DoorDash Hack
DoorDash司机利用虚假账户和员工权限,在系统中创建大量订单并重复标记完成以骗取资金,导致超过250万美元损失。软件设计漏洞使该行为得以实施,最终因金额过大而被发现。 2025-5-20 11:5:0 Author: www.schneier.com(查看原文) 阅读量:9 收藏

DoorDash Hack

A DoorDash driver stole over $2.5 million over several months:

The driver, Sayee Chaitainya Reddy Devagiri, placed expensive orders from a fraudulent customer account in the DoorDash app. Then, using DoorDash employee credentials, he manually assigned the orders to driver accounts he and the others involved had created. Devagiri would then mark the undelivered orders as complete and prompt DoorDash’s system to pay the driver accounts. Then he’d switch those same orders back to “in process” and do it all over again. Doing this “took less than five minutes, and was repeated hundreds of times for many of the orders,” writes the US Attorney’s Office.

Interesting flaw in the software design. He probably would have gotten away with it if he’d kept the numbers small. It’s only when the amount missing is too big to ignore that the investigations start.

Tags: , ,

Posted on May 20, 2025 at 7:05 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/05/doordash-hack.html
如有侵权请联系:admin#unsafe.sh