DoorDash followers were served a bit of a harrowing blog post Thursday.

The food delivery service alerted people to “unusual activity involving a third-party service provider” resulting in unauthorized third-party access to user data. While any number of companies have been through this drill before, this latest data incident serves as a reminder that not only do companies need to mind their own cyber-security—they also need to keep an eye on the data protection practices of their third-party vendors.