LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › drizly.com Listed by apt73 Ransomware Group

HIGH severityUnverified claimHow we verify

drizly.com Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·October 17, 2024
drizly.com Listed by apt73 Ransomware Group

Reported October 17, 2024.

HIGH
Severity
October 17, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Drizly.com was listed by the apt73 ransomware group on October 17, 2024, with internal files reportedly exfiltrated from the organization. An undisclosed number of people may have been affected; users should check for breach notices from Drizly and consider updating passwords or monitoring their accounts.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who have used Drizly, the alcohol delivery service, may now face questions about whether their personal details sit in the hands of a ransomware group. On October 17, 2024, the group known as apt73 listed drizly.com on its leak site, claiming it had taken internal files and user databases from the e-commerce platform. The number of people affected remains unknown, yet the listing itself raises immediate practical concerns for anyone whose account, purchase history, or identifying information could be among the material the group says it holds.

Public detail is limited to the group's claim and a brief description of the data. No independent confirmation of the intrusion's success, the full scope of files taken, or any ransom demand has been released in the available record. For users, the stakes are concrete: personal data once trusted to an online retailer can be reused for fraud, phishing, or identity misuse if it has left the company's control.

Breaking down the breach

According to the reported listing, apt73 claims to have conducted a ransomware attack against drizly.com that resulted in the exfiltration of internal files. The group describes the material as databases of users of the e-commerce platform Drizly, a service for the sale of alcoholic beverages. The listing cites 2,479,145 lines of data and mentions dates of birth along with device information, though the description cuts off and does not provide a complete inventory.

The date the listing appeared is October 17, 2024. No further timeline—when the intrusion began, how long the attackers remained inside the network, or whether systems were encrypted—has been disclosed in the public facts. The number of individuals whose records may be involved is listed as unknown. Method of initial access, any ransom amount, and whether the company has acknowledged the incident are likewise undisclosed. The only concrete assertions available are those made by the group on its leak site; they remain unverified claims rather than confirmed findings.

Inside apt73

apt73 is a ransomware group that operates by infiltrating corporate networks, exfiltrating data, and then listing victims on a dedicated leak site if payment is not made or if the group chooses to publicize the theft. Like other actors in this category, it typically advertises stolen material to pressure victims and to attract buyers or further attention. Public reporting on the group has associated it with opportunistic targeting of organizations that hold customer databases, often in retail and service sectors.

In this instance the group claims it obtained internal files and user databases from Drizly. No additional statements from apt73 about this specific victim—such as screenshots, sample records beyond the line count, or technical details of the intrusion—appear in the available facts. The listing itself is therefore treated as an unverified claim. Established patterns of the group include posting partial data descriptions to demonstrate possession, then threatening full release; whether that sequence will follow here is not yet known.

Who is drizly.com?

Drizly is an online platform that connects customers with local liquor stores for the delivery of beer, wine, and spirits. It functions as an e-commerce intermediary: users create accounts, provide delivery addresses, payment details, and often dates of birth to verify legal age, then place orders fulfilled by partner retailers. The service has operated primarily in the United States and has been part of larger corporate structures in recent years.

Organizations of this type routinely hold customer names, email addresses, phone numbers, physical addresses, dates of birth, device identifiers, order histories, and payment-related information. Because alcohol sales require age verification, date-of-birth data is especially common. A breach involving such a platform is consequential precisely because the data set combines identity elements with location and purchasing habits—information that can be valuable for fraud or social engineering. The listing by apt73 therefore places a service that many people have used for everyday transactions under scrutiny.

The information in question

The facts name the exposed material as internal files exfiltrated in a ransomware attack. The group's description specifies databases of Drizly users totaling 2,479,145 lines and references dates of birth and device information. Beyond those points the exact contents remain unconfirmed; the public record does not list every field, nor does it state whether payment card numbers, passwords, or full addresses were included.

E-commerce platforms that sell age-restricted goods typically store account credentials, contact details, shipping addresses, birth dates for compliance, device fingerprints for fraud prevention, and transaction logs. It is reasonable to expect that some combination of these categories could be present, yet the precise inventory for this incident has not been independently verified. Readers should treat the line count and partial field list as claims made by the group rather than as audited findings.

What's at stake

For individuals, the primary risks are identity-related. Dates of birth paired with other personal details can support account takeovers, synthetic identity creation, or targeted phishing that appears legitimate because it references real purchase history. Device information may help attackers craft more convincing messages or bypass certain security checks. Even if financial data is absent, the combination of identity and location data can enable harassment or further scams.

For the organization, the stakes include operational disruption, regulatory scrutiny, customer trust erosion, and potential legal exposure under data-protection rules. Ransomware incidents often force companies to investigate, notify affected parties, and strengthen defenses—costs that extend well beyond any ransom demand. Because the number of people affected is unknown, the full scale of notification and remediation work cannot yet be measured. The incident also underscores the broader exposure of consumer platforms that collect sensitive personal attributes as a condition of service.

Were you affected?

If you have ever created an account or placed an order through Drizly, treat the possibility of exposure seriously until more definitive information appears. Begin by changing any password you reused on the platform, enabling multi-factor authentication on related email and financial accounts, and monitoring bank and credit statements for unusual activity. Consider placing a fraud alert with the major credit bureaus if you believe your date of birth and other identifiers may have been involved.

You can also run a free exposure scan of your email address to check whether it has already appeared in known breach data sets. Stay alert for unsolicited messages that reference alcohol orders or personal details; such messages may be phishing attempts that exploit the publicity around this listing. Official updates, if any, will come from the company itself or from regulatory notices rather than from the ransomware group's site.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companydrizly.com security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See drizly.com’s full breach history →

More recent breaches

liftkits4less.com Listed by apt73 Ransomware GroupNovember 8, 2024mgfsourcing.com Listed by apt73 Ransomware GroupOctober 23, 2024www.trifecta.com Listed by apt73 Ransomware GroupApril 5, 2024westernint.com Listed by apt73 Ransomware GroupJuly 6, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the drizly.com Listed by apt73 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by apt73 — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram