• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

TechEngage®

Connecting mankind with technology

  • News
  • Reviews
  • Cryptocurrency
  • How-to
  • Roundups
  • Science
    • Energy
    • Environment
    • Health
    • Space
  • Apps
  • More
    • Opinion
    • Noteworthy
    • Culture
    • Events
    • Deals
    • Startups
      • Startup Submissions
  • Videos
  • Tools
TechEngage » News » Security

DoorDash: A $4 billion dollar Food Delivery app has been hacked

Fazeel Ashraf Follow Fazeel Ashraf on Twitter Updated: January 17, 2019

Shares102FacebookTweetPinLinkedInPrintEmail

Food delivery app DoorDash have been swarmed by angry customers who claim their accounts have been hacked. These users were billed for food they never ordered. These hacks are a PR nightmare for the food delivery startup.

Several people had tweeted to DoorDash to gain their attention but to little or no avail. In many users’ cases, the hackers had changed their email addresses.
This meant many customers lost their access to the app and had to contact customer service to regain control.

DoorDash hasn’t responded to many users’ complaints. The few users who got a response didn’t get their issues resolved. Many users even took to Reddit to voice their concerns.
4 customers who tweeted their accounts had been hacked, told Techcrunch that they used their DoorDash passwords for other websites as well. Three people were unsure if they used the same password for other sites as well.

Out of the dozen or so people interviewed, 6 said that they used password specifically for DoorDash. 3 users had used a password generator to create a strong and unique password.

What is even more shocking is, the fact that a startup valued at $4 billion had such a huge lapse in security.

The food delivery startup said there was no data breach on their servers. They explained that the users could have stolen a list of usernames and passwords and try them on different platforms, such as Instagram, Twitter, Facebook etc.

This process is known as credential stuffing. DoorDash could not respond when they were asked about the accounts with unique passwords being hacked.

Becky Sosonov, a spokesperson for DoorDash said, “We do not have any information to suggest that DoorDash has suffered a data breach. To the contrary, based on the information available to us, including internal investigations, we have determined that the fraudulent activity reported by consumers resulted from credential stuffing.”

Some users either used the smartphone app or accessed DoorDash through its website, while some used both. Most users only realized about the scam when their credit card companies called them about possible fraud.

Many users were unsurprisingly furious with the company. Their main concern was how seemingly easy it was for the hackers to get users’ login details. They were also angry with the company’s lack of interest in the matter.

One user said, “Simply makes no sense that so many people randomly had their accounts infiltrated for so much money at the same time.”

DoorDash says that it is not to be blamed for the hacks, rather its credential stuffing is the culprit in this whole matter.

Also Read: Lime causes another death this morning

But when questioned about their weak password input algorithm, they did not have a clear answer. The startup’s current password policy allows only 8 characters minimum, and weak passwords such as “12345678” and “password” can be used.

Many of these flaws can be overcome by just implementing tighter password policies such as two-factor authentication.

Stay tuned for more updates!

This post was originally published on September 26, 2018 and was updated on January 17, 2019.

Filed Under: Security, World of Tech Tagged With: DoorDash, Food Delivery app

Related Stories

  • Vodafone halts purchase of Huawei equipment amid Western bans

    Vodafone halts purchase of Huawei equipment amid Western bans

  • Harley Davidson’s Electric Motorbike makes it to CES19

    Harley Davidson’s Electric Motorbike makes it to CES19

  • People don’t like robots that are better than them

    People don’t like robots that are better than them

Shares102FacebookTweetPinLinkedInPrintEmail

About Fazeel Ashraf

IT graduate from the National University of Science and Technology with a passion for writing. When not reading or writing, I can be found listening to rock and metal or playing some classic jams on my electric guitar. I’m also a big fan of horror movies.

Reader Interactions

Join the Discussion
  1. Rina says

    September 27, 2018

    My doordash account was also hacked a couple months ago! I got a email from doordash stated that my email was changed which I did not do. So when I called they couldn’t find my account I was and still am freaking out about it because this person named Alan knows where I live! I had a number of cards saved that I couldn’t remember which one do one by one I replaced them, I had to go through every website that have passwords to and change them and get a new email, What a freakin headache!!! It was my genius idea to look up that email that replaced mine to find my account which worked and all they did was deactivate it and apologize!! There’s still someone out there with my full name, address, phone number!!01 I have children too how am I to feel safe???? Thankfully they only changed the email and the name on the account at least as far as I know. So I wanted to warn people to stay away from doordash!!!! My hacker was Alan R s4ndman55@mail.com

    Reply
    • Amnah Fawad says

      September 27, 2018

      Legit concerns, I really hope DoorDash comes up with a better security plan considering how vulnerable the entire online arena has become to hacking attacks.

      Reply
    • Jazib Zaman says

      September 28, 2018

      That’s really sad. Thanks for warning the potential users. It really becomes frustrating when somebody lands into your private life without your permission and that’s what hacker actually does.
      I hope, you will not face the same situation again.

      Reply
  2. christine lester says

    September 28, 2018

    My account was just hacked last night too! They didnt change my email but changed my phone number and of course address. They reversed the charges and said an investigator will be contacting me but after reading this i have doubts that they really will do that. I loved having doordash but this makes me want to get rid of it altogether, especially since the site does not have an option for dumping my card info.

    Reply
  3. Erika says

    September 28, 2018

    Dashers usually have a lot of questions.Dasher questions can be broken down into the following sections: payment, DoorDash’s Red Card, editing personal information, switching cities and questions about dasher ratings.Sometimes it could be difficult to find direct answers. Some of them are clearly described in the article: https://help-center.pissedconsumer.com/top-consumer-questions-to-doordash/

    Reply
  4. Cary says

    September 28, 2018

    My account was hacked last night as well. Changed password and email tied to the account. Of course – first thing customer support asks “What’s the email on the account?….” then says “Hmm we can’t seem to find an account under that email.” YES. It was HACKED and the email was changed. Frustrating as hell. Still no resolution. It was supposedly “escalated” to a team that’s investigating. At the very least – my credit card has awesome fraud security.

    Reply
  5. Stephen Luce says

    December 13, 2018

    Just happened to me today. DoorDash and my bank were quick to help. This was a relief. Within 2 hours everything was fixed. # I called: (855) – 973 – 1040

    But this is for sure on door dash’s side. The login email I used is my work email and is the ONLY app/website I have ever used my work emai for; as I commonly order food for coworkers that work late. My passwords, while similar, are also unique to every app and website. These passwords are very complicated.

    Reply

Share Your Thoughts Cancel reply

Please read our comment policy before submitting your comment. Your email address will not be used or published anywhere. You will only receive comment notifications if you opt to subscribe below.

Primary Sidebar

Become a contributor

We are accepting contributor applications. All applications will be decided in 3 days after applying. To learn more visit the contributors page.
TextSheet Alternative

6 Top Alternatives to Textsheet for 2025

Muhammad Zeshan Sarwar October 5, 2024

battery draining apps

Top 10 battery draining apps to avoid 2025

Muhammad Abdullah October 5, 2024

Recent Stories

  • 6 Top Alternatives to Textsheet for 2025
  • Top 10 battery draining apps to avoid 2025
  • The Benefits of Having a Small Air Compressor for Flat Tires
  • 4 Best Free VPNs for 2025
  • 9 Best Calendar Apps in 2025

Footer

Discover

  • About us
  • Newsroom
  • Staff
  • Advertise
  • Send us a tip
  • Startup Submission Questionnaire
  • Brand Kit
  • Contact us

Legal pages

  • Reviews Guarantee
  • Community Guidelines
  • Corrections Policy and Practice
  • Cookies Policy
  • Our Ethics
  • Disclaimer
  • GDPR Compliance
  • Privacy Policy
  • Terms and Conditions

Must reads

  • Best AirPods alternatives on Amazon
  • Best PC monitors for gaming on Amazon
  • Best family board games
  • Best video doorbells without subscription
  • Best handheld video game consoles
  • Best all-season tires for snow
  • Best mobile Wi-Fi hotspots
  • Best treadmills on Amazon

Download our apps

TechEngage app coming soon on App Store

© 2024 TechEngage®. All Rights Reserved. TechEngage® is a project of TechAbout LLC.

TechEngage® is a registered trademark in the United States under Trademark Number 6823709 and in the United Kingdom under Trademark Number UK00003417167. It is also ISSN protected under ISSN 2690-3776 and has OCLC Number 1139335774.

  • Terms & Conditions
  • Privacy Policy