Skip to content

Drizly

Disclosed Jul 28, 20206 years ago2,500,000 affectedSettled

Official notice

2020 breach exposed 2.5M customers; FTC order binding company and CEO

After a Drizly employee had posted cloud login credentials on GitHub in 2018, a 2020 intrusion exposed data of about 2.5 million consumers. The FTC's 2022 order required Drizly to destroy unneeded data and limit collection, and personally bound CEO James Cory Rellas to security requirements.

What is known

People affected2,500,000 (as reported by the organization)
DisclosedJul 28, 2020
HappenedJul 2, 2020
AttackHacking
Data exposedDates of birth, Emails, IP addresses, Names, Passwords, Phone numbers, Addresses
SectorRetail · US
StatusSettled
Lawsuit or fineFTC consent order against Drizly and CEO (Oct 2022, finalized Jan 2023); no monetary penalty
Check your emailHave I Been Pwned

Sources

Source
Have I Been Pwned: Drizlyhaveibeenpwned.com · Aggregator
Drizly (Wikipedia)en.wikipedia.org · News
FTC Takes Action Against Drizly and its CEOftc.gov · Regulator

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataJul 28, 20202,479,044
ResearchtotalJul 28, 20202,500,000
History of this record
  • 2026-09-25 · source_type: aggregator to regulator · seed source
  • 2026-09-25 · source_url: https://haveibeenpwned.com/Breach/Drizly to https://www.ftc.gov/news-events/news/press-releases/2022/10/ftc-takes-action-against-drizly-its-ceo-james-cory-rellas-security-failures-exposed-data-25-million · seed source
  • 2026-09-25 · status: disclosed to settled · seed source
  • 2026-09-25 · verified_by: empty to research · seed source
  • 2026-09-25 · verified: 0 to 1 · seed source
  • 2026-09-25 · lawsuit: empty to FTC consent order against Drizly and CEO (Oct 2022, finalized Jan 2023); no monetary penalty · seed source
  • 2026-09-25 · country: empty to US · seed source
  • 2026-09-25 · sector: tech to retail · seed source
  • 2026-09-25 · attack: unknown to hacking · seed source
  • 2026-09-25 · records_basis: hibp to organization · seed source
  • 2026-09-25 · records: 2479044 to 2500000 · seed source
  • 2026-09-25 · summary: In approximately July 2020, the US-based online alcohol delivery service Drizly suffered a data breach . The data was sold online before being extensively redistributed and contained 2.5 million unique email addresses alongside names, physi to After a Drizly employee had posted cloud login credentials on GitHub in 2018, a 2020 intrusion exposed data of about 2.5 million consumers. The FTC's 2022 order required Drizly to destroy unneeded data and limit collection, and personally b · seed source
  • 2026-09-25 · title: empty to 2020 breach exposed 2.5M customers; FTC order binding company and CEO · seed source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Have I Been Pwned), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Drizly

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.