Company Updates

A Security Update From Instacart

We wanted to share an update for Instacart customers related to reports about a recent third-party security issue.

Internally, we’ve assembled a cross-functional team to promptly investigate this issue and provide an update to our customers. Our teams have been working around the clock to quickly determine the validity of reports related to site security and so far our investigation has shown that the Instacart platform was not compromised or breached.

Based on our team’s assessment, we believe that this is what is commonly referred to as credential stuffing — an activity that occurs across the web when a person uses the same login credentials across various websites and apps. If a user’s credentials are compromised on another website or app and their login information is shared across platforms, it makes it easier for third-party bad actors to access and utilize accounts connected to those compromised login credentials.

In this instance, it appears that third-party bad actors were able to use usernames and passwords that were compromised in previous data breaches of other websites and apps to login to some Instacart accounts. In some instances, this would have given the third party bad-actors access to basic customer account information such as first name, address, last order, total order number, and in some cases, the last four digits of a customer’s credit card. This information was not uniformly pulled for every impacted customer, and no credit card data was compromised as Instacart does not store full credit card information.

We are taking a number of steps to further support those impacted, as well as to ensure the continued security of our platform. We’re actively communicating to all affected customers, invalidating their previous password and advising them to reset their password as an extra security measure. As is standard practice, we advise all customers to select unique, strong passwords for their Instacart accounts that they do not use on any other apps or websites as an extra precaution.

We have a dedicated security team, as well as multiple layers of security measures, focused on protecting the integrity of all customer accounts and data. The security of our customers’ accounts and data is a top priority at Instacart, and we are committed to maintaining a safe and secure environment for all members of the Instacart community.

Instacart

Author

Instacart is the leading grocery technology company in North America, partnering with more than 1,400 national, regional, and local retail banners to deliver from more than 80,000 stores across more than 14,000 cities in North America. To read more Instacart posts, you can browse the company blog or search by keyword using the search bar at the top of the page.

Most Recent in Company Updates

Helping the people of Los Angeles with access to fresh groceries and essentials

Company Updates

Helping the people of Los Angeles with access to fresh groceries and essentials

We are devastated by the effects of the wildfires sweeping through Los Angeles, impacting tens of thousands of people who have lost their homes, have been forced to evacuate, or are on call to evacuate…

Jan 9, 2025
Making Expert Nutrition Advice Accessible and Actionable with Instacart Health

Instacart Health

Making Expert Nutrition Advice Accessible and Actionable with Instacart Health

It should be easy to understand how nutritious a food is, but we’ve all been there – studying the fine print on a package, trying to figure out how it fits into our health needs…

Dec 20, 2024
New Solutions for Suppliers and Merchants with Instacart Business

Company Updates

New Solutions for Suppliers and Merchants with Instacart Business

At Instacart Business, our mission is to empower businesses of all kinds with seamless access to the fresh ingredients, snacks and business supplies they need. And over the past few months, Instacart Business has not…

Dec 16, 2024