CSIDB logo
Incident

Instacart

Incident posture

Attack window
Aug 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-07-16 13:39

Linked entities

Victim
Instacart
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Instacart experienced a security incident involving unauthorized access by two third-party support agents who excessively reviewed shopper profiles, potentially exposing names, email addresses, telephone numbers, driver's license numbers, and license thumbnails for 2,180 individuals. The company confirmed no data was stored, downloaded, or copied during the breach but offered affected users complimentary credit monitoring for two years as a precaution. Following the incident, enhanced security protocols were implemented, including improved authentication methods, shopper ID verification, secure login procedures, automatic logouts, and restrictions on device switching. This follows a separate credential stuffing attack earlier in the year where compromised accounts were sold online.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Instacart disclosed a security incident on August 20, 2020, involving unauthorized access to shopper data by two third-party support agents. The company identified the breach during a routine review of support protocols, prompting an immediate investigation with forensic analysts. The agents, employed by an unnamed vendor, accessed more shopper profiles than required for their support roles. Investigators confirmed the exposed information included names, email addresses, telephone numbers, driver's license numbers, and thumbnail images of licenses for 2,180 shoppers. Instacart stated no evidence indicated data was stored, downloaded, or digitally copied during the access period. The company emphasized no customer profiles or information were compromised beyond the specified shopper group. Affected individuals received direct notifications and were offered two years of free credit monitoring as a precautionary measure despite the absence of confirmed data exfiltration.

Instacart implemented enhanced security controls following the investigation, including new shopper ID verification processes and secure login requirements. Additional measures involved automatic logout functionality and restrictions on device switching to limit unauthorized account access. The company also announced plans to launch a dedicated customer support service for security-related inquiries and potential personal information compromises. This incident occurred shortly after Instacart addressed a separate credential stuffing attack in July 2020, where 278,531 user accounts were listed for sale on dark web forums. Forensic reviews focused exclusively on the third-party agents' activities without expanding the impacted shopper count beyond the initially identified 2,180 individuals. The company maintained that all remedial actions were applied proactively despite finding no evidence of persistent data compromise.

Sources

Sources available to members: 1 source.

CSIDB