DoorDash was reported affected by a security incident in November 2025, with reporting attributing entry to social engineering of employees.
Eight Months After The First Retail File, Nothing Had Changed
The corpus opened its 2025 campaign coverage in April with UK retailers at 25-0430 and 25-0501. It closes in November with a consumer technology platform reached by the same method.
In between: insurers, airlines, universities, SaaS tenants, an exchange’s outsourced support agents. The technique synthesis at 25-1022 collected them and found no technical control engaged at any point.
Resources Are Not The Variable
This desk filed at 25-0810 that Google was reached the same way as everyone else, and that the under-resourcing explanation this database relies on is unavailable for that file.
DoorDash is a second data point of the same kind: a well-funded technology company with a mature security function, reached through a conversation. Across a year of incidents, organisational wealth shows no relationship to the outcome.
And The Year Produced No Correction
Seven arrests and one conviction, per 25-1205 and 25-0812. Official warnings during the aviation phase, per 25-0627. Sector alerts from a regulator, per 25-1126b.
Each was real. None of them stopped a November incident using an April technique. Graded medium: the incident is reported in compilations and this desk has no company statement, affected count or confirmed vector.
Compiled from published breach compilations, listed below. No affected count or company statement was available in the material we reviewed. Corrections: corrections@forensicpost.com.