DisclosureLens
HackingTechnologyRetail & ConsumerInformationStolen CredentialsCustomer Data InvolvedIdentity (basic)Government IDCredentialsMediumContained

DOORDASH, INC.

bd_51f538b02aa638c6 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 4, 2019

Filed

Sep 26, 2019

To disclose

21 weeks

Affected

21state residents only

Linked

5 filings

Confidence

66%
Full breach record for DOORDASH, INC.

DoorDash notified Montana residents that an unauthorized third party accessed user data on May 4, 2019, via a third-party service provider. Compromised data included names, driver's license numbers, emails, phone numbers, DOBs, and hashed passwords. DoorDash engaged forensic experts, enhanced security, and offered identity theft protection.

Incident timeline

discovery → filing · 21 weeks / 145 days

May 4, 2019

Begins

May 4, 2019

Discovered

Sep 26, 2019

Filed

vs. sector median

+2 wks slower

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Massachusetts State AGSep 26 · first
Washington State AGSep 26 · first
Montana State AGSep 26 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.