Company Updates

A Security Update From Instacart

Instacart

Instacart

Jul 24, 2020

We wanted to share an update for Instacart customers related to reports about a recent third-party security issue.

Internally, we’ve assembled a cross-functional team to promptly investigate this issue and provide an update to our customers. Our teams have been working around the clock to quickly determine the validity of reports related to site security and so far our investigation has shown that the Instacart platform was not compromised or breached.

Based on our team’s assessment, we believe that this is what is commonly referred to as credential stuffing — an activity that occurs across the web when a person uses the same login credentials across various websites and apps. If a user’s credentials are compromised on another website or app and their login information is shared across platforms, it makes it easier for third-party bad actors to access and utilize accounts connected to those compromised login credentials.

In this instance, it appears that third-party bad actors were able to use usernames and passwords that were compromised in previous data breaches of other websites and apps to login to some Instacart accounts. In some instances, this would have given the third party bad-actors access to basic customer account information such as first name, address, last order, total order number, and in some cases, the last four digits of a customer’s credit card. This information was not uniformly pulled for every impacted customer, and no credit card data was compromised as Instacart does not store full credit card information.

We are taking a number of steps to further support those impacted, as well as to ensure the continued security of our platform. We’re actively communicating to all affected customers, invalidating their previous password and advising them to reset their password as an extra security measure. As is standard practice, we advise all customers to select unique, strong passwords for their Instacart accounts that they do not use on any other apps or websites as an extra precaution.

We have a dedicated security team, as well as multiple layers of security measures, focused on protecting the integrity of all customer accounts and data. The security of our customers’ accounts and data is a top priority at Instacart, and we are committed to maintaining a safe and secure environment for all members of the Instacart community.

Instacart

Instacart

Instacart is the leading grocery technology company in North America, partnering with more than 1,400 national, regional, and local retail banners to deliver from more than 80,000 stores across more than 14,000 cities in North America. To read more Instacart posts, you can browse the company blog or search by keyword using the search bar at the top of the page.

Most Recent in Company Updates

Helping Local Independent Grocers Streamline Their Catering and Prepared Foods Businesses

FoodStorm

Helping Local Independent Grocers Streamline Their Catering and Prepared Foods Businesses

Over the past few years, FoodStorm - our order management system (OMS) designed specifically to help grocers manage their deli, prepared foods and catering - has seen remarkable growth. And today, we’re excited to share…...

Apr 24, 2024
Making Nutritious & Delicious Choices Easier with Instacart and WeightWatchers

Company Updates

Making Nutritious & Delicious Choices Easier with Instacart and WeightWatchers

New WeightWatchers integration with Instacart unlocks ability to browse ‘Points’-friendly recipes, shop for ingredients, and get everything delivered to your door - now live in the WeightWatchers app  In the hustle of everyday life, making…...

Apr 17, 2024
Why Smart Carts Are the Winning Technology Format for Grocers

Caper

Why Smart Carts Are the Winning Technology Format for Grocers

One of the most common misconceptions about smart carts is that they only serve as an alternative to self-checkout. However, the real magic behind a Caper Cart, our AI-powered smart cart, is the digital screen.…...

Apr 9, 2024