Desk live·
ForensicPost
Breaches/Cloud/File 25-1119b

DoorDash Affected Through Social Engineering of an Employee

DoorDash was reported affected in November 2025 through social engineering of an employee. It is the last named victim of the year in the corpus, and the technique had not changed since April.

Constructed geometry · not a chart of case data
TargetDoorDash
ActorUnattributed
S. Rosler11 min readConfidence: medium2 sources reviewed

DoorDash was reported affected by a security incident in November 2025, with reporting attributing entry to social engineering of employees.

Eight Months After The First Retail File, Nothing Had Changed

The corpus opened its 2025 campaign coverage in April with UK retailers at 25-0430 and 25-0501. It closes in November with a consumer technology platform reached by the same method.

In between: insurers, airlines, universities, SaaS tenants, an exchange’s outsourced support agents. The technique synthesis at 25-1022 collected them and found no technical control engaged at any point.

Resources Are Not The Variable

This desk filed at 25-0810 that Google was reached the same way as everyone else, and that the under-resourcing explanation this database relies on is unavailable for that file.

DoorDash is a second data point of the same kind: a well-funded technology company with a mature security function, reached through a conversation. Across a year of incidents, organisational wealth shows no relationship to the outcome.

And The Year Produced No Correction

Seven arrests and one conviction, per 25-1205 and 25-0812. Official warnings during the aviation phase, per 25-0627. Sector alerts from a regulator, per 25-1126b.

Each was real. None of them stopped a November incident using an April technique. Graded medium: the incident is reported in compilations and this desk has no company statement, affected count or confirmed vector.

How we reported this

Compiled from published breach compilations, listed below. No affected count or company statement was available in the material we reviewed. Corrections: corrections@forensicpost.com.

Sources
  1. November 2025: major cyber attacks, ransomware attacks, data breachesCM Alliance
  2. Top data breaches of 2025SharkStriker
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary