DOORDASH, INC.
bd_aef90a7ba6bb5be5 · schema v1 · pii pii-v1
Full breach record for DOORDASH, INC. →DoorDash, Inc. reported that an unauthorized third party accessed user data via a third-party service provider on May 4, 2019. The company became aware of the incident on September 5, 2019. Affected data included names, email addresses, phone numbers, hashed/salted passwords, and in some cases, the last four digits of payment cards or bank accounts. For some Dashers, driver's license numbers were also accessed. Approximately 41,740 California residents were affected. DoorDash engaged outside security experts, blocked access, and enhanced security protocols. Complimentary identity theft protection was offered to affected Dashers.
J jump to incidentP pin to compareR raw source
Incident timeline
May 4, 2019
Begins
Sep 5, 2019
Discovered
Sep 27, 2019
Filed
vs. sector median
16 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- New Hampshire State AGbd_175bc3b4b6791f752019-09-27Verified
- Massachusetts State AGbd_05cc94ac4e136a232019-09-26 · +1dVerified
- Montana State AGbd_51f538b02aa638c62019-09-26 · +1dCandidate
- Washington State AGbd_9c1afd7d0ba186822019-09-26 · +1dVerified by operator
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.