If you've ever had an account or relationship with DoorDash, it's worth checking whether your personal data was exposed in this incident. Here's what happened, what data was involved, and what to do about it.
What Happened
DoorDash disclosed in September 2019 that it had discovered unusual activity involving a third party gaining unauthorized access to its systems. The unauthorized access reportedly occurred on 4 May 2019, affecting approximately 4.9 million consumers, delivery workers (Dashers), and merchants who had joined the platform on or before 5 April 2019.
What Data Was Exposed
The exposed data included names, email addresses, delivery addresses, phone numbers, and hashed passwords for consumers. For a subset of Dashers, the last four digits of their bank account numbers were exposed, and for a smaller subset, the last four digits of their Social Security numbers. For some consumers, the last four digits of payment card numbers were also exposed.
Why This Still Matters
Exposed data doesn't expire. It's sold, traded, and reused for years, fueling credential stuffing attacks — automated attempts to reuse your email and password combination across other sites. If you reused a password anywhere, one old exposure can compromise several current accounts.
How to Check If You Were Affected
Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.
What to Do If You Were Affected
- Change any reused password immediately, starting with your most sensitive accounts.
- Enable two-factor authentication wherever it's offered.
- Monitor financial and health accounts closely if that kind of data was involved.
- Watch for phishing — exposed data is often used to craft convincing scam messages.
- Freeze your credit if your SSN or government ID number was exposed.
👉 Check your own exposure in 30 seconds → scan your email free.
Frequently Asked Questions
When did the DoorDash data breach happen?
The unauthorized access reportedly occurred on 4 May 2019. DoorDash discovered and disclosed the breach in September 2019, affecting users who joined on or before 5 April 2019.
What data was stolen in the DoorDash breach?
Names, emails, delivery addresses, phone numbers, and hashed passwords were exposed for consumers. Some Dashers had the last four digits of bank account numbers and, for a smaller group, SSNs exposed. Some consumers had the last four digits of payment cards exposed.
Were full payment card or bank account numbers exposed in the DoorDash breach?
No. DoorDash stated that only the last four digits of bank accounts and payment cards were exposed for affected users, not full account or card numbers.
How do I check if I was affected by the DoorDash breach?
DoorDash notified affected users directly. You can also check your email at Scan My Shadow, and if you were a Dasher with SSN digits exposed, consider monitoring your credit.
What did DoorDash do after the breach?
DoorDash stated it enhanced its security measures, engaged outside security experts to investigate, and reported the incident to law enforcement.