HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSHighContained
DOORDASH, INC.
bd_aef90a7ba6bb5be5 · schema v1 · pii pii-v1
Full breach record for DOORDASH, INC. →DoorDash, Inc. reported a data breach involving a third-party service provider. Unauthorized access occurred on May 4, 2019, affecting user, merchant, and Dasher account information. Data accessed included names, email addresses, phone numbers, hashed/salted passwords, and in some cases, driver's license numbers and the last four digits of bank/payment card numbers. Approximately 41,740 California residents were notified. DoorDash engaged outside security experts, blocked access, and offered one year of credit monitoring via ID Experts.
California clockDiscovered Sep 5, 2019 → Notified Sep 26, 201921d ✓ CA 60-day OK22 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_51f538b02aa638c6Montana State AGfiled 2019-09-26(1d gap)Candidate
- bd_9c1afd7d0ba18682Washington State AGfiled 2019-09-26(1d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-150916
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 27, 2019
- Raw hash
- de45a4d273ba01e579d1702bd3fdcbec44d29cb1ead1a6ec71525dea3dbd1c92
Reporting entity
- Name
- DOORDASH, INC.norm: doordash
- Domain
- doordash.com
Victim entity
- Name
- DOORDASH, INC.norm: doordash
- Domain
- doordash.com
Incident
- Discovered
- Sep 5, 2019
- Materiality determined
- —
- Notification sent
- Sep 26, 2019
- Affected individuals
- 41,740
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 21d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 5, 2019→ Notified: Sep 26, 201921d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.