The U.S. Federal Trade Commission took action against alcohol delivery company Drizly and its CEO, James Cory Rellas, over security failures that exposed personal data belonging to about 2.5 million consumers. The agency said the company failed to implement basic safeguards, allowing an attacker to access a company GitHub account and use credentials stored there to reach Drizly's cloud environment, where customer information was compromised.
Under the proposed order, Drizly must destroy unnecessary personal data, limit future collection and retention, and establish a comprehensive information security program with outside assessments. The FTC also imposed obligations on Rellas that would follow him to future companies, requiring him to ensure any business he leads implements strong security controls if it collects personal information from more than 25,000 people.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
The U.S. Federal Trade Commission announced a proposed order against Drizly and its CEO James Cory Rellas over alleged security failures tied to the breach. The order included requirements to destroy unnecessary personal data, implement stronger security controls, and imposed obligations on Rellas for future companies he leads.
Drizly experienced a security incident that exposed the personal information of about 2.5 million consumers. The FTC later said the breach stemmed from security failures including inadequate access controls and poor data retention practices.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
archive.ph
Open sourceftc.gov
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.