[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2sf6pe0tqvu7p":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda48825192","drizly","Drizly Data Breach","drizly.com","2020-07-02T00:00:00.000Z","2020-07-28T21:45:05.000Z","2026-07-29T11:40:53.262Z","Config exposure","https:\u002F\u002Fwww.ftc.gov\u002Fnews-events\u002Fnews\u002Fpress-releases\u002F2022\u002F10\u002Fftc-takes-action-against-drizly-its-ceo-james-cory-rellas-security-failures-exposed-data-25-million",[14,16,17],"https:\u002F\u002Fwww.ftc.gov\u002Fsystem\u002Ffiles\u002Fftc_gov\u002Fpdf\u002F2023185-Drizly-Complaint.pdf","https:\u002F\u002Fwww.axios.com\u002F2022\u002F10\u002F24\u002Fftc-drizly-ceo-privacy-violations-data-breach",2479044,"known",null,"unknown","Critical",[24,25,26,27,28,29,30,31,32],"Dates of birth","Device information","Email addresses","IP addresses","Names","Hashed passwords","Passwords","Phone numbers","Physical addresses","\u003Cp>The Drizly data breach is a customer data incident experienced by the US-based online alcoholic beverage ordering platform in July 2020. The record contains 2,479,044 unique email addresses. Publicly available regulatory documents and breach records indicate that the incident was based on access to the customer database through abuse of cloud access credentials in an employee-sourced developer account. The verified data fields include birth dates, device information, email addresses, IP addresses, names, phone numbers, physical addresses, and bcrypt password hashes. Therefore, the Drizly data breach should be considered highly significant both in terms of account security and the privacy of address and age information.\u003C\u002Fp>\n\u003Cp>Although the Drizly service was later acquired by Uber and shut down as an independent app in 2024, the data from the 2020 breach may still pose a risk. Old customer records can combine a person's age, address, phone number, device and network information, and email account. The password field was reported in bcrypt hash form rather than plain text; this protection reduces risk but does not make password reuse completely safe. In this record, credit card numbers, bank accounts, or official ID numbers are not in the verified data class. The focus of the risk is customer profile, address privacy, phishing, and reused passwords.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>The types of data verified in a Drizly account are birth dates, device information, email addresses, IP addresses, names, phone numbers, physical addresses, and bcrypt password hashes. Birth date and address information make a person's identity profile stronger. When phone and email are together, fake support, delivery, age verification, or account update messages may appear more convincing. IP address and device information can provide additional clues about the user's approximate network context and the type of device they are using.\u003C\u002Fp>\n\u003Cp>The fact that password hashes are protected with bcrypt is a better situation compared to plaintext password leaks. Nevertheless, the risk persists for weak, short, or reused passwords. If the same email and password were used on other shopping, delivery, email, or social accounts, attackers might try this combination. Being an alcoholic beverage ordering service also increases the privacy dimension; the user's age, address, and consumption context could provide a basis for more targeted messages. Therefore, the Drizly data breach should be evaluated not only in terms of password changes but also in terms of communication and address security.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified incident belongs to the July 2020 period and is associated with 2,479,044 unique email addresses. In different sources, approximately 2.5 million customers may be mentioned; this rounded expression is consistent with the number of unique emails in the record. Regulatory documents also address Drizly's previous security vulnerabilities and deficiencies related to employee account security. This information provides technical context; however, the main risk to be shown to the user is the verified customer data fields and the potential for misuse of these fields.\u003C\u002Fp>\n\u003Cp>It is important not to expand the scope. In this record, the full credit card number, bank account, official ID number, order content, or plain text password are not shown as verified data classes. Password risk is interpreted through bcrypt hashing. Drizly's later closure does not negate the impact of the 2020 data; because fields like email, phone, date of birth, and address may not change for a long time. This record is limited to Drizly's 2020 customer data incident; it should not be confused with other services of Uber or later separate incidents.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group is made up of customers who created a Drizly account or ordered alcoholic beverages through Drizly before 2020. People who use the same email address for other delivery, grocery, shopping, or email accounts can be more easily targeted. Date of birth and address information can make fraud messages appear personalized for the individual. For users with a phone number, fake delivery, age verification, account update, or promotion calls can be expected.\u003C\u002Fp>\n\u003Cp>Users who reuse the same password across different services are also at risk. While bcrypt hash protection makes it difficult to immediately read the password, the risk of attempts continues for old and weak passwords. Even if Drizly is no longer used as an independent service, your old Drizly password may still persist in your email account, Uber account, delivery platforms, or other store accounts. Fields that do not change, such as physical address and date of birth, can be used in personalized phishing messages even years after the incident.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>If the password used on the Drizly account is still being used elsewhere, it should be changed immediately. If the same or a similar password has been used for email, shopping, delivery, payment-linked accounts, or the Uber account, a unique password should be assigned for each. The email account should be protected with two-factor authentication. If access to the old Drizly account is not possible, other accounts linked with the same email address should be checked and any suspicious sessions should be closed.\u003C\u002Fp>\n\u003Cp>Attention should be paid to delivery, age verification, membership update, or campaign messages received via phone and email. Even if the person's date of birth, address, or phone number appears correctly in the message, the message should not be considered reliable. Instead of clicking on links, the address of the relevant service should be opened directly. Requests asking for card numbers, one-time codes, banking information, or passwords should be rejected. Even if financial data is not verified in this record, leaked personal information can be used later to trick someone into giving financial information.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In the long term, the address, phone number, and date of birth information kept in delivery and retail accounts should be reviewed regularly. Unused accounts should be closed, outdated addresses should be deleted, and separate addresses should be preferred for campaign accounts instead of the main email. A password manager makes it easier to check whether an old Drizly password remains on other accounts. Since physical address and date of birth are information that does not change, personalized messages associated with this information should be handled carefully even years later.\u003C\u002Fp>\n\u003Cp>On the corporate side, the Drizly incident shows that developer accounts and cloud access information can pose a direct risk to the customer database. The principle of least privilege, regular rotation of access keys, strong authentication on employee accounts, unusual data access alerts, and deletion of unnecessary customer data are critical measures. Regulatory decisions regarding Drizly also emphasize the importance of data minimization and personal responsibility. When customer data is stored minimally, the impact domain is also reduced in the event of a breach.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>If you see a match in this record, your email address may be among the 2,479,044 unique emails associated with the Drizly data breach. A match does not mean that your full card number or plain-text password was leaked. However, it indicates that fields such as date of birth, address, phone number, device information, IP address, and bcrypt password hash pose a security risk. The first step is to check whether the password you used during the Drizly period is being used on other accounts.\u003C\u002Fp>\n\u003Cp>Even if Drizly is no longer an independent app, leaked data can still be effective through old email, phone, and address information. Be careful with messages regarding delivery, age verification, account updates, or campaign-themed messages. The fact that the information contains details about you does not make the message trustworthy. Secure your relevant email account, delivery accounts, and payment-linked accounts. The correct approach to the Drizly data breach is not to see it as old records from a service that has closed; it is to accept that long-lasting personal data fields can still be used in social engineering.\u003C\u002Fp>","","Drizly Data Breach (2.5 Million Reported Records)","Drizly Data Breach. 2.5 Million reported records were reported. Reported data: Dates of birth, Device information, Email addresses. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fdrizly_com.webp",false,{"name":40,"sector":41,"country":42,"website":9,"websiteArchiveUrl":43,"websiteStatus":44,"websiteCheckedAt":45},"Drizly","Retail","United States","https:\u002F\u002Fweb.archive.org\u002Fweb\u002F20250114232943\u002Fhttps:\u002F\u002Fdrizly.com\u002F","archived","2026-07-29T11:30:22.391Z"]