Food Delivery Support Scam Hijacks Worker Accounts

A food delivery support call or text appears to know about an order that was canceled, duplicated, or flagged as fraudulent. The sender says the problem can be fixed before the payment disappears.

For a restaurant, customer, or delivery worker, the message can feel connected to a normal problem inside a busy app. One verification code is all the caller says they need.

Fake food delivery support text claiming an order was canceled and requesting a one-time code

Overview

The scam copies a problem that really happens in delivery apps

The food delivery support scam uses order cancellations, refunds, double orders, account reviews, and payout delays as its cover story. These are ordinary events on delivery platforms, so an unexpected message can sound plausible.

The sender may pretend to represent DoorDash, Uber Eats, a restaurant, a customer, or a payment team. They ask for a telephone number, password, bank information, or one-time code needed to “confirm” the account.

The genuine platform may send a real code because the criminal is attempting a login or account change at the same moment. That code belongs only in the official app.

Customers, restaurants, and drivers can all be targeted

A customer may receive a refund story and be directed to a fake payment form. A restaurant may be told that its merchant account is suspended. A delivery worker may hear that a canceled order requires identity verification before earnings can be released.

Once an account is hijacked, criminals can change payout information, use stored payment methods, redeem credits, place orders, view personal details, or impersonate the owner in further support conversations.

The worker variation is especially damaging because a changed bank account can divert money already earned. The theft may not be noticed until the normal payout date.

An official scam alert confirms the multi-sided campaign

Australia’s National Anti-Scam Centre published a June 2026 warning about food delivery account-takeover scams. The alert says criminals target restaurants, customers, and delivery workers while impersonating platforms, businesses, and users.

The confirmed requests include one-time codes, login details, mobile numbers, and bank information. Scamwatch also warned that criminals can change payment settings and redirect workers’ earnings.

Watch for these warning signs:

  • support contacts you unexpectedly outside the official app;
  • the caller says an order is fraudulent but gives few verifiable details;
  • a refund requires your password or one-time code;
  • a worker must confirm a bank account after a cancellation;
  • the message pressures you to act before a payout or refund expires;
  • a link opens a sign-in page outside the platform’s known domain;
  • the caller asks you to read back a genuine security message;
  • payout or recovery information changes without a normal in-app notice;
  • the sender becomes hostile when you choose to contact official support.

Why a Real Verification Code Does Not Verify the Caller

A one-time code proves that the person entering it has access to the recipient’s phone or email. It does not prove that the person requesting it works for the company.

The scammer can trigger the real code by entering the victim’s telephone number into a login, password-reset, or payout-change process. They then call and describe the message before it arrives.

That timing feels like inside knowledge. In reality, the caller knows about the code because they caused the security system to send it.

The message itself may warn not to share the number. Read the entire notification rather than accepting the explanation supplied by the caller.

A support representative should be able to handle an order issue without learning a password or private authentication code. If identity confirmation is required, it should happen inside the official app or site.

Do not type a code into a page opened from an unsolicited message. A phishing page can relay it to the real service immediately.

Fraudulent delivery driver payout screen showing an unauthorized bank account change

How the Food Delivery Support Scam Works

Step 1: The criminal selects a familiar platform problem

The opening message mentions a canceled order, duplicate charge, refund, account complaint, or delayed payout. It may include a common restaurant name or generic order number.

Because many people use several delivery services, the sender does not need accurate order data to receive responses.

Step 2: The conversation moves outside normal support

A telephone number, text reply, or external link becomes the only route to fix the supposed problem. The victim is discouraged from opening the app because the account is allegedly frozen or under review.

That instruction prevents the simplest check: whether the order, alert, or support ticket exists in the real account.

Step 3: Basic details prepare the account takeover

The caller asks for the registered telephone number, email address, delivery address, or driver identifier. Some of this information may already be known from a data breach or public restaurant listing.

The answers help the criminal locate the real account and make later questions appear routine.

Step 4: A genuine one-time code is triggered

The scammer starts a login or recovery action. The real platform sends an authentication code to the account owner.

The caller relabels it as a refund number, cancellation code, or proof that the worker completed a delivery. Sharing it approves the scammer’s action.

Step 5: Account and payout settings are changed

Inside a worker or restaurant account, the intruder may replace the bank details, email, telephone number, or password. A customer account may expose saved payment methods, credits, order history, and addresses.

The attacker acts quickly because the owner may receive legitimate change notifications.

Step 6: Money, earnings, or stored payment access is stolen

Workers can lose a scheduled payout. Restaurants can have settlement funds redirected. Customers may see unauthorized orders or card activity.

The criminal may also sell the account or use it to approach other people with a more convincing identity.

Step 7: Fake recovery support asks for another code

When the victim notices the takeover, the same operation may call back as a senior support agent. Another code is supposedly needed to reverse the changes.

Every recovery attempt must begin inside the official app or through contact information found on the platform’s real website.

How to Check a Delivery Alert Safely

Close the message and open the official delivery app from its normal icon. Look for the order, cancellation, payout, or security notice inside the authenticated account.

Restaurants should use their known merchant portal and established account representative. Delivery workers should review earnings and payout details without following the caller’s link.

Compare the contact method with the platform’s published support process. A caller may know company terminology while using a route the company does not support.

If a code arrives unexpectedly, treat it as an account-attack signal. Change the password and review sessions instead of reading the code to the caller.

Check email forwarding rules and recovery information. Account thieves sometimes change a secondary setting so they can return after the main password is replaced.

Review the exact bank account or card attached to the platform. For workers and restaurants, compare the last digits with the destination used for the previous legitimate payout.

Customers should inspect order history, saved addresses, credits, gift cards, and connected payment methods. Remove anything unfamiliar.

Do not rely on a screenshot sent by the supposed customer or support agent. The authoritative record is inside the verified platform and your own financial account.

One Code Can Redirect an Entire Week of Earnings

A one-time code is often the last barrier between a criminal and the account. The caller does not ask for it because support needs to identify the worker. They ask because they have already entered the username, started a password reset, or attempted to add a new device.

The code message may display the platform’s real sender name because the platform generated it. That makes the scam unusually convincing. The message is genuine, but the action that triggered it belongs to the attacker.

For drivers and restaurants, account control can lead directly to payout theft. The criminal changes the bank account or instant-payment destination, then withdraws earnings before the real owner understands why the dashboard is inaccessible.

Customers face a different version of the same risk. An attacker may use stored cards, order credits, gift balances, personal addresses, or account history. A convincing refund story can also lead the customer to a phishing page that collects payment details outside the app.

Order information does not authenticate a caller. Details can come from a compromised account, a dishonest customer, a leaked receipt, or earlier social engineering. The safe check is whether the problem appears after opening the official app independently.

If a support representative creates urgency around a code, end the conversation. Changing the password and checking payout settings immediately is faster and safer than debating the caller.

Businesses should also review who has administrator access to the merchant account. Remove unknown users, rotate shared passwords, and make sure payout-change alerts reach more than one trusted person. A second alert recipient can catch a takeover before the next settlement leaves the platform.

Company, Address, and Fulfillment Checks

The caller must connect to an official support case

End the conversation and open support through the app. Ask whether the ticket, order number, and representative exist without revealing extra account information first.

A spoofed caller ID or branded text label cannot replace that independent check.

The order address must match the real account

Compare the restaurant, customer address, items, time, and status inside the app. Generic details that fit thousands of orders should not be treated as private knowledge.

Do not confirm an address simply because the caller asks. Make them state information that can be checked without exposing more.

The payment destination must not change through a call

Workers and restaurants should treat any payout change as a high-risk action. Make changes only inside the official portal after confirming the current destination.

A legitimate support agent does not need a one-time code read aloud to redirect earnings.

The platform relationship must be verifiable

A restaurant, courier, and delivery platform are separate parties. Someone who knows the restaurant name may still have no relationship with the platform’s support team.

Verify each role through its own trusted contact route rather than allowing one caller to speak for all of them.

What to Do if You Have Fallen Victim to This Scam

  1. Use the official app immediately. Change the password, remove unknown sessions, and restore the correct email, telephone number, and recovery settings.
  2. Contact official support. Report an account takeover and ask the platform to freeze payout, order, gift-card, or payment activity while it investigates.
  3. Check payout information. Workers and restaurants should confirm the bank destination and ask whether a pending settlement can be stopped or recalled.
  4. Call the bank or card issuer. Report unauthorized orders, transfers, or exposed payment details. Replace the card when advised and monitor for small test charges.
  5. Secure the linked email. Change its password, enable strong multifactor authentication, remove forwarding rules, and review recovery contacts.
  6. Save evidence. Keep the message, caller number, code notification, order reference, account-change emails, payout destination, and transaction records.
  7. Scan affected devices. If you installed software or opened a suspicious attachment, run a complete Malwarebytes scan to detect remote-access or credential-stealing malware.
  8. Block malicious routes. AdGuard can prevent some known phishing pages and deceptive ads from loading. It cannot recover an account, so platform and bank action still come first.
  9. Report the scam. Notify the platform and local cybercrime authority. Australian victims can report through Scamwatch; US victims can use ReportFraud.ftc.gov.
  10. Reject follow-up recovery callers. Do not share another code or pay a fee to someone who claims the account can only be restored privately.

Frequently Asked Questions

Will delivery support ask for my one-time code?

A code may be entered inside an official app during a process you initiated, but it should not be read aloud or sent to an unsolicited caller.

What if the caller knew my real order details?

Details can come from a compromised account, dishonest participant, breached data, or ordinary guessing. End the contact and verify the order inside the official app.

Can a delivery worker lose completed earnings?

Yes. If criminals change payout details before settlement, earnings may be redirected. Workers should review bank information after any suspicious support contact.

Is a text from a branded sender automatically genuine?

No. Sender labels and numbers can be spoofed or abused. The alert should also exist in the official account reached independently.

Should I call the number in a cancellation message?

No. Open the app or type the platform’s official website yourself, then use the support route listed there.

What if I only shared the code but no password?

The code may have completed the login or change the criminal already started. Secure the account immediately and inspect sessions, payout details, and recovery settings.

The Bottom Line

The food delivery support scam borrows the noise and urgency of real orders. A canceled delivery or delayed payout becomes the excuse for stealing the one code that can unlock an account.

Keep support inside the verified app. Never read a one-time code to an unexpected caller, and check payout details quickly if anything changes. A genuine order problem can wait while you verify the person claiming to fix it.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Zoopark.fr EXPOSED – Fake or Real Store? Our Findings

Next

Senior Activities Ad Scam Installs Android Malware