A food delivery support call or text appears to know about an order that was canceled, duplicated, or flagged as fraudulent. The sender says the problem can be fixed before the payment disappears.
For a restaurant, customer, or delivery worker, the message can feel connected to a normal problem inside a busy app. One verification code is all the caller says they need.

Overview
The scam copies a problem that really happens in delivery apps
The food delivery support scam uses order cancellations, refunds, double orders, account reviews, and payout delays as its cover story. These are ordinary events on delivery platforms, so an unexpected message can sound plausible.
The sender may pretend to represent DoorDash, Uber Eats, a restaurant, a customer, or a payment team. They ask for a telephone number, password, bank information, or one-time code needed to “confirm” the account.
The genuine platform may send a real code because the criminal is attempting a login or account change at the same moment. That code belongs only in the official app.
Customers, restaurants, and drivers can all be targeted
A customer may receive a refund story and be directed to a fake payment form. A restaurant may be told that its merchant account is suspended. A delivery worker may hear that a canceled order requires identity verification before earnings can be released.
Once an account is hijacked, criminals can change payout information, use stored payment methods, redeem credits, place orders, view personal details, or impersonate the owner in further support conversations.
The worker variation is especially damaging because a changed bank account can divert money already earned. The theft may not be noticed until the normal payout date.
An official scam alert confirms the multi-sided campaign
Australia’s National Anti-Scam Centre published a June 2026 warning about food delivery account-takeover scams. The alert says criminals target restaurants, customers, and delivery workers while impersonating platforms, businesses, and users.
The confirmed requests include one-time codes, login details, mobile numbers, and bank information. Scamwatch also warned that criminals can change payment settings and redirect workers’ earnings.
Watch for these warning signs:
- support contacts you unexpectedly outside the official app;
- the caller says an order is fraudulent but gives few verifiable details;
- a refund requires your password or one-time code;
- a worker must confirm a bank account after a cancellation;
- the message pressures you to act before a payout or refund expires;
- a link opens a sign-in page outside the platform’s known domain;
- the caller asks you to read back a genuine security message;
- payout or recovery information changes without a normal in-app notice;
- the sender becomes hostile when you choose to contact official support.
Why a Real Verification Code Does Not Verify the Caller
A one-time code proves that the person entering it has access to the recipient’s phone or email. It does not prove that the person requesting it works for the company.
The scammer can trigger the real code by entering the victim’s telephone number into a login, password-reset, or payout-change process. They then call and describe the message before it arrives.
That timing feels like inside knowledge. In reality, the caller knows about the code because they caused the security system to send it.
The message itself may warn not to share the number. Read the entire notification rather than accepting the explanation supplied by the caller.
A support representative should be able to handle an order issue without learning a password or private authentication code. If identity confirmation is required, it should happen inside the official app or site.
Do not type a code into a page opened from an unsolicited message. A phishing page can relay it to the real service immediately.

How the Food Delivery Support Scam Works
Step 1: The criminal selects a familiar platform problem
The opening message mentions a canceled order, duplicate charge, refund, account complaint, or delayed payout. It may include a common restaurant name or generic order number.
Because many people use several delivery services, the sender does not need accurate order data to receive responses.
Step 2: The conversation moves outside normal support
A telephone number, text reply, or external link becomes the only route to fix the supposed problem. The victim is discouraged from opening the app because the account is allegedly frozen or under review.
That instruction prevents the simplest check: whether the order, alert, or support ticket exists in the real account.
Step 3: Basic details prepare the account takeover
The caller asks for the registered telephone number, email address, delivery address, or driver identifier. Some of this information may already be known from a data breach or public restaurant listing.
The answers help the criminal locate the real account and make later questions appear routine.
Step 4: A genuine one-time code is triggered
The scammer starts a login or recovery action. The real platform sends an authentication code to the account owner.
The caller relabels it as a refund number, cancellation code, or proof that the worker completed a delivery. Sharing it approves the scammer’s action.
Step 5: Account and payout settings are changed
Inside a worker or restaurant account, the intruder may replace the bank details, email, telephone number, or password. A customer account may expose saved payment methods, credits, order history, and addresses.
The attacker acts quickly because the owner may receive legitimate change notifications.
Step 6: Money, earnings, or stored payment access is stolen
Workers can lose a scheduled payout. Restaurants can have settlement funds redirected. Customers may see unauthorized orders or card activity.
The criminal may also sell the account or use it to approach other people with a more convincing identity.
Step 7: Fake recovery support asks for another code
When the victim notices the takeover, the same operation may call back as a senior support agent. Another code is supposedly needed to reverse the changes.
Every recovery attempt must begin inside the official app or through contact information found on the platform’s real website.
How to Check a Delivery Alert Safely
Close the message and open the official delivery app from its normal icon. Look for the order, cancellation, payout, or security notice inside the authenticated account.
Restaurants should use their known merchant portal and established account representative. Delivery workers should review earnings and payout details without following the caller’s link.
Compare the contact method with the platform’s published support process. A caller may know company terminology while using a route the company does not support.
If a code arrives unexpectedly, treat it as an account-attack signal. Change the password and review sessions instead of reading the code to the caller.
Check email forwarding rules and recovery information. Account thieves sometimes change a secondary setting so they can return after the main password is replaced.
Review the exact bank account or card attached to the platform. For workers and restaurants, compare the last digits with the destination used for the previous legitimate payout.
Customers should inspect order history, saved addresses, credits, gift cards, and connected payment methods. Remove anything unfamiliar.
Do not rely on a screenshot sent by the supposed customer or support agent. The authoritative record is inside the verified platform and your own financial account.
One Code Can Redirect an Entire Week of Earnings
A one-time code is often the last barrier between a criminal and the account. The caller does not ask for it because support needs to identify the worker. They ask because they have already entered the username, started a password reset, or attempted to add a new device.
The code message may display the platform’s real sender name because the platform generated it. That makes the scam unusually convincing. The message is genuine, but the action that triggered it belongs to the attacker.
For drivers and restaurants, account control can lead directly to payout theft. The criminal changes the bank account or instant-payment destination, then withdraws earnings before the real owner understands why the dashboard is inaccessible.
Customers face a different version of the same risk. An attacker may use stored cards, order credits, gift balances, personal addresses, or account history. A convincing refund story can also lead the customer to a phishing page that collects payment details outside the app.
Order information does not authenticate a caller. Details can come from a compromised account, a dishonest customer, a leaked receipt, or earlier social engineering. The safe check is whether the problem appears after opening the official app independently.
If a support representative creates urgency around a code, end the conversation. Changing the password and checking payout settings immediately is faster and safer than debating the caller.
Businesses should also review who has administrator access to the merchant account. Remove unknown users, rotate shared passwords, and make sure payout-change alerts reach more than one trusted person. A second alert recipient can catch a takeover before the next settlement leaves the platform.
Company, Address, and Fulfillment Checks
The caller must connect to an official support case
End the conversation and open support through the app. Ask whether the ticket, order number, and representative exist without revealing extra account information first.
A spoofed caller ID or branded text label cannot replace that independent check.
The order address must match the real account
Compare the restaurant, customer address, items, time, and status inside the app. Generic details that fit thousands of orders should not be treated as private knowledge.
Do not confirm an address simply because the caller asks. Make them state information that can be checked without exposing more.
The payment destination must not change through a call
Workers and restaurants should treat any payout change as a high-risk action. Make changes only inside the official portal after confirming the current destination.
A legitimate support agent does not need a one-time code read aloud to redirect earnings.
The platform relationship must be verifiable
A restaurant, courier, and delivery platform are separate parties. Someone who knows the restaurant name may still have no relationship with the platform’s support team.
Verify each role through its own trusted contact route rather than allowing one caller to speak for all of them.
What to Do if You Have Fallen Victim to This Scam
- Use the official app immediately. Change the password, remove unknown sessions, and restore the correct email, telephone number, and recovery settings.
- Contact official support. Report an account takeover and ask the platform to freeze payout, order, gift-card, or payment activity while it investigates.
- Check payout information. Workers and restaurants should confirm the bank destination and ask whether a pending settlement can be stopped or recalled.
- Call the bank or card issuer. Report unauthorized orders, transfers, or exposed payment details. Replace the card when advised and monitor for small test charges.
- Secure the linked email. Change its password, enable strong multifactor authentication, remove forwarding rules, and review recovery contacts.
- Save evidence. Keep the message, caller number, code notification, order reference, account-change emails, payout destination, and transaction records.
- Scan affected devices. If you installed software or opened a suspicious attachment, run a complete Malwarebytes scan to detect remote-access or credential-stealing malware.
- Block malicious routes. AdGuard can prevent some known phishing pages and deceptive ads from loading. It cannot recover an account, so platform and bank action still come first.
- Report the scam. Notify the platform and local cybercrime authority. Australian victims can report through Scamwatch; US victims can use ReportFraud.ftc.gov.
- Reject follow-up recovery callers. Do not share another code or pay a fee to someone who claims the account can only be restored privately.
Frequently Asked Questions
Will delivery support ask for my one-time code?
A code may be entered inside an official app during a process you initiated, but it should not be read aloud or sent to an unsolicited caller.
What if the caller knew my real order details?
Details can come from a compromised account, dishonest participant, breached data, or ordinary guessing. End the contact and verify the order inside the official app.
Can a delivery worker lose completed earnings?
Yes. If criminals change payout details before settlement, earnings may be redirected. Workers should review bank information after any suspicious support contact.
Is a text from a branded sender automatically genuine?
No. Sender labels and numbers can be spoofed or abused. The alert should also exist in the official account reached independently.
Should I call the number in a cancellation message?
No. Open the app or type the platform’s official website yourself, then use the support route listed there.
What if I only shared the code but no password?
The code may have completed the login or change the criminal already started. Secure the account immediately and inspect sessions, payout details, and recovery settings.
The Bottom Line
The food delivery support scam borrows the noise and urgency of real orders. A canceled delivery or delayed payout becomes the excuse for stealing the one code that can unlock an account.
Keep support inside the verified app. Never read a one-time code to an unexpected caller, and check payout details quickly if anything changes. A genuine order problem can wait while you verify the person claiming to fix it.