Policy

DoorDash workers got phished. They say DoorDash refused to help.

The phishing scam resulted in one worker losing nearly $900. DoorDash reimbursed these workers only after Protocol reached out.

DoorDash

DoorDash workers say the company was initially unhelpful in resolving their issues.

Photographer: Gabby Jones/Bloomberg via Getty Images

Sherrie Vidaurri first started delivering for DoorDash in March, and she loved it. The work paid at least $100 per day. In her first week on the job, Vidaurri made a little under $1,000.

"I loved it because I could work when I wanted and didn't have to work when I didn't want to," she told Protocol. "I was really happy. I mean, I couldn't believe I got paid to do what I was doing."

Vidaurri's feelings started to change the week of May 9, when she fell victim to a phishing scam that resulted in the loss of nearly $900. What made matters worse was her experience trying to resolve the issue with DoorDash: Vidaurri and another Dasher did not receive compensation for their stolen wages until they and the Gig Workers Collective reached out to Protocol.

"I am so shocked and thankful," Vidaurri told Protocol when she received an email about her recovered wages in her inbox. She added, "They had to be shamed into doing the right thing."

A phishy link

Phishing scams affected 241,342 people last year, making it the top cybercrime in 2020, according to the FBI's internet crime report. The scams resulted in a collective loss of about $54 million. Meanwhile, 61% of Americans could not identify a fraudulent website, according to a 2019 survey.

The scam works like this: DoorDash workers receive an order that they begin to fulfill. The Dasher then receives a phone call from someone pretending to be a DoorDash support representative, saying the order has been canceled. But because DoorDash hasn't actually canceled the order, the Dasher is unable to get it off their screen. That's when the scammer offers to send the Dasher a link. Upon clicking the link, the Dasher gets logged out of their account and then has to enter their username and password.

The scammer who called Vidaurri also told her about a bogus delivery "challenge" that would give her a $200 bonus. She completed the required number of deliveries the scammer told her to, but never received her bonus. That's when she called DoorDash's support team, only to find the support agent had no idea what she was talking about.

That night, the scammer called Vidaurri again to let her know she had successfully completed the challenge. All she had to do was "confirm" some information and then they would send her a Visa gift card in the mail.

"That kind of raised my suspicion a little bit, but not to the level of there's a problem," Vidaurri said. "And that code he sent me and what I read back to him gave him the last piece of what he needed to change my banking information inside my DoorDash app."

Vidaurri realized something was wrong a couple of days later when she went back to work. She couldn't seem to contact her customer, so she called the support team again, thinking there might be something wrong with the technology DoorDash uses to connect customers with delivery drivers. The support representative asked Vidaurri to confirm some information, but none of it matched what was on her file — because the scammers had gone into her account and changed all her information.

Unfortunately, the support agent was unable to help. "She couldn't do anything for me other than escalate the situation and put it up the chain," Vidaurri said.

Vidaurri started asking questions about how the scam would affect her and her standing in the DoorDash community. But the representative grew irritated with her, she said: "I really tried not to be rude, but I'm sure I came off poorly, because she hung up on me."

Vidaurri called back. This time, she spoke with a different representative who confirmed for her that the scammer successfully withdrew money from her DoorDash account and deposited it into their bank account. The representative explained that it was too late for DoorDash to cancel the payment and retrieve it, but that the company would get back to her within 48 hours. DoorDash never got back to her, she said.

DoorDash did email Vidaurri about suspicious attempts to log in to her account, in the days leading up to when the scammer changed her bank account information. Unfortunately, Vidaurri didn't see those emails immediately and by the time she did, DoorDash had already inadvertently paid the scammers.

"The last time I spoke to anybody, I was basically told that, on their end, the situation is solved," she said. "And that on their end, they're done."

'There is nothing more we can do to salvage these stolen funds'

Dasher Shelly Roofe caught the scammers midway through the process when they tried a similar tactic on her. She successfully reset her DoorDash password and corrected her banking information before the platform distributed the payment, but DoorDash never paid her the $246 she legitimately earned that week, she told Protocol. Similar to Vidaurri, Roofe only received money — $185.14 of it — after we reached out.

DoorDash told Roofe they first needed to conduct an investigation, which could take up to 11 days. Eleven days and then some went by without her money.

In an email to Roofe on May 31, DoorDash acknowledged how frustrating it must be for her, saying the company "understand[s] how hard [she] worked on the DoorDash platform for these earnings."

The support representative went on to blame her, Roofe said.

"Unfortunately, by sharing your password and/or your security code, you gave someone else access to your account and to your money — it's just like giving out the PIN to your ATM card or debit card," the representative wrote in the email seen by Protocol. "For your security and protection, we do not keep your bank account information in our own records. That information lives in your Dasher app and is accessed by our third party payments vendor in order to pay you. When we received your inquiry, we contacted our payments vendor and had them attempt to reverse the transfer of funds. Unfortunately, they were unable to recover your payment. At this point, there is nothing more we can do to salvage these stolen funds."

Roofe felt frustrated by that response because she had already updated her account before payday, she said. Roofe maintains that the scammers didn't take her money — DoorDash withheld it.

"DoorDash takes the trust of our community very seriously, and we're committed to the security of those we serve," a DoorDash spokesperson told Protocol. "We have addressed the fraudulent activity and resolved the issue for both Dashers involved, and appreciate their patience as we ensured proper payment into the correct accounts."

A 'one-time courtesy' reimbursement

DoorDash says it has a policy to reimburse Dashers who have experienced and reported fraud. If workers do experience fraud, DoorDash says they should contact customer support to help resolve the issue. That's why it felt odd to Vidaurri that she received little to no support from DoorDash during this whole process.

DoorDash's email to Vidaurri, viewed by Protocol, specified that "this repayment is a one-time courtesy." It also said DoorDash has the right "not to provide this courtesy if we determine that you have jeopardized the security of your account by sharing your confidential information."

Both Roofe and Vidaurri are relieved to have gotten their money back, but feel frustrated with DoorDash for not doing more to support them and to warn other Dashers of the scam.

It's unclear how many workers the scam has affected. DoorDash said these were one-off incidents and that these types of phishing scams are not a prevalent issue on the DoorDash platform. But on a Reddit thread, a handful of other people reported experiencing similar issues in the past month.

Whether or not it's prevalent, Vidaurri would have liked for DoorDash to have notified her and other Dashers about the scam, just as DoorDash has sent notifications to Dashers warning them not to leave their cars running while they run inside to pick up food due to the potential for vehicle theft. DoorDash could also provide an onboarding process for Dashers in which it explains the ways it will or won't contact Dashers and the type of information they'll never request from Dashers, she added.

"They knew this was happening because they'd been getting a ton of phone calls from people already for two days," Vidaurri said. "When I called support, the gal immediately knew what was going on."

Roofe similarly feels frustrated in DoorDash's handling of the scam, especially given that it happened to Vidaurri two weeks before it happened to her.

"I feel violated because they never informed us there was a problem and they apparently have known about this for a while," Roofe said. "They knew but never said anything about it. They never warned us."







Entertainment

The (gaming) clones never stopped attacking

Clones keep getting through app review despite App Store rules about copying. It's a sign of the weaknesses in mobile app stores — and the weakness in Big Tech’s after-the-fact moderation approach.

Clones aren't always illegal, but they are widely despised.

Image: Disney

Two of the most fundamental tenets of the mobile gaming market:

  1. Free always wins.
  2. No good gaming idea is safe from copycats.

In combination, these two rules help produce what the industry calls a clone. Most often, clones are low-effort, ripped-off versions of popular games that monetize in not-so-savory fashion while drawing in players with a price tag of zero.

Keep Reading Show less
Nick Statt
Nick Statt is Protocol's video game reporter. Prior to joining Protocol, he was news editor at The Verge covering the gaming industry, mobile apps and antitrust out of San Francisco, in addition to managing coverage of Silicon Valley tech giants and startups. He now resides in Rochester, New York, home of the garbage plate and, completely coincidentally, the World Video Game Hall of Fame. He can be reached at nstatt@protocol.com.
Sponsored Content

A CCO’s viewpoint on top enterprise priorities in 2022

The 2022 non-predictions guide to what your enterprise is working on starting this week

As Honeywell’s global chief commercial officer, I am privileged to have the vantage point of seeing the demands, challenges and dynamics that customers across the many sectors we cater to are experiencing and sharing.

This past year has brought upon all businesses and enterprises an unparalleled change and challenge. This was the case at Honeywell, for example, a company with a legacy in innovation and technology for over a century. When I joined the company just months before the pandemic hit we were already in the midst of an intense transformation under the leadership of CEO Darius Adamczyk. This transformation spanned our portfolio and business units. We were already actively working on products and solutions in advanced phases of rollouts that the world has shown a need and demand for pre-pandemic. Those included solutions in edge intelligence, remote operations, quantum computing, warehouse automation, building technologies, safety and health monitoring and of course ESG and climate tech which was based on our exceptional success over the previous decade.

Keep Reading Show less
Jeff Kimbell
Jeff Kimbell is Senior Vice President and Chief Commercial Officer at Honeywell. In this role, he has broad responsibilities to drive organic growth by enhancing global sales and marketing capabilities. Jeff has nearly three decades of leadership experience. Prior to joining Honeywell in 2019, Jeff served as a Partner in the Transformation Practice at McKinsey & Company, where he worked with companies facing operational and financial challenges and undergoing “good to great” transformations. Before that, he was an Operating Partner at Silver Lake Partners, a global leader in technology and held a similar position at Cerberus Capital LP. Jeff started his career as a Manufacturing Team Manager and Engineering Project Manager at Procter & Gamble before becoming a strategy consultant at Bain & Company and holding executive roles at Dell EMC and Transamerica Corporation. Jeff earned a B.S. in electrical engineering at Kansas State University and an M.B.A. at Dartmouth College.
Entertainment

Beat Saber, Bored Apes and more: What to do this weekend

Don't know what to do this weekend? We've got you covered.

Images: Ross Belot/Flickr; IGBD; BAYC

This week we’re listening to “Harvest Moon” on repeat; burning some calories playing Beat Saber; and learning all about the artist behind the goofy ape pics that everyone (including Gwyneth Paltrow?) is talking about.

Neil Young: Off Spotify? No problem.

Neil Young removed his music from Spotify this week, but countless recordings are still available on YouTube, including this 1971 video of him performing “Heart of Gold” in front of a live studio audience, complete with some charming impromptu banter. And while you’re there, scroll down and read a few of the top-rated comments. I promise you won’t be disappointed.

'Archive 81': Not based on a book, but on a podcast!

Netflix’s latest hit show is a supernatural mystery horror mini-series, and I have to admit that I was on the fence about it many times, in part because the plot just often didn’t add up. But then the main character, Dan the film buff and archivist, would put on his gloves, get in the zone, and meticulously restore a severely damaged, decades old video tape, and proceed to look for some meaning beyond the images. That ritual, and the sentiment that we produce, consume and collect media for something more than meets the eye, ultimately saved the show, despite some shortcomings.

'Secrets of Sulphur Springs': Season 2 is out now

If you’re looking for a mystery that's a little more family-friendly, give this show about a haunted hotel, time travel, and kids growing up in a world that their parents don’t fully understand a try. Season 2 dropped on Disney+ this month, and it not only includes a lot more time travel mysteries, but even uses the show’s time machine to tackle subjects as serious as reparations.

The artist behind those Bored Apes

Remember how NFTs are supposed to generate royalties with every resale, and thus support artists better than any of their existing revenue streams? Seneca, the artist who was instrumental in creating those iconic apes for the Bored Ape Yacht Club, wasn’t able to share details about her compensation in this Rolling Stone profile, but it sure sounds like she is not getting her fair share.

Beat Saber: Update incoming

Years later, Beat Saber remains my favorite VR game, which is why I was very excited to see a teaser video for cascading blocks, which could be arriving any day now. Time to bust out the Quest for some practice time this weekend!

Correction: Story has been updated to correct the spelling of Gwyneth Paltrow's name. This story was updated Jan. 28, 2022.


Janko Roettgers

Janko Roettgers (@jank0) is a senior reporter at Protocol, reporting on the shifting power dynamics between tech, media, and entertainment, including the impact of new technologies. Previously, Janko was Variety's first-ever technology writer in San Francisco, where he covered big tech and emerging technologies. He has reported for Gigaom, Frankfurter Rundschau, Berliner Zeitung, and ORF, among others. He has written three books on consumer cord-cutting and online music and co-edited an anthology on internet subcultures. He lives with his family in Oakland.

Boost 2

Can Matt Mullenweg save the internet?

He's turning Automattic into a different kind of tech giant. But can he take on the trillion-dollar walled gardens and give the internet back to the people?

Matt Mullenweg, CEO of Automattic and founder of WordPress, poses for Protocol at his home in Houston, Texas.
Photo: Arturo Olmos for Protocol

In the early days of the pandemic, Matt Mullenweg didn't move to a compound in Hawaii, bug out to a bunker in New Zealand or head to Miami and start shilling for crypto. No, in the early days of the pandemic, Mullenweg bought an RV. He drove it all over the country, bouncing between Houston and San Francisco and Jackson Hole with plenty of stops in national parks. In between, he started doing some tinkering.

The tinkering is a part-time gig: Most of Mullenweg’s time is spent as CEO of Automattic, one of the web’s largest platforms. It’s best known as the company that runs WordPress.com, the hosted version of the blogging platform that powers about 43% of the websites on the internet. Since WordPress is open-source software, no company technically owns it, but Automattic provides tools and services and oversees most of the WordPress-powered internet. It’s also the owner of the booming ecommerce platform WooCommerce, Day One, the analytics tool Parse.ly and the podcast app Pocket Casts. Oh, and Tumblr. And Simplenote. And many others. That makes Mullenweg one of the most powerful CEOs in tech, and one of the most important voices in the debate over the future of the internet.

Keep Reading Show less
David Pierce

David Pierce ( @pierce) is Protocol's editorial director. Prior to joining Protocol, he was a columnist at The Wall Street Journal, a senior writer with Wired, and deputy editor at The Verge. He owns all the phones.

Workplace

Mental health at work is still taboo. Here's how to make it easier.

Tech leaders, HR experts and organizational psychologists share tips for how to destigmatize mental health at work.

How to de-stigmatize mental health at work, according to experts.

Illustration: Christopher T. Fong/Protocol

When the pandemic started, HR software startup Phenom knew that its employees were going to need mental health support. So it started offering a meditation program, as well as a counselor available for therapy sessions.

To Chief People Officer Brad Goldoor’s surprise, utilization of these benefits was very low, starting at about a 10% take rate and eventually weaning off. His diagnosis: People still aren’t fully comfortable opening up about mental health, and they’re especially not comfortable engaging with their employer on the topic.

Keep Reading Show less
Michelle Ma

Michelle Ma (@himichellema) is a reporter at Protocol, where she writes about management, leadership and workplace issues in tech. Previously, she was a news editor of live journalism and special coverage for The Wall Street Journal. Prior to that, she worked as a staff writer at Wirecutter. She can be reached at mma@protocol.com.

Fintech

Robinhood's regulatory troubles are just the tip of the iceberg

It’s easiest to blame Robinhood’s troubles on regulatory fallout, but its those troubles have obscured the larger issue: The company lacks an enduring competitive edge.

A crypto comeback might go a long way to help Robinhood’s revenue

Image: Olena Panasovska / Alex Muravev / Protocol

It’s been a full year since Robinhood weathered the memestock storm, and the company is now in much worse shape than many of us would have guessed back in January 2021. After announcing its Q4 earnings last night, Robinhood’s stock plunged into the single digits — just below $10 — down from a recent high of $70 in August 2021. That means Robinhood’s valuation dropped more than 84% in less than six months.

Investor confidence won’t be bolstered much by yesterday’s earnings results. Total net revenues dropped to $363 million from $365 million in the preceding quarter. In the quarter before that, Robinhood reported a much better $565 million in net revenue. Net losses were bad but not quite as bad as before: Robinhood reported a $423 million net loss in Q4, an improvement from the $1.3 billion net loss in Q3 2021. One of the most shocking data points: Average revenue per user dropped to $64, down from a recent high of $137 in Q1 2021. At the same time, Robinhood actually reported a decrease in monthly active users, from 18.9 million in Q3 2021 to 17.3 million in Q4 2021.

Keep Reading Show less
Hirsh Chitkara

Hirsh Chitkara ( @HirshChitkara) is a is a reporter at Protocol focused on the intersection of politics, technology and society. Before joining Protocol, he helped write a daily newsletter at Insider that covered all things Big Tech. He's based in New York and can be reached at hchitkara@protocol.com.

Latest Stories
Bulletins