LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Drizly Data Breach (2020)

CRITICAL severityConfirmedHow we verify

Drizly Data Breach (2020): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 2, 2020

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Drizly Data Breach (2020)

Reported July 2, 2020. Approximately 2.5M people affected.

CRITICAL
Severity
2.5M
People affected
8
Data types exposed
July 2, 2020
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Drizly Data Breach (2020) (reported July 2, 2020) exposed Dates of birth, Device information, Email addresses and IP addresses belonging to roughly 2.5M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
CRITICAL severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Drizly Data Breach (2020) breach?
2.5M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In July 2020, the online alcohol delivery service Drizly reported a data breach that exposed records for 2.5 million individuals. The incident involved names, email addresses, physical addresses, phone numbers, dates of birth, IP addresses, device information, and passwords stored as bcrypt hashes. The data later appeared for sale and was redistributed online, with the collection later supplied to Have I Been Pwned. The exposure placed personal contact details and account credentials in circulation at a time when many users relied on the platform for routine purchases. Because the records included dates of birth and physical addresses alongside login information, the breach created conditions for targeted follow-on activity such as account testing or unwanted contact.

Inside the incident

The breach was publicly noted on 2 July 2020. It affected an estimated 2.5 million unique email addresses belonging to users of the Drizly service. The data set also contained names, physical addresses, phone numbers, dates of birth, IP addresses, device information, and passwords stored as bcrypt hashes. Reports indicate the material was sold online and later redistributed before portions reached public breach repositories through dehashed.com.

Public records do not disclose the precise date or method of initial access, the duration of unauthorised presence, or the full scope of systems examined. No official statement from Drizly on the root cause has been referenced in the available reporting.

How a breach like this happens

Incidents involving customer databases at online service providers often begin with the compromise of an internet-facing application, a misconfigured server, or credentials obtained from a separate breach. Once inside, an attacker may locate stored user records, export them, and attempt to monetise the collection through underground markets. Passwords protected only by hashing remain at risk of offline cracking attempts if the hashes are obtained.

After initial sale or sharing, the same data set frequently circulates among multiple parties, increasing the chance that it will eventually surface in public breach archives. The absence of Reported Details on initial access in this case leaves the exact sequence unestablished.

Drizly and its sector

Drizly operates as a platform that connects customers with licensed retailers for alcohol delivery in the United States. Services of this type routinely collect account registration data, delivery addresses, and payment-related identifiers to complete orders and comply with age-verification rules. The combination of identity details and delivery information is therefore inherent to the business model.

A breach at such a company is consequential because the records directly link individuals to transactions that involve regulated products and physical locations. This linkage can extend the utility of the data beyond simple marketing lists.

What was likely exposed

The reported data types include dates of birth, device information, email addresses, IP addresses, names, passwords stored as bcrypt hashes, phone numbers, and physical addresses. These categories were present in the collection that reached public breach databases. The exact contents of every record remain unconfirmed beyond the summary descriptions provided with the data set.

Organisations in this sector commonly hold additional fields such as order histories or partial payment tokens, yet no evidence confirms whether those fields were included here.

The real-world impact

Individuals whose records were exposed face the possibility of increased spam, phishing attempts, and attempts to test the bcrypt-hashed passwords against other accounts. The presence of dates of birth and physical addresses alongside contact details can support more targeted social-engineering efforts.

For the organisation, the incident adds to the operational costs of breach response, potential regulatory scrutiny, and loss of customer trust. The redistribution of the data increases the duration over which these risks remain active.

Were you affected?

Users can check whether their email address appears in known breach data by running a free exposure scan through established breach-notification services. If a match is found, the recommended first steps are to change the Drizly password and any other account that reuses it, enable multi-factor authentication where available, and monitor statements and credit reports for unusual activity.

Organisations that held the data have not published a public list of affected individuals, so personal verification through breach-search tools remains the most direct method available.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyDrizly security record
73/100
DoxxScan™ · Moderate doxx risk
C- 64Below-average record

1 reported incident on record.

See Drizly’s full breach history →

More recent breaches

MEO Data Breach (2020)December 24, 2020NetGalley Data Breach (2020)December 21, 2020MMG Fusion Data Breach (2020)December 20, 2020DriveSure Data Breach (2020)December 19, 2020

Latest breaches

Read GalaxyWarden’s full analysis of the Drizly Data Breach (2020) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram