[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3957f7rkqd37j":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":15,"seoTitleEn":29,"seoDescription":15,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":4,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda48825118","blooms-today","Blooms Today Data Breach","bloomstoday.com","2023-11-11T00:00:00.000Z","2024-09-03T07:06:36.000Z","2025-10-08T16:08:32.784Z","2026-07-18T23:44:32.446Z","Third party breach","",[],3184010,"known",null,"unknown","Critical",[23,24,25,26,27],"Email addresses","Names","Partial credit card data","Phone numbers","Physical addresses","\u003Cp>Blooms Today is a retail brand operating as an online flower and gift ordering service, working with data containing customer name, delivery address, and payment context. The incident, which includes the most recent records dated November 2023, affected approximately 3.2 million unique email addresses along with the dataset released for sale in 2024.\u003C\u002Fp>\u003Cp>Since the record contains name-surname, phone, physical address, and partial payment card information, the risk is not limited to email spam alone. Partial fields such as card type, the last four digits, and expiration date are not enough to make a full payment; however, they can make fake refund, order verification, or customer service fraud more convincing.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The data classes collected in Blooms Today should be considered as email addresses, full names, partial payment card information, phone numbers, and physical addresses. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Full name information makes fake support, fake delivery, fake invoice, and customer service messages more convincing. Partial payment card information alone is not sufficient for making purchases, but it can enhance frauds carried out under the pretext of card verification. Phone numbers allow the setup of personalized fraud scenarios via SMS, calls, and messaging apps. Physical addresses can be used in delivery, billing, subscription, and local service-themed social engineering messages.\u003C\u002Fp>\u003Cp>Since flower and gift orders often include delivery address and recipient information, attackers may contact the user under the pretext of a personal order or delivery. Partial card information can be used to create a sense of trust; the user may be asked for the full card number, verification code, or new payment information.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is associated with the domain name bloomstoday.com, customer data extending up to November 2023, and approximately 3.2 million unique email addresses. The full card number or data sufficient to process transactions with the card is not among the verified fields; the description should be limited to partial payment card information.\u003C\u002Fp>\u003Cp>Fields not present in this record should not be described as if they have leaked. Areas such as full card numbers, account passwords, official ID, private messages, device content, or health information should only be included in the risk assessment if they are explicitly present within the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Customers who place orders through Blooms Today, people who use different recipient addresses for gift shipments, users who store their phone and address information in their order accounts, and people who are open to customer service calls that can be persuaded with partial card information are at higher risk.\u003C\u002Fp>\u003Cp>Users who use the same email address across different services, repeat their old passwords, and share their phone and address information across many shopping or community accounts are at higher risk. The connection between a pseudonym and real identity in corporate or community accounts can create additional social engineering risks.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users should check the password repetition on their Blooms Today account and confirm unexpected order, delivery, return, or card verification messages through the official channel. Bank transactions should be monitored; full card information or one-time verification codes should not be shared via any call or email.\u003C\u002Fp>\u003Cp>Users in the positive match area should update their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check recent sessions. Caution should be exercised against unexpected calls, deliveries, returns, support, and verification messages on records containing phone numbers, addresses, payment information, or sensitive community information.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Old addresses, registered phones, and unnecessary payment information in retail accounts should be regularly cleaned. Users should use only the official site or bank application for delivery and payment notifications and should know that partial card information is not proof of real customer service.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is found in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset, and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address appears in Blooms Today customer data. Since this record carries the context of partial payment and delivery, the user should be careful regarding both account password and bank and order security.\u003C\u002Fp>","Blooms Today Data Breach (3.2 Million Reported Records)","Blooms Today Data Breach. 3.2 Million reported records were reported. Reported data: Email addresses, Names, Partial credit card data. Review the scope…","\u002Fuploads\u002Flogo\u002Fbloomstoday_com.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Blooms Today","Online Florist \u002F Retail","United States"]