vector
MOTIVATION
Potential Financial Gain (Extortion Attempt by Researcher)Phishing/Scam Campaigns (Hypothetical Threat Actors)Reputation Damage (Disclosure Dispute)
IMPACT
Data Compromised: NoneDoorDash for Business PlatformEmail Servers ([email protected])Risk of Phishing Attacks Targeting Customers/Merchants/General PublicDispute Over Vulnerability Disclosure ProcessNegative Publicity Due to Disclosure DisputePerception of Weak Security PracticesComparison to Uber's 2022 Email Spoofing FlawIdentity Theft Risk: Low (Required User Interaction via Phishing)Payment Information Risk: Low (Required User Interaction via Phishing)
DATA BREACH
Type Of Data Compromised: NoneNumber Of Records Exposed: 0Sensitivity Of Data: NoneData Exfiltration: NoPersonally Identifiable Information: None
AUGUST 2022
738Before Incident
Breach
01 Aug 2022DoorDash
DoorDash

DoorDash Data Breach

701After Incident
CRITICAL-37
DOO0162922
Food delivery firm DoorDash suffered a data breach exposing customer and employee data that was compromised in a cyberattack on Twilio. The threat actor gained access to the company's internal tools using stolen credentials from a third-party vendor that had access to their systems. As a response, they disabled the vendor's access to their system and contained the incident. The exposed information included the names, email addresses, delivery addresses, and phone numbers of consumers. In addition, for a small subset of customers, the hackers accessed basic order information and partial credit card information, including the card type and the last four digits of the card number.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesemail addressesdelivery addressesphone numbersbasic order informationpartial credit card information
DATA BREACH
namesemail addressesdelivery addressesphone numbersbasic order informationpartial credit card informationnamesemail addressesdelivery addressesphone numbers
SEPTEMBER 2019
705Before Incident
Breach
01 Sep 2019DoorDash
DoorDash

DoorDash Data Breach

656After Incident
CRITICAL-49
DOO15123922
DoorDash suffered a data breach after an unauthorized user gained access to the personal information of 4.9 million consumers, Dashers, and merchants. The exposed information included email addresses, delivery addresses, order history, phone numbers, and hashed and salted passwords, last four digits of their credit cards or bank accounts consumers, dashers, and merchants. The company notified all the affected individuals through the mail.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Email AddressesDelivery AddressesOrder HistoryPhone NumbersHashed and Salted PasswordsLast Four Digits of Credit CardsLast Four Digits of Bank Accounts
DATA BREACH
Email AddressesDelivery AddressesOrder HistoryPhone NumbersHashed and Salted PasswordsLast Four Digits of Credit CardsLast Four Digits of Bank Accounts
JUNE 2019
751Before Incident
Breach
16 Jun 2019DoorDash
DoorDash

DoorDash Data Breach via Social Engineering Attack (October 2025)

699After Incident
CRITICAL-52
DOO5203452112125
In October 2025, DoorDash suffered a sophisticated social engineering attack where an unauthorized third party tricked an employee into granting access to internal systems. The breach compromised personal information—including names, email addresses, phone numbers, and physical addresses—of an unspecified number of customers, delivery workers (Dashers), and merchants. While DoorDash claimed no 'sensitive' data (e.g., credit cards, SSNs, passwords) was exposed, the leaked details pose risks for phishing, identity theft, and targeted scams. The incident mirrors past breaches (2019: 5M users; 2022: driver license numbers), highlighting persistent vulnerabilities in employee training and third-party risk management. The company offered free credit monitoring but faced criticism for reactive measures. The breach underscores systemic gaps in the gig economy’s cybersecurity, with potential reputational damage, regulatory scrutiny, and heightened risks for affected users (e.g., Dashers’ physical safety).
INCIDENT DETAILS -
TYPE
Data BreachSocial EngineeringPhishing
MOTIVATION
Data TheftPotential Financial Gain (via phishing/identity theft)Targeted Scams
IMPACT
NamesEmail addressesPhone numbersPhysical addressesInternal systems (unspecified)Operational Impact: Notification process to affected users (mid-to-late November 2025), partnership with security firms for investigationRevenue Loss: Minor stock dip reportedBrand Reputation Impact: Negative; erosion of trust in gig economy platforms, potential regulatory scrutinyLegal Liabilities: Possible fines or mandated audits under regulations like CCPA; historical context of lawsuits from 2019 breachIdentity Theft Risk: High (exposed PII can be used for phishing, spear-phishing, or cross-referencing with other databases)Payment Information Risk: Low (DoorDash confirmed no credit card details or passwords were accessed)
DATA BREACH
Personally Identifiable Information (PII)Number Of Records Exposed: Unspecified (potentially large, given 30M+ user base)Sensitivity Of Data: Moderate (no financial data or passwords, but PII can enable phishing/identity theft)Data Exfiltration: Likely (data accessed by unauthorized party)NamesEmail addressesPhone numbersPhysical addresses
MAY 2019
793Before Incident
Breach
04 May 2019DoorDash
DoorDash, Inc.

DoorDash Data Breach

750After Incident
CRITICAL-43
DOO622072825
The California Office of the Attorney General reported on September 27, 2019, that DoorDash, Inc. experienced a data breach on May 4, 2019, involving unauthorized access to user data. Approximately 41,740 California residents were affected, with compromised information including names, email addresses, phone numbers, hashed passwords, and driver's license numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesemail addressesphone numbershashed passwordsdriver's license numbers
DATA BREACH
namesemail addressesphone numbershashed passwordsdriver's license numbersSensitivity Of Data: High
SEPTEMBER 2018
822Before Incident
Breach
01 Sep 2018DoorDash
DoorDash

DoorDash Account Hack

788After Incident
MEDIUM-34
DOO232301022
Food delivery startup DoorDash customer's accounts have been hacked. Dozens of people have tweeted that their accounts had been improperly accessed and had fraudulent food deliveries charged to their account. The hackers changed their email addresses. There has been no data breach and that the likely culprit was credential stuffing, in which hackers take lists of stolen usernames and passwords and try them on other sites that may use the same credentials.
INCIDENT DETAILS -
TYPE
Account Compromise
MOTIVATION
FraudFinancial Gain
IMPACT
Unauthorized account accessFraudulent charges

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for DoorDash ?
?
What was DoorDash's A.I Rankiteo Cyber Score in May 2026 ?
?
What was DoorDash's A.I Rankiteo Cyber Score in April 2026 ?
?
What was DoorDash's A.I Rankiteo Cyber Score in March 2026 ?
?
What was DoorDash's A.I Rankiteo Cyber Score in February 2026 ?
?
What was DoorDash's A.I Rankiteo Cyber Score in January 2026 ?
?
What was DoorDash's A.I Rankiteo Cyber Score in December 2025 ?
?
What was DoorDash's A.I Rankiteo Cyber Score in November 2025 ?
?
What was DoorDash's A.I Rankiteo Cyber Score in October 2025 ?
?
What was DoorDash's A.I Rankiteo Cyber Score in September 2025 ?
?
What was DoorDash's A.I Rankiteo Cyber Score in August 2025 ?
?
What was DoorDash's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on DoorDash's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with DoorDash ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view DoorDash's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?