DoorDash Support Scam: Fake $200 Bonuses and Stolen Dasher Account Codes

The call arrives while you’re finishing an order. Someone from Support mentions a problem, then offers a $200 bonus for your trouble.

A DoorDash support scam can feel like part of the job. The important question is what that caller needs you to do next.

Illustrative fictional DoorDash Support chat using an order problem and a sample bonus to request a verification code

Overview

The problem is the impersonator, not DoorDash

This is an account-takeover scam in which a caller or message pretends to resolve an order, deliver assistance, or release a bonus.

The request crosses a clear boundary when the supposed helper wants your password, a security code, or an attacker-chosen replacement password.

DoorDash explicitly warns Dashers about those requests in its account-protection guidance. Knowing something about an order does not make the request safe.

The $200 amount is one reported lure, not a confirmed promotion or a fixed feature of every incident. The same approach can use another amount.

DoorDash is a legitimate service. The deceptive call, link, or conversation is the scam, not the existence of support or genuine bonuses.

Different accounts create different kinds of loss

For a Dasher, access can put earnings and payout settings at risk. That is different from a customer account holding order history and payment methods.

A customer should check purchases and payment activity. A driver should also review where earnings are being sent. Restaurant accounts require their own support route.

Do not assume an ordinary delivery customer has a driver payout account. Mixing those roles can send someone toward the wrong recovery steps.

An unexpected code or reset notice is worth investigating, but it does not by itself prove that anyone successfully entered the account.

Use the app to restart the conversation

If a contact asks for account secrets, end that exchange. Open the app yourself and contact support from the route available there.

The useful checks are concrete:

  • Did you initiate this support contact independently?
  • Is the person requesting a login secret or asking you to change it?
  • Does the claimed bonus appear through your normal account?
  • Are your account email, phone, and payment settings still yours?
  • Has any purchase, withdrawal, or payout changed without your approval?

The images are fictional screen-only examples. They illustrate the unsafe requests, not a captured caller, live website, or verified bonus offer.

Why an Order Problem Makes the Call Believable

The interruption fits the working day

A delivery involves timing, substitutions, cancellations, and communication. A call during that process can seem more plausible than an unrelated message arriving overnight.

The driver may be looking for parking or trying to finish a pickup. There is less attention available for checking who actually started the conversation.

A caller can benefit from that ordinary pressure without controlling the whole delivery platform. The recipient supplies much of the missing credibility.

It helps to separate two questions: whether an order has a problem, and whether this person is authorized to request a login secret.

The first question might have a real answer. It does not change the answer to the second.

A bonus changes suspicion into cooperation

The promised credit or assistance gives the call a friendly ending. Instead of threatening a loss, the caller offers to make the inconvenience worthwhile.

That can make a request feel like routine eligibility checking. A code is described as a small administrative step rather than access to an account.

Real incentives can exist, so an article should not dismiss every bonus. The unsafe part is handing over access to obtain the supposed benefit.

A legitimate offer should remain explainable when checked through your own app. You should not need to stay on an unsolicited call to discover it.

How the DoorDash Support Scam Works

Step 1: A caller attaches the story to an order or bonus

The approach may begin with an alleged cancellation, an order review, or financial assistance. Sometimes the caller makes the issue sound urgent.

DoorDash’s warning includes a scenario where a small order leads to a cancellation request and then a supposed support call seeking the driver’s password.

That example is a warning pattern, not evidence that every small order is fraudulent. Ordinary customers place small orders for perfectly legitimate reasons.

Do not confront a customer simply because an order resembles an online anecdote. The important signal is the later request for confidential account access.

Stay focused on what you can verify. Record the order reference and the caller’s claim, then check through support you reach independently.

Step 2: The supposed helper makes access sound necessary

The caller explains that a review must be completed before the issue can be resolved. The explanation may sound technical without identifying any real account process.

You might be asked to provide the account email, enter a linked page, or accept a reset as part of clearing the problem.

Some contacts instead tell you which password to use. A password chosen by an unexpected caller is not private, even if you enter it yourself.

This is the turning point. The conversation stops being about the order and starts changing who can control the account.

You do not owe the caller a demonstration of trust. Leaving the call and opening your own support route is a sensible way to resolve uncertainty.

Step 3: A real security step is repackaged as verification

A code may arrive from a legitimate account system after someone starts a login or recovery attempt. Its arrival does not authenticate the person on the call.

The caller can ask you to read it aloud while insisting that it is needed for the bonus. That story changes the apparent purpose, not the code’s power.

Read the actual message on your screen. A warning against sharing a code is more meaningful than the caller’s explanation of why an exception is needed.

Do not approve an unexpected prompt merely to make it disappear. An approval may complete an action you did not initiate.

If you already disclosed a code, explain that precisely to support. They need to distinguish a possible attempted login from a confirmed account change.

The next illustration shows an invented account-review form. Its address is fictional, and none of the displayed fields should be filled with real information.

Illustrative fictional Dasher account-review page requesting an email address, password, and security code

Step 4: Access may expose the account’s money-related settings

If access succeeds, the consequences depend on the account and its available controls. Not every stolen code produces an immediate withdrawal.

A driver should investigate earnings destinations, while a customer should investigate orders and payment activity. Both should check account contact details and unfamiliar changes.

The scammer may keep talking while making changes. A calm voice and a promise that the review is almost finished can discourage the recipient from looking.

Do not take a displayed balance as the whole answer. A future payout destination can matter even when today’s balance still looks unchanged.

Similarly, no immediate bank charge does not prove a disclosed password is safe. Account access and financial loss are separate events to contain.

Step 5: The caller leaves the recipient with a second problem

The original order or bonus may never be resolved. The recipient now has to determine what was shared and whether the account remains under their control.

A message that says everything is fixed is not reliable confirmation. The account’s own records and independently reached support are better starting points.

Keep any cancellation or payout dispute separate from the impersonation report. Both can be important, but they may involve different records and teams.

There is no need to keep the scammer available as an adviser. Stop the conversation before another request expands the damage.

What to Check Inside Your Real Account

Review identity and access before looking only for charges

Check whether the account email and phone still belong to you. Unexpected changes can interfere with password recovery and alerts about later activity.

Look for reset notices and any available signs of unfamiliar access. Save useful records without publishing codes, full bank details, or personal information.

If the account is unavailable, do not follow the caller’s recovery link. Tell official support that access is lost and describe the last action you remember.

A driver who also orders as a customer should consider both roles. DoorDash’s reset instructions note that the password change can affect both accounts.

Look at the destination, not just the amount

For drivers, confirm the Earnings bank account and any Fast Pay debit-card information. Ask support to investigate changes you did not authorize.

For customers, compare order records with card statements. An unfamiliar saved payment method or delivery address also deserves a closer look.

Tell the relevant provider whether money moved, a destination changed, or information was merely disclosed. Those are different starting points for their investigation.

Do not test the situation by sending a small payment. You can document an unauthorized change without adding another transaction.

Check the story without following its route

Ask support whether the order problem or offered assistance exists. You can state the caller’s claim without reproducing their instructions.

Use the Dasher app’s support guidance to start a separate conversation. Avoid search ads promising instant account restoration.

When helping another driver, encourage them to perform the account checks themselves. Do not ask them to send you passwords or login codes.

What to Do if You Have Fallen Victim to This Scam

  1. End the incoming contact. Stop the call or chat before another verification request arrives. Do not let an alleged support deadline keep you engaged.

    Keep the order reference, visible message, and time of the call. You can record what happened without returning to the suspicious page.

  2. Reach DoorDash through your own app. Report support impersonation and identify whether you are a customer, Dasher, or merchant.

    Explain exactly what you shared: password, code, approval, card information, or remote access. Ask for help securing access and reviewing affected account activity.

    Support may need time to investigate. A case reference is more useful than the scammer’s promise that a payout will be restored immediately.

  3. Reset exposed account access safely. Start the password-reset process through the app or official help instructions, using a device you have reason to trust.

    Choose a new, unique password yourself. If the old password was reused elsewhere, secure those accounts too, especially the email used for recovery.

    Ask official support about suspicious sessions or account-contact changes. Do not assume one password reset automatically resolves every possible exposure.

  4. Check the money controls relevant to your role. Drivers should verify Earnings bank details and Fast Pay card settings. Customers should review orders and saved payments.

    Preserve screenshots of unauthorized changes with sensitive details masked. Tell support which entries do not match your own records.

    A missing payout and a card charge need different investigations. Keep those amounts, dates, and transaction references in separate notes.

  5. Contact the payment provider if money or card details were exposed. Use its established app or the number on your card, not the caller’s contact.

    Describe unauthorized transactions and ask what protective or dispute options apply. If a transfer was authorized under deception, say so accurately.

    Do not label every loss a chargeback case. Eligibility, timing, and available reversals depend on the payment method and the provider’s rules.

  6. Respond to any software or device exposure. If the caller persuaded you to install a tool, disconnect their access and seek trusted technical assistance.

    A Malwarebytes scan can help investigate suspicious downloads or persistent device symptoms. AdGuard can reduce exposure to malicious advertising while browsing.

    Neither tool recovers a stolen payout or replaces account recovery. Simply receiving the call does not mean your device contains malware.

  7. Keep a useful incident record. Save messages, order details, support references, and payment receipts together. Record when you first noticed each change.

    For U.S. reporting, FTC guidance explains payment-specific response options and reporting. Local authorities may also need evidence of a financial loss.

    A report helps document the incident, but it is not a guarantee that funds will be returned or a particular caller identified.

  8. Reject paid recovery approaches. A stranger who promises to unlock your Dasher earnings after another fee may be targeting the same loss.

    Do not hand account access to a social-media recovery expert. Continue through the platform and payment provider you contacted independently.

Frequently Asked Questions

Is every DoorDash bonus a scam?

No. The warning concerns an impersonator who uses an offer to obtain access. Verify genuine incentives through your account without sharing a password or code.

Does a caller knowing my order prove they work for DoorDash?

No. Order context can make a story convincing, but it does not authorize a request for confidential login information. Restart support contact independently.

Can a customer account change my Dasher payout destination?

Do not assume all account roles have identical controls. Check the affected account type and review the money-related settings available to you with official support.

What if I shared a code but see no missing money?

Report the disclosure and secure access anyway. No immediate loss does not establish that the code was unused or that account settings remain unchanged.

Should I use a password supplied by the caller?

No. An unexpected caller knows any password they choose for you. Set your own unique password through the real recovery process.

Will a security scan recover my earnings?

No. Scanning addresses possible device threats. Account recovery, payout review, and payment disputes must be handled through the relevant service and financial provider.

The Bottom Line

The DoorDash support scam turns an order problem or bonus into an access request. A familiar delivery context does not make a password or code safe to share.

End the incoming contact, check your real account, and use in-app support. If you disclosed access, review both account security and the money settings relevant to your role.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

AmeriCorps Grant Scam: Fake CNCS Lists and Agents Demanding Release Fees

Next

Bristol Bay Seafood Scam: Fake Facebook Ads and the Keeprake Checkout Trap