
Australia's Scamwatch is warning about food delivery scams targeting customers, restaurants and delivery workers. Scammers may impersonate platforms such as DoorDash or Uber Eats, a restaurant, a customer or support staff to steal login details, verification codes or financial information.
For restaurant owners, a compromised delivery account can also put payout information and business earnings at risk.
Here's what to watch for.
According to Scamwatch, scammers are impersonating food delivery platforms, restaurants and customers to convince people that something has gone wrong with an order or account.
You might receive a call, text or other message claiming there's a problem with an order, cancellation, refund, payment or your account, or that a transaction is fraudulent or a "double order."
The scammer then asks for information they supposedly need to fix the problem. That might include your mobile number, login credentials, bank details or a one-time verification code sent to your phone or email. The verification code may actually be the key the scammer needs to access your account. Once inside, scammers may change account information, take control of the account or redirect payments.
Timing is one of the scammers' biggest advantages. If you've just placed an order, are waiting for a delivery or are currently working on an order, a call claiming something has gone wrong doesn't necessarily seem suspicious. The fact that they know something about the order doesn't prove that the person contacting you is legitimate.
DoorDash specifically warns Dashers that scammers may trigger a verification code and then ask the driver to read it over the phone. If successful, the scammer may be able to change banking information, redirect earnings and lock the legitimate user out of the account. DoorDash says its support staff will never ask for a password or one-time verification code.
Delivery workers and restaurants are attractive targets because their delivery accounts are connected to payments and banking information.
Scamwatch warns that a delivery worker might be told an order has been cancelled because it is fraudulent or is a "double order." The scammer may then offer compensation and ask for account or personal details supposedly needed to process the payment. In other cases, scammers may impersonate platform support and claim there's a problem with the driver's account or an active delivery. If they gain access to the account, they may be able to change payout details and redirect the driver's earnings.
In July 2026, two men pleaded guilty to participating in a scheme that used stolen personal information to impersonate DoorDash delivery drivers and redirect their earnings. According to the U.S. Department of Justice, one defendant admitted that he and his co-conspirators stole at least $743,235 from victims.
Restaurants can be targeted in similar ways. A scammer may pose as a representative of a delivery platform and claim there's a problem with an order, payment or restaurant account, then ask for login credentials, banking information or verification codes. If they gain access, they may be able to change account or payout information, disrupt orders or use the compromised account for further fraud.
These scams can be particularly convincing during busy service periods, when employees are handling multiple orders and may feel pressure to resolve an apparent problem quickly.
One warning sign by itself doesn't necessarily mean your account has been compromised, but investigate:
If someone contacts you unexpectedly about an order or account problem, don't rush to respond. Never share passwords or one-time verification codes, and don't use links provided in unexpected messages. Instead, open the delivery platform yourself and contact support through the official app or website.
If you run a restaurant, limit access to delivery-platform accounts to employees who actually need it. Make sure staff know who is authorized to communicate with platform support or change payment and payout information, and that passwords and verification codes should never be shared with unexpected callers.
If you receive a suspicious message about a food delivery order, refund or account problem, check it before you respond.
Bitdefender Scamio can analyze suspicious texts, emails, links, QR codes and screenshots to help you determine whether you're dealing with a scam. You can also use Bitdefender Link Checker to check a suspicious URL before opening it.
If you run a restaurant, the risk goes beyond individual scam messages. The phones and computers you use for orders, payments, email and banking can also be targeted by phishing, malware and account takeover attempts.
Bitdefender Ultimate Small Business Security protects very small businesses against these threats across their devices, accounts and employees. It also includes Scam Copilot, an AI-powered scam detection tool designed for businesses that can help identify suspicious messages and other scam attempts, alongside email protection and device security.
That means restaurant owners can protect both the accounts they rely on to run the business and the employees who may be targeted by scammers during a busy shift.
Try Bitdefender Ultimate Small Business Security free for 30 days. No credit card required.
You may also want tot read:
A food delivery scam is a fraud involving a food delivery order, account or platform. Scammers may impersonate delivery companies, restaurants, customers or support staff to steal money, passwords, verification codes or financial information.
Yes. If scammers obtain your login credentials or a one-time verification code, they may be able to access your account. Depending on the account, they could change information, make unauthorized transactions or redirect payments.
DoorDash says its support staff will never ask you for your password or one-time verification code. If someone unexpectedly asks for either, stop communicating and contact DoorDash through the official app.
The scammer may already have some of the information needed to log in to your account. The verification code is designed to prove that you are the person trying to sign in. Giving that code to someone else can allow them to complete the login or account recovery process.
Don't rely on the caller ID or information the caller knows about your order. End the call and contact the delivery platform through its official app or website. If the issue is legitimate, you can deal with it there.
Restaurant owners should use unique passwords, enable two-factor authentication where available, limit account access to employees who need it, and establish clear rules about who can change payment or payout information. Employees should never give passwords or one-time verification codes to unexpected callers claiming to represent a delivery platform.
Change the account password immediately and contact the delivery platform through its official support channels. Check payout and banking information for unauthorized changes, review who has access to the account, and remove any unfamiliar users or devices. If money has been redirected or banking information compromised, contact your bank or payment provider as soon as possible.
tags
Cristina Popov is a Denmark-based content creator and small business owner who has been writing for Bitdefender since 2017, making cybersecurity feel more human and less overwhelming.
View all posts