Food Delivery Account Takeover Scam Exposed: Codes, Payouts and Refunds

A delivery problem seems like the sort of thing you should fix quickly. The message mentions an order, a cancellation, or money you expect to receive.

Before replying, check which conversation you are actually in. A message about a real-looking order can come from outside the service handling it.

Illustrative food delivery text asking for a one-time code

Overview

One pretext, three groups of targets

Scamwatch warns that food delivery scammers target customers, restaurants, and delivery workers. They may impersonate a platform, a restaurant, or a customer.

The contact may concern an order, refund, cancellation, account problem, or payment. It asks the recipient to resolve an issue before checking through the real app.

DoorDash and Uber Eats are examples of platforms whose identities criminals may borrow. The warning does not accuse those services of running the fraud.

What the criminal needs

One-time codes, passwords, bank details, and account information can let an outsider take over an account or change where money is paid.

For a customer, that may mean unauthorized orders or exposed payment details. For a worker, a changed payout setting can redirect earned income.

For a restaurant, account access can create payment and order confusion. The exact damage depends on which account and permission the criminal obtains.

A single warning therefore needs different responses. Checking a customer’s saved card is not enough to protect a driver’s weekly payout.

The common point is account control. The supposed helper asks for information that lets someone else act as the person receiving the message.

The safe place to check

Open the platform’s official app or a bookmarked website yourself. Check order history, security alerts, and payout settings there.

  • Do not read a one-time code to a caller or paste it into an unexpected chat.
  • Do not send payment details to “correct” an order outside the app.
  • Contact support through the platform’s established help route.
  • Change credentials promptly if an unauthorized login appears.

The message shown above is a fictional reconstruction. Its sender, restaurant, and order amount are examples, not a captured case from Scamwatch.

How the Food Delivery Account Takeover Scam Works

Step 1: Create a believable order problem

The contact may claim a duplicate order, a failed payment, or a refund that cannot be processed. Those issues are common enough to sound routine.

A worker may be told an order was cancelled as “fraudulent” or entered twice. Scamwatch reports that this pretext can be used to ask for details.

The fraudster does not need to control a real order to raise concern. A broad message can catch someone who recently used the app.

Delivery happens so often that a generic “recent order” message can feel personally timed. The recipient may supply the missing order details in reply.

A restaurant during a rush is especially exposed to interruptions. Staff may prioritize clearing an order issue over verifying the caller’s identity.

If they know an actual order number, that information still does not authenticate them. Details can be seen, guessed, copied, or supplied during the conversation.

Step 2: Move the conversation outside the platform

A text or phone call may say the platform needs immediate action. The recipient is nudged away from the order screen, where the truth is easier to check.

Some callers claim to be a customer or restaurant. The role matters less than the attempt to make you use their instructions instead of official support.

Scamwatch warns about demands for extra payment or details outside the app, even when the caller says they can see the order.

Never treat the ability to name a delivery as permission to ask for your login code. Support should not need you to surrender account control.

A caller might offer to “walk you through” a refund. If the steps lead outside the app and into your account security settings, stop.

For workers, the pretext may be compensation after a supposedly fraudulent order. The promised credit is used to justify collecting details.

Step 3: Trigger a genuine one-time code

The operator may initiate a login or password reset using the victim’s contact details. A genuine code then arrives from the real platform.

The scammer says the code is needed to reverse a charge, verify a refund, or compensate a driver. The real purpose may be access to the account.

This is why a legitimate-looking code message can accompany a scam. The platform sent it, but the person asking to receive it is an outsider.

Read the code message carefully. Many such messages explain that the code is for signing in or that it should never be shared.

Do not type the code into a form reached through the stranger’s link either. That can deliver it to the same operator without a phone conversation.

If a code arrived when you did not request one, someone may already be trying to enter your account. Review security settings through the real app.

One-time codes are brief by design. Their short lifetime can make the caller insist that you hurry, which is another reason to pause.

Step 4: Enter the account and alter its settings

Once inside, a criminal may change the password, recovery contact, payment details, or payout destination. Scamwatch identifies account takeover and payment redirection as risks.

For delivery workers, this can mean earnings already accumulated are paid to someone else. A worker might discover the change only on the next payout date.

For restaurants, access to a merchant account can affect operations, contact details, or payment settings. The response should involve the platform’s merchant support.

A customer account may hold saved cards and addresses. The response should include both account recovery and a review of card activity.

If an account uses a shared restaurant email, the incident can affect multiple staff members. Reset access centrally and review who still has permission.

A worker should pay special attention to changes that happen just before payday. A redirected transfer can arrive before the next login alert is noticed.

Step 5: Explain away the warning signs

The victim may receive a password reset email or unfamiliar-login notice. The impostor might call it a normal side effect of resolving the order.

Do not accept that explanation from the person who asked for the code. Open the app independently and inspect the account’s security history.

The outsider may say the warning will disappear after the refund completes. There is no reason to let a suspected intruder finish a process first.

The second image illustrates a payout change alert in a fictional worker portal. It is not an actual platform screen or a documented victim account.

Illustrative worker account showing an unexpected payout change

Step 6: Redirect money or keep access

If the payout change is not stopped, earned money may be sent to the criminal’s chosen account. A customer might see charges or orders they never placed.

The operator may also continue using the account until the victim regains control. The precise sequence differs between workers, restaurants, and customers.

Scamwatch’s core warning is not one universal text script. It is the handoff from an order pretext to codes, credentials, and payment changes.

That handoff is easy to miss because each step sounds like customer service. Look at the final effect: who gains access, and who receives money?

Why “I Can See Your Order” Proves Very Little

People expect a real support agent to know their order. That expectation makes the statement persuasive, even when the caller provides no verifiable detail.

Someone posing as a restaurant may have information visible to a customer. A compromised account can reveal even more, but the first contact still needs verification.

Ask the platform to confirm any order issue through its own app. Do not use a link in the unexpected message to reach the supposed support page.

If an order is genuinely wrong, the official app should show a record or an established support route. A caller demanding secrecy or urgency deserves extra caution.

Do not ask the caller to recite more personal details as a test. That can invite them to fish for answers or repeat information already in the message.

A stronger test is channel independence: you initiate contact with the platform rather than continuing the stranger’s thread.

Check the timing too. An alert about an order that is not in your history may be a broad lure rather than a real service message.

Even when an order is real, the platform may show a different status from the caller’s story. Let the app record guide your next question.

Different Risks for Customers, Restaurants, and Workers

Customers: saved payment methods and addresses

Review recent orders, refunds, saved cards, addresses, and account email. Unrecognized changes may point to unauthorized access.

Contact your card provider if an unfamiliar order or charge appears. The platform can address account access while the provider handles payment disputes.

If a refund was promised, verify it in the original payment account. A screenshot supplied by the caller cannot prove money returned.

Remove an unfamiliar saved card or address only after recording evidence for support. Then ask the platform to terminate unknown sessions.

Restaurants: merchant access and order operations

Managers should check who can sign in, edit store details, and update deposit accounts. A supposed order problem should not require sharing owner credentials.

Tell staff where real platform support appears. A clear internal escalation path makes an urgent outside call less persuasive during a busy service.

Decide in advance who may change the merchant payout account. Limiting that permission can reduce damage when a front-line login is compromised.

Train staff to route suspicious calls to a manager without sharing a code. That is a specific action they can take during a crowded shift.

Workers: earnings and payout destinations

Open the worker app and verify the payout account, recent withdrawals, and contact information. A small change in routing can affect a full week’s earnings.

Report unauthorized changes to the platform immediately. Keep screenshots of the old and new settings where possible, without exposing full bank numbers publicly.

Check the last payout date and the next scheduled one. That tells support which transfer may need investigation.

If the app still shows your correct account, continue monitoring. The scammer may have tried and failed to change it, or may return later.

What to Do If You Fell for the Food Delivery Scam

  1. Open the official app yourself. Do not follow the caller’s link. Check whether an actual order problem exists and whether your account is still under your control.
  2. Change the password and secure recovery options. Use a unique password, review active sessions, and verify the phone number and email address attached to the account.
  3. Contact platform support through its genuine channel. Say that an outsider obtained a code or account details. Ask support to lock suspicious access and review recent changes.
  4. Inspect payment or payout activity. Customers should review cards and orders. Workers and restaurants should verify the bank account receiving earnings or sales.
  5. Notify the bank if money moved. Explain unauthorized orders, transfers, or diverted payouts. Ask what disputes or protective actions are available.
  6. Preserve messages and alerts. Keep the unexpected text, sender number, login notifications, order references, and screenshots of changed settings for the platform and authorities.
  7. Warn people sharing the account. Family members, restaurant staff, or a worker’s business partner may encounter follow-up messages or still have compromised sessions.

If the message led to a download or suspicious browser page, run a Malwarebytes scan. AdGuard can reduce some deceptive ads and malicious destinations.

Neither tool replaces account recovery. The urgent step is to revoke the outsider’s access and correct any payment destination.

If you reused the same password elsewhere, change those accounts too. Start with email because control of it can support additional resets.

Ask support whether it can provide a timeline of sign-ins and payout edits. That can help separate a suspicious message from completed account takeover.

Frequently Asked Questions

Can a real platform send a one-time code during a scam?

Yes. A thief can trigger a genuine login or reset code, then trick you into sharing it. The code’s authenticity does not authenticate the caller.

What if the caller knows my order number?

That detail alone is not proof of authority. Open the official app and contact support through its known help route.

Can a worker lose earnings without sharing a bank password?

Potentially. Access to a worker account may let an outsider change payout settings. Report any unfamiliar change to the platform immediately.

Does the warning mean DoorDash or Uber Eats is fraudulent?

No. Scamwatch says criminals may impersonate these services or other participants. The platforms’ names are borrowed in the scam.

Should I pay outside the app to fix a duplicate order?

No. Check the order inside the platform and use official support. An unexpected demand for separate payment is a warning sign.

Where can I report a food delivery impersonation?

Report it to the affected platform and your bank if money moved. Australian readers can also report to Scamwatch.

The Bottom Line

Food delivery account takeover scams use an ordinary order problem to obtain the one code or credential that opens the account.

Resolve the problem only inside the real app. If you shared a code, secure the account and inspect payments or payouts before the next transaction.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Fake Bunnings Environmental Bonds Scam Exposed: The 9% Return Claim Tested

Next

Personal Loan Payment Protection Scam Exposed: Upfront Fee Trap Explained