DOORDASH, INC.
ent_019e45e0137683f104ec2a9381c3e724
Disclosures
5
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
41,740
as filed · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DOORDASH, INC.
- Normalized
- doordash— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300NUQ43FGGSK5051
- SEC EDGAR CIK
- 0001792789
- Domain
- None on record
Disclosure history (5)newest first
- New Hampshire State AGas victim2019-09-27
DoorDash Inc. notified the NH AG of a breach involving a third-party service provider. Unauthorized access occurred on May 4, 2019, affecting user data including names, emails, hashed passwords, and last 4 digits of payment info. Driver's license numbers were accessed for some Dashers. 86 NH residents affected. Notifications began Sept 26, 2019.
- California State AGas victim2019-09-27
DoorDash, Inc. reported that an unauthorized third party accessed user data via a third-party service provider on May 4, 2019. The company became aware of the incident on September 5, 2019. Affected data included names, email addresses, phone numbers, hashed/salted passwords, and in some cases, the last four digits of payment cards or bank accounts. For some Dashers, driver's license numbers were also accessed. Approximately 41,740 California residents were affected. DoorDash engaged outside security experts, blocked access, and enhanced security protocols. Complimentary identity theft protection was offered to affected Dashers.
- Massachusetts State AGas victim2019-09-26
DoorDash, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-09-26. 3,943 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2019-09-26
DoorDash notified Montana residents that an unauthorized third party accessed user data on May 4, 2019, via a third-party service provider. Compromised data included names, driver's license numbers, emails, phone numbers, DOBs, and hashed passwords. DoorDash engaged forensic experts, enhanced security, and offered identity theft protection.
- Washington State AGas victim2019-09-26
DoorDash Inc notified Washington AG of unauthorized access to user data via a third-party service provider. Access occurred May 4, 2019; discovered Sept 5, 2019. Data included names, emails, hashed passwords, and driver's licenses for some Dashers. 2,243 Washington residents notified. Remediation included enhanced security layers and protocols.