Drizly
Disclosed Jul 28, 20206 years ago2,500,000 affectedSettled
2020 breach exposed 2.5M customers; FTC order binding company and CEO
After a Drizly employee had posted cloud login credentials on GitHub in 2018, a 2020 intrusion exposed data of about 2.5 million consumers. The FTC's 2022 order required Drizly to destroy unneeded data and limit collection, and personally bound CEO James Cory Rellas to security requirements.
What is known
| People affected | 2,500,000 (as reported by the organization) |
|---|---|
| Disclosed | Jul 28, 2020 |
| Happened | Jul 2, 2020 |
| Attack | Hacking |
| Data exposed | Dates of birth, Emails, IP addresses, Names, Passwords, Phone numbers, Addresses |
| Sector | Retail · US |
| Status | Settled |
| Lawsuit or fine | FTC consent order against Drizly and CEO (Oct 2022, finalized Jan 2023); no monetary penalty |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| Have I Been Pwned: Drizlyhaveibeenpwned.com · Aggregator | Aggregator |
| Drizly (Wikipedia)en.wikipedia.org · News | News |
| FTC Takes Action Against Drizly and its CEOftc.gov · Regulator | Regulator |
Notices filed
| Where | Filed | People |
|---|---|---|
| Have I Been Pwnedaccounts in the data | Jul 28, 2020 | 2,479,044 |
| Researchtotal | Jul 28, 2020 | 2,500,000 |
History of this record
- 2026-09-25 · source_type: aggregator to regulator · seed source
- 2026-09-25 · source_url: https://haveibeenpwned.com/Breach/Drizly to https://www.ftc.gov/news-events/news/press-releases/2022/10/ftc-takes-action-against-drizly-its-ceo-james-cory-rellas-security-failures-exposed-data-25-million · seed source
- 2026-09-25 · status: disclosed to settled · seed source
- 2026-09-25 · verified_by: empty to research · seed source
- 2026-09-25 · verified: 0 to 1 · seed source
- 2026-09-25 · lawsuit: empty to FTC consent order against Drizly and CEO (Oct 2022, finalized Jan 2023); no monetary penalty · seed source
- 2026-09-25 · country: empty to US · seed source
- 2026-09-25 · sector: tech to retail · seed source
- 2026-09-25 · attack: unknown to hacking · seed source
- 2026-09-25 · records_basis: hibp to organization · seed source
- 2026-09-25 · records: 2479044 to 2500000 · seed source
- 2026-09-25 · summary: In approximately July 2020, the US-based online alcohol delivery service Drizly suffered a data breach . The data was sold online before being extensively redistributed and contained 2.5 million unique email addresses alongside names, physi to After a Drizly employee had posted cloud login credentials on GitHub in 2018, a 2020 intrusion exposed data of about 2.5 million consumers. The FTC's 2022 order required Drizly to destroy unneeded data and limit collection, and personally b · seed source
- 2026-09-25 · title: empty to 2020 breach exposed 2.5M customers; FTC order binding company and CEO · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Have I Been Pwned), confirmed by Research. Record counts are as reported. Not legal advice.