Class action lawsuits over DoorDash data breaches have been filed after each of the company’s three major incidents in 2019, 2022, and 2025, but none has resulted in a settlement or payout to affected users. The most recent U.S. case, filed after the October 2025 breach, was voluntarily dismissed in April 2026. A Canadian claim is still in its early stages, and a separate California regulatory settlement did not distribute money to consumers.
Andrizzi v. DoorDash and the 2025 Breach Litigation
On November 18, 2025, Michelle Andrizzi filed a proposed class action in the U.S. District Court for the Northern District of California, Andrizzi v. DoorDash Incorporated, Case No. 3:25-cv-09926.1Top Class Actions. DoorDash Class Action Claims Data Breach Exposed PII of Thousands of Users The complaint alleged negligence, negligence per se, breach of implied contract, invasion of privacy, breach of fiduciary duty, and unjust enrichment, and accused DoorDash of failing to use reasonable security practices, holding onto old data, and taking too long to notify users after the October 2025 breach.
On January 28, 2026, Judge Araceli Martinez-Olguin consolidated Andrizzi with a related action, Case No. 3:25-cv-10281, and denied a motion to appoint interim class counsel. An amended complaint followed on February 27, 2026. The plaintiffs then filed a Notice of Voluntary Dismissal on April 8, 2026, and the case was terminated. The docket does not publicly explain the reasons for the dismissal.2CourtListener. Andrizzi v. DoorDash Incorporated
A separate class action tied to the 2025 breach was reportedly filed on January 21, 2026, alleging DoorDash failed to implement proper cybersecurity measures to protect the private information of customers, employees, and merchants.3ClassAction.org. DoorDash Inc.
In Canada, Buckingham Law issued a Statement of Claim in November 2025 on behalf of users and drivers notified of the breach, asserting a breach of privacy claim against DoorDash and affiliated companies. The firm is still collecting registrations from affected individuals, and the action is in early stages.4Buckingham Law. Door Dash Class Action
The Earlier 2019 Class Actions
The first significant class action, Nelson v. DoorDash, was filed by Melissa Nelson on October 4, 2019, in the U.S. District Court for the Eastern District of New York, Case No. 1:19-cv-05622.5Top Class Actions. DoorDash Class Action Says 5M Customers Info Exposed in Data Breach It alleged negligence, unjust enrichment, and breach of a duty of care, and criticized DoorDash for waiting until September 2019 to disclose a breach that had occurred in May.6Food Logistics. DoorDash Gets Hit With Data Breach, 5 Million People Affected Publicly available research does not indicate a final resolution for this case.
A parallel Canadian action was filed by JSS Barristers in the Alberta Court of King’s Bench on behalf of everyone whose data was stored by DoorDash as of May 4, 2018, and accessed without authorization.7JSS Barristers. DoorDash Class Action That case was discontinued on September 17, 2024, on a “without costs” basis after Alberta Court of Appeal decisions and the Supreme Court of Canada’s denial of leave to appeal in similar cases made the claim unviable.8JSS Barristers. Appendix B – Notice of Discontinuance Approval Hearing Order Neither side paid the other’s fees, and no compensation went to class members.
What Each Breach Exposed
The three breaches differed in scope and in what data attackers reached.
2019 Breach
DoorDash disclosed on September 26, 2019, that unauthorized third parties had accessed data on May 4, 2019, affecting about 4.9 million customers, Dashers, and merchants who joined before April 5, 2018. For customers, that meant names, email addresses, phone numbers, order histories, and the last four digits of payment cards. Delivery workers had names, contact information, and the last four digits of bank accounts exposed, and roughly 100,000 also had their driver’s license numbers taken. Restaurants had the last four digits of their bank accounts exposed. Full card numbers, Social Security numbers, and complete bank details were not accessed.9Identity Theft Resource Center. Steps to Take After DoorDash Data Breach
2022 Breach
DoorDash confirmed on August 25, 2022, that a phishing campaign known as “0ktapus” had compromised a third-party vendor with limited access to internal tools. Attackers reached names, email addresses, delivery addresses, and phone numbers of a “small percentage” of users, with a smaller subset also having partial payment information (card type and last four digits) exposed. Dashers had names, phone numbers, and email addresses accessed. Social Security numbers, full card numbers, and bank details were not part of this breach.10TechCrunch. DoorDash Customer Data Breach Twilio
2025 Breach
DoorDash disclosed on November 13, 2025, that an employee had fallen for a social engineering attack on October 25, 2025, giving an unauthorized party access to names, email addresses, phone numbers, and physical addresses of customers, Dashers, and merchants. The company said no Social Security numbers, driver’s license information, or financial data was accessed, and confirmed the matter was under law enforcement investigation.11SecurityWeek. DoorDash Says Personal Information Stolen in Data Breach12Yahoo Finance. DoorDash Discloses Data Breach The 19-day gap between discovery and notification drew criticism, though it would have satisfied California Senate Bill 446’s 30-day notification requirement, which took effect January 1, 2026.13Malwarebytes. Thieves Order a Tasty Takeout of Names and Addresses From DoorDash
Related Actions That Are Not Breach Class Actions
Two other DoorDash-related matters often come up in searches but are separate from the breach class actions and do not pay affected users.
In February 2024, California Attorney General Rob Bonta announced a $375,000 settlement with DoorDash over allegations that the company shared customer names, addresses, and transaction histories with marketing cooperatives in exchange for advertising access, which the attorney general determined amounted to a “sale” of personal information under the California Consumer Privacy Act without required notice or opt-out. DoorDash also agreed to review vendor contracts, add technical controls to detect data sales, and file annual compliance reports for three years.14California Office of the Attorney General. Attorney General Bonta Announces Settlement With DoorDash The penalty went to the state, not to consumers, and the case addressed commercial data sharing rather than a hack.15California Office of the Attorney General. Privacy Enforcement Actions
A separate class action, Atkins v. Amplitude, Inc., Case No. 24-cv-04913, targets data analytics company Amplitude over software development kits embedded in the DoorDash app that plaintiffs say tracked location, device identifiers, and in-app activity without consent, in alleged violation of federal and California wiretap and computer fraud laws. On September 2, 2025, the court denied Amplitude’s motion to dismiss but granted its motion to compel arbitration under equitable estoppel, tying the claims to DoorDash’s own arbitration clause. The case is stayed pending arbitration.16GovInfo. Atkins v. Amplitude, Inc. Labaton Keller Sucharow LLP is also pursuing individual arbitration claims against Amplitude on behalf of DoorDash users who ordered through the app since January 1, 2022, with potential statutory damages of up to $1,000 or more per claimant.17Labaton Keller Sucharow LLP. Amplitude The defendant there is Amplitude, not DoorDash.
If You Received a Breach Notice
No U.S. breach class action against DoorDash is currently active with a claims process. If you were notified about the 2025 breach and live in Canada, Buckingham Law is registering potential class members.4Buckingham Law. Door Dash Class Action If you ordered through the DoorDash app on or after January 1, 2022, Labaton Keller Sucharow is signing up individual arbitration claimants against Amplitude over the tracking allegations.17Labaton Keller Sucharow LLP. Amplitude Because the exposed data across the three breaches has included email addresses, phone numbers, and physical addresses, targeted phishing is the main practical risk, and DoorDash has recommended phishing awareness and data removal services to affected users.