web analytics

DoorDash Hack – Source: www.schneier.com

Rate this post

Source: www.schneier.com – Author: Bruce Schneier

A DoorDash driver stole over $2.5 million over several months:

The driver, Sayee Chaitainya Reddy Devagiri, placed expensive orders from a fraudulent customer account in the DoorDash app. Then, using DoorDash employee credentials, he manually assigned the orders to driver accounts he and the others involved had created. Devagiri would then mark the undelivered orders as complete and prompt DoorDash’s system to pay the driver accounts. Then he’d switch those same orders back to “in process” and do it all over again. Doing this “took less than five minutes, and was repeated hundreds of times for many of the orders,” writes the US Attorney’s Office.

Interesting flaw in the software design. He probably would have gotten away with it if he’d kept the numbers small. It’s only when the amount missing is too big to ignore that the investigations start.

Tags: , ,

Posted on May 20, 2025 at 7:05 AM4 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Original Post URL: https://www.schneier.com/blog/archives/2025/05/doordash-hack.html

Category & Tags: Uncategorized,courts,scams,theft – Uncategorized,courts,scams,theft

Views: 1

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post