DoorDash confirmed that an unauthorized third-party adversary accessed a subset of production data stored on a downstream commercial utility system. The breach leaked profile names, email indexes, delivery logs, and hashed password strings of users and merchants.