this post was submitted on 17 May 2025
247 points (99.6% liked)

Technology

70107 readers
2308 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Devagiri admitted to working with others in 2020 and 2021 to cause DoorDash to pay for deliveries that never occurred. At the time, Devagiri was a delivery driver for DoorDash orders. Under the scheme, Devagiri used customer accounts to place high value orders and then, using an employee’s credentials to gain access to DoorDash software, manually reassigned DoorDash orders to driver accounts that he and others controlled. Devagiri then caused the fraudulent driver accounts to report that the orders had been delivered, when they had not, and manipulated DoorDash’s computer systems to prompt DoorDash to pay the fraudulent driver accounts for the non-existent deliveries. Devagiri would then use DoorDash software to change the orders from “delivered” status to “in process” status and manually reassign the orders to driver accounts he and others controlled, beginning the process again. This procedure usually took less than five minutes, and was repeated hundreds of times for many of the orders.

The scheme resulted in fraudulent payments exceeding $2.5 million.

you are viewing a single comment's thread
view the rest of the comments
[–] rc__buggy@sh.itjust.works 45 points 1 day ago* (last edited 1 day ago) (4 children)

So many technically smart criminals being busted by just not having OPSEC. Dude did the technical theft and left his IP wide open. Get behind seven proxies.

What a fucking moron. Like DoorDash isn't going to notice this shit?

edit: so it's been pointed out that you must have a legit ID to sign up for DoorDash and they probably didn't track him down on the internut. I guess I have to assume that a smart guy that had a DD account found this hole and exploited it with his own DD account. his. own. DD. account. That's super dumb, even dumber than I thought at first. Why wouldn't he use my DD account? Why wouldn't he use yours? (I don't have a DD account)

edit again: why do so many people want to downvote in this thread and not tell me why this motherfucker is one of the dumbest criminals ever? There's been a few that want to argue but no one can tell me why he's not a complete idiot.

[–] Filetternavn@lemmy.blahaj.zone 20 points 1 day ago (2 children)

Moot point, as DoorDash driver accounts require a verified driver's license, comprehensive background check, and a valid bank account set up to deposit payment (though after setting up a direct deposit bank account, you can add alternative cash out options). Haven't used DoorDash in a while, but UberEats started requiring facial recognition on top of all that, so I wouldn't be surprised if that were in the DoorDash driver app, too. Hiding IP would do quite literally nothing in this scenario, as you can't create an account anonymously. Counterfeit IDs would not work as they are verified against state records. Oh, and yet another step, you have to provide proof of auto insurance, which is yet another connection to your identity.

[–] rc__buggy@sh.itjust.works 1 points 1 day ago

Hah, yeah what a dumbass

[–] sunzu2@thebrainbin.org 1 points 1 day ago

People still don't understand what KYC'd service and keep giving out their data to these parasitea... Jfc

[–] Kbobabob@lemmy.world 22 points 1 day ago (1 children)

Where did you see that? I didn't see anything in the article or in the linked indictment article.

[–] Rivalarrival@lemmy.today 17 points 1 day ago (3 children)

Did he really just leave his IP wide open? Or did they somehow manage to get through his seven proxies to find him?

I know I'm being paranoid. What I don't know is if I'm being paranoid enough.

[–] Forester@pawb.social 23 points 1 day ago* (last edited 1 day ago) (2 children)

Pro tip if you're going to rob a bank don't use your car as the getaway car. Vinyl wrapping your car doesn't change the fact that it's your car.

[–] console@lemmy.world 14 points 1 day ago (4 children)

do you have any more bank robbing tips, asking for a friend

[–] EightBitBlood@lemmy.world 15 points 1 day ago (1 children)

Reddit had an AMA with a Bank Robber ten years ago that they've since deleted for corpo purity reasons 😂

Here's the big points from it:

  • Banks don't care about losing amounts under 5k.
  • Security won't stop you if you don't have a visible weapon.
  • Worst they do is lock the door, so bring a hammer.
  • the goal is to get in, and get the teller to give you a couple grand asap, then leave under 10 minutes.
  • Guy did this to at least 5 different banks (all different companies) in one day, once a month, for several months.

He eventually got caught because of the money he had, not because his face was on every security camera.

He recommends not doing this, as do I, as it's just not worth it.

But just in case you wanted to know how it was done a decade ago, fuck Reddit, here's the details they recently deleted.

[–] LustyArgonianMana@lemmy.world 11 points 1 day ago* (last edited 1 day ago) (1 children)

Reddit used to have an entire shoplifting subreddit (r/shoplifting for the wayback) that regularly made fun of the loss prevention subreddit and the two subs often stole ideas from each other and would taunt each other. There was obvious sexual tension between them

Ofc it got banned even though it was technically a "roleplay" sub

see, some days I'm happy that I didn't grow up on the Internet and on IRC, and some days (today) I'm sad that I missed these bits of internet history. God I love this so much

[–] Death_Equity@lemmy.world 11 points 1 day ago (1 children)

It is generally advisable to not get caught.

[–] Forester@pawb.social 4 points 1 day ago

Leave the singing to Sinatra

Bicycles don't have license plates 😉

[–] skulblaka@sh.itjust.works 5 points 1 day ago (1 children)

Ok but what if I take it through the Pay-N-Spray after

[–] Forester@pawb.social 4 points 1 day ago

Why would you pay for paint when GTA is free?

[–] flandish@lemmy.world 5 points 1 day ago

i’d go with 8 proxies and a dial up modem on one end just to be safe.

[–] throwawayacc0430@sh.itjust.works 2 points 1 day ago (1 children)

I don't think doordash lets you use a VPN.

Many platforms that deal with finance would reject an order when they detect VPNs or Tor (since that's what fraudsters and scammers use), or they ask for additional verification (like SMS) to verify you are in fact the account holder. So they probably were just using their real IP address.

[–] rc__buggy@sh.itjust.works -4 points 1 day ago (1 children)

Well in this case a proxy isn't a VPN, but an intermediate the criminal has taken control of. A proxy does not have to be legitimate.

[–] AmbiguousProps@lemmy.today 5 points 1 day ago* (last edited 1 day ago)

True, but again, you're making a lot of assumptions here. I don't see anything about proxies anywhere.

He probably got caught because of an internal audit, that's the assumption I would make.