DoorDash's Third Breach: Why Some Companies Never Learn

DoorDash suffers its third data breach in six years. When does negligence become liability?

DoorDash's Third Breach: A Pattern of Negligence?

For the third time in six years, DoorDash has fallen victim to a data breach, exposing sensitive customer data to bad actors. As consumers grow increasingly wary of companies unable to secure their information, businesses like DoorDash face mounting pressure to answer one question: When does negligence become liability? This latest incident serves as a stark reminder that cybersecurity lapses are rarely isolated events—they’re often symptoms of deeper organizational failures.

The Breach: What Happened This Time?

In the latest breach, DoorDash confirmed that unauthorized access resulted in the exposure of customer names, delivery addresses, and partial payment card information. Early investigations point to a compromised third-party vendor, an issue strikingly similar to their 2022 breach. The breach also highlights vulnerabilities in token-based API authentication, a technology widely adopted but poorly managed by some organizations.

While DoorDash reassured customers that passwords and full payment card details were encrypted and secured, the breach still raises critical questions about their vendor management protocols and overall cybersecurity hygiene.

Recurring Themes in DoorDash’s Breach History

  • 2019: A data breach exposed the personal information of 4.9 million users due to poor internal access controls.

  • 2022: A third-party vendor’s security failure led to compromised customer data.

  • 2025: This most recent breach again involved a vendor vulnerability, suggesting systemic issues in how DoorDash manages external partnerships.

Three breaches in six years are not just unfortunate coincidences—they reveal a pattern of inadequate prioritization of cybersecurity at both the strategic and operational levels.

Why Companies Like DoorDash Struggle to Learn

Repeated breaches often stem from a combination of cultural, operational, and strategic shortcomings. Here are the most common reasons companies fail to evolve their cybersecurity posture:

1. Reactive, Not Proactive

Many organizations only invest in security measures after an incident occurs. DoorDash’s 2019 breach prompted better encryption protocols, but the company still neglected critical areas like vendor management, which contributed to subsequent breaches.

2. Over-Reliance on Vendors

By 2025, the SaaS ecosystem is more interconnected than ever, with businesses relying on dozens of third-party vendors for core operations. However, many companies fail to vet their vendors rigorously or monitor ongoing compliance with security standards.

3. Insufficient Board-Level Engagement

Cybersecurity is often viewed as a technical issue rather than a business-critical risk. Executives and boards that fail to treat cybersecurity as a strategic priority leave organizations vulnerable to repeated failures.

“Cybersecurity negligence isn’t just poor management; in today’s environment, it’s a direct business risk that can erode customer trust and brand reputation irreparably.”

The Cost of Negligence in 2025

Data breaches are no longer just PR nightmares; they’re existential threats. The financial fallout from cybersecurity incidents has skyrocketed in recent years. According to the 2025 Ponemon Institute report, the average cost of a data breach has risen to $5.4 million, up from $4.5 million in 2023. For consumer-facing companies like DoorDash, the intangible costs—loss of customer trust, legal liabilities, and reputational damage—are even harder to quantify.

In the U.S., regulatory bodies like the FTC and state governments have begun imposing heavier fines and stricter requirements on companies with repeated breaches. California’s Consumer Privacy Act (CCPA) and similar legislations have extended liability to companies that fail to adequately vet their vendors. This regulatory shift turns negligence into a legal liability, making breaches like DoorDash’s latest incident far more consequential.

Lessons for the Business World

  • Vendor Accountability: Ensure third-party vendors meet stringent cybersecurity standards and conduct regular audits.

  • Board Involvement: Treat cybersecurity as a business risk and make it a board-level priority.

  • Continuous Improvement: Build an adaptive security strategy that evolves with emerging threats.

Actionable Steps for Business Leaders

Every executive should ask themselves: Could this happen to us? The answer is almost always yes unless proactive measures are taken. Here’s how leaders can ensure their organizations avoid DoorDash’s fate:

1. Build a Culture of Security

Cybersecurity needs to be embedded into the company culture, not treated as an IT department issue. From the C-suite to entry-level employees, everyone should understand their role in maintaining security.

2. Leverage AI for Threat Detection

AI-powered cybersecurity tools have advanced significantly by 2025. These tools can identify anomalies, predict vulnerabilities, and automate responses to detected threats. Business leaders should invest in AI solutions to reduce the human error component that contributes to breaches.

3. Prioritize Vendor Risk Management

Organizations must establish robust vendor management programs that include:

  • Comprehensive risk assessments before onboarding vendors

  • Regular audits of vendor compliance with security standards

  • Clear incident response protocols for vendor-related breaches

4. Adopt Zero Trust Architecture

Zero Trust principles are not new, but their adoption has accelerated in recent years. By assuming all access requests are potentially malicious until verified, companies can reduce the risk of both internal and external threats.

The Road Ahead

DoorDash’s third breach is a cautionary tale for all businesses. In an era of heightened consumer awareness and stricter regulations, repeated cybersecurity failures are no longer excusable. Companies must treat cybersecurity as a core business function, not a technical afterthought.

For DoorDash, the path forward will require significant investment in vendor management, cultural shifts, and a commitment to continuous improvement. For other organizations, this should serve as an urgent wake-up call: learn from others’ mistakes before they become your own.

Browse all insights · Contact Bart McDonough