DOORDASH, INC.
ent_019e45e0137683f104ec2a9381c3e724
Disclosures
4
SEC 10-K Item 1C · State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
41,740
as filed · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DOORDASH, INC.
- Normalized
- doordash— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300NUQ43FGGSK5051
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- FEDERALSEC 10-K Item 1Cas victim2024-02-20
DoorDash's Form 10-K Item 1C cybersecurity disclosure describes its enterprise information security program, governance (audit-committee oversight, CISO leadership; Wolt's VP of Security for its subsidiary), third-party risk management, and program assessments. The filing acknowledges DoorDash has been subject to past cybersecurity incidents and expects future attacks, but states that to date, risks from cybersecurity threats have not materially affected its business or operations. No specific incident details are disclosed.
- 🐻California State AGas victim2019-09-27
DoorDash, Inc. reported a data breach involving a third-party service provider. Unauthorized access occurred on May 4, 2019, affecting user, merchant, and Dasher account information. Data accessed included names, email addresses, phone numbers, hashed/salted passwords, and in some cases, driver's license numbers and the last four digits of bank/payment card numbers. Approximately 41,740 California residents were notified. DoorDash engaged outside security experts, blocked access, and offered one year of credit monitoring via ID Experts.
- 🦬Montana State AGas victim2019-09-26
DoorDash reported a data breach to the Montana Attorney General. The breach was reported on 2019-09-26. The breach occurred from 4/5/2019 to 9/5/2019. 21 Montana residents were affected.
- 🌲Washington State AGas victim2019-09-26
DoorDash Inc, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2019-09-05 and filed notice on 2019-09-26. 2,243 Washington residents were affected. 21 days elapsed between awareness and notification. 124 days to identify the breach. 0 days to contain the breach.