https://www.ftc.gov/news-events/news/press-releases/2022/10/ftc-takes-action-against-drizly-its-ceo-james-cory-rellas-security-failures-exposed-data-25-million Skip to main content U.S. flag An official website of the United States government Here's how you know Here's how you know Dot gov The .gov means it's official. Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you're on a federal government site. Https The site is secure. The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely. Translation Menu * Espanol Secondary Menu * Report Fraud * Sign Up for Consumer Alerts * Search the Legal Library Menu close Main Menu Mega * Show/hide Enforcement menu items Enforcement We enforce federal competition and consumer protection laws that prevent anticompetitive, deceptive, and unfair business practices. View Enforcement Search or browse the Legal Library Find legal resources and guidance to understand your business responsibilities and comply with the law. Browse legal resources Search small [ ]Search Sections + Cases and Proceedings + Premerger Notification Program + Merger Review + Anticompetitive Practices + Rulemaking + Statutes + Competition and Consumer Protection Guidance Documents + Warning Letters + Consumer Sentinel Network + Criminal Liaison Unit + Recent FTC Cases Resulting in Refunds + Notices of Penalty Offenses + Competition Matters Blog Take action + Report an antitrust violation + File adjudicative documents + Find banned debt collectors + View competition guidance Competition Matters Blog Competition Matters HSR threshold adjustments and reportability for 2022 the Premerger Notification Office Staff February 11, 2022 View all Competition Matters Blog posts * Show/hide Policy menu items Policy We work to advance government policies that protect consumers and promote competition. View Policy Search or browse the Legal Library Find legal resources and guidance to understand your business responsibilities and comply with the law. Browse legal resources Search small [ ]Search Sections + Advocacy and Research + Advisory Opinions + Cooperation Agreements + Federal Register Notices + Reports + Public Comments + Studies + Testimony + Policy Statements + International Take action + Find policy statements + Submit a public comment Feature [ftc_hq6_400x350] Vision and Priorities Memo from Chair Lina M. Khan to commission staff and commissioners regarding the vision and priorities for the FTC. Learn more Tech@FTC Blog Tech@FTC On FTC's Twitter Case: Enhancing Security Without Compromising Privacy DPIP and CTO Staff May 25, 2022 View all Tech@FTC Blog posts * Show/hide Advice and Guidance menu items Advice and Guidance Learn more about your rights as a consumer and how to spot and avoid scams. Find the resources you need to understand how consumer protection law impacts your business. Take action + Report fraud + Report identity theft + Register for Do Not Call + Sign up for consumer alerts + Get Business Blog updates + Get your free credit report + Find refund cases + Order bulk publications Consumer Advice + Shopping and Donating + Credit, Loans, and Debt + Jobs and Making Money + Unwanted Calls, Emails, and Texts + Identity Theft and Online Security + Scams Business Guidance + Advertising and Marketing + Credit and Finance + Privacy and Security + By Industry + For Small Businesses + Browse Business Guidance Resources + Business Blog Servicemembers: Your tool for financial readiness Visit militaryconsumer.gov Get consumer protection basics, plain and simple Visit consumer.gov Learn how the FTC protects free enterprise and consumers Visit Competition Counts Looking for competition guidance? Competition Guidance * Show/hide News and Events menu items News and Events Latest News Press Release FTC's PrivacyCon 2022 Will Feature Research on Commercial Surveillance, Automated Decision Making October 25, 2022 View News and Events Upcoming Event Oct31 Oral Argument Before the Commission: Intuit, Inc. - October 31, 2022 Monday, October 31, 2022 | 1:00PM - 3:00PM View more Events Sections + News + Events + Features + Topics + Data and Visualizations + Stay Connected Sign up for the latest news Follow us on social media Feature Computer-generated illustration of gray and red coronavirus cell on solid black background Coronavirus Scams Spot the latest COVID scams, get compliance guidance, and stay up to date on FTC actions during the pandemic. Latest Data Visualization COVID-19 Visualization Map Daily COVID-19 Complaint Data Use our visualizations to explore scam and fraud trends in your state based on reports from consumers like you. * Show/hide About the FTC menu items About the FTC Our mission is protecting consumers and competition by preventing anticompetitive, deceptive, and unfair business practices through law enforcement, advocacy, and education without unduly burdening legitimate business activity. Learn more about the FTC Sections + Mission + History + Commissioners and Staff + Bureaus and Offices + Budget and Strategy + Office of Inspector General + Careers at the FTC + Contact Featured Lina M. Khan Meet the Chair Lina M. Khan was sworn in as Chair of the Federal Trade Commission on June 15, 2021. Chair Lina M. Khan * Search Show/hide Search menu items Enter Search Term(s): [ ][Search] Looking for legal documents or records? Search the Legal Library instead. Translation Menu * Espanol Secondary Menu * Report Fraud * Sign Up for Consumer Alerts * Search the Legal Library * Enforcement Show/hide Enforcement menu items + Cases and Proceedings + Premerger Notification Program + Merger Review + Anticompetitive Practices + Rulemaking + Statutes + Competition and Consumer Protection Guidance Documents + Warning Letters + Consumer Sentinel Network + Criminal Liaison Unit + Recent FTC Cases Resulting in Refunds + Notices of Penalty Offenses + Competition Matters Blog * Policy Show/hide Policy menu items + Advocacy and Research + Advisory Opinions + Cooperation Agreements + Federal Register Notices + Reports + Public Comments + Studies + Testimony + Policy Statements + International * Advice and Guidance Show/hide Advice and Guidance menu items + Consumer Advice + Military Consumer + Consumer.gov + Business Guidance + Competition Guidance + Bulk Publications * News and Events Show/hide News and Events menu items + News + Events + Features + Topics + Data and Visualizations + Stay Connected * About the FTC Show/hide About the FTC menu items + Mission + History + Commissioners and Staff + Bureaus and Offices + Budget and Strategy + Office of Inspector General + Careers at the FTC + Contact Enter Search Term(s): [ ][Search] Looking for legal documents or records? Search the Legal Library instead. Breadcrumb 1. Home 2. News and Events 3. News 4. Press Releases For Release FTC Takes Action Against Drizly and its CEO James Cory Rellas for Security Failures that Exposed Data of 2.5 Million Consumers Order requires company to destroy unnecessary data, restricts future data collection and retention, and binds CEO to specific data security requirements October 24, 2022 Tags: * Consumer Protection * Bureau of Consumer Protection * Identity Theft * Alcohol * Privacy and Security * Consumer Privacy * Data Security The Federal Trade Commission is taking action against the online alcohol marketplace Drizly and its CEO James Cory Rellas over allegations that the company's security failures led to a data breach exposing the personal information of about 2.5 million consumers. Drizly and Rellas were alerted to security problems two years prior to the breach yet failed to take steps to protect consumers' data from hackers. The FTC's proposed order requires the company to destroy unnecessary data, restricts the data that the company can collect and retain, and binds Rellas to specific data security requirements for his role in presiding over unlawful business practices. "Our proposed order against Drizly not only restricts what the company can retain and collect going forward but also ensures the CEO faces consequences for the company's carelessness," said Samuel Levine, Director of the FTC's Bureau of Consumer Protection. "CEOs who take shortcuts on security should take note." Boston-based Drizly, a subsidiary of Uber, operates an online marketplace where consumers of legal drinking age can place orders with retailers to buy beer, wine, and alcohol for delivery. The company collects and stores on Amazon Web Services cloud computing service a wide range of personal information from consumers such as email, postal addresses, phone numbers, unique device identifiers, geolocation information and data purchased from third parties. According to the FTC's complaint, Drizly and Rellas were alerted to problems with the company's data security procedures following an earlier security incident. In 2018, a Drizly employee posted company cloud computing account login information on the software development and hosting platform GitHub. As a result of this security breakdown, hackers were able to use Drizly's servers to mine cryptocurrency until the company changed its login information for its cloud computing account. Drizly failed to take steps to adequately address its security problems while publicly claiming to have appropriate security protections in place. Two years later, a hacker breached an employee account, got access to Drizly's corporate GitHub login information, hacked into the company's database, and then stole customers' information. In its complaint, the FTC alleges that Drizly and Rellas: * Failed to implement basic security measures: The FTC alleged that despite statements claiming the company used appropriate security practices to protect consumer data, Drizly and Rellas failed to put in place reasonable safeguards to secure the personal information it collected and stored. It did not require employees to use two-factor authentication for GitHub, limit employee access to personal data, develop adequate written security policies, or train employees on those procedures. * Stored critical database information on an unsecured platform: According to the FTC's complaint, Drizly stored login credentials on GitHub contrary to the platform's own guidance and well-publicized security incidents involving GitHub. For example, in its 2018 complaint against Uber, the FTC specifically publicized and described poor security practices involving the use of Uber's GitHub account that contributed to a data breach involving the ridesharing app. * Neglected to monitor network for security threats: The FTC alleged that Drizly did not put a senior executive in charge of ensuring that the company was keeping its data secure, nor did it monitor its network for unauthorized attempts to access or remove personal data. * Exposed customers to hackers and identity thieves: Following the company's data breach, personal information that Drizly had collected about consumers was offered for sale on two different publicly accessible sites on the dark web, where criminals post and sell data stolen by hackers. Identity thieves and other malicious actors can use such data to open fraudulent lines of credit or commit other fraud. When unauthorized accounts are opened in their name, consumers can suffer financial harm by incurring debt and damaging their credit, the FTC alleged. Enforcement Action The proposed order against Drizly and Rellas includes several requirements aimed at ensuring they take steps to address the problems outlined in the FTC's complaint. Under the proposed FTC order, Drizly and Rellas are required to: * Destroy unnecessary data: Drizly is required to destroy any personal data it collected that is not necessary for it to provide products or services to consumers. It must also document and report to the Commission what data it destroyed. * Limit future data collection: Going forward, Drizly must refrain from collecting or storing personal information unless it is necessary for specific purposes outlined in a retention schedule. It must also must publicly detail on its website the information it collects and why such data collection is necessary. * Implement an information security program: Drizly is required to implement a comprehensive information security program and establish security safeguards to protect against the security incidents outlined in the complaint. This includes measures such as providing security training for its employees; designating a high-level employee to oversee the information security program; implementing controls on who can access personal data; and requiring employees to use multi-factor authentication to access databases and other assets containing consumer data. Notably, the order applies personally to Rellas, who presided over Drizly's lax data security practices as CEO. In the modern economy, corporate executives frequently move from company to company, notwithstanding blemishes on their track record. Recognizing that reality, the Commission's proposed order will follow Rellas even if he leaves Drizly. Specifically, Rellas will be required to implement an information security program at future companies if he moves to a business collecting consumer information from more than 25,000 individuals, and where he is a majority owner, CEO, or senior officer with information security responsibilities. This action is part of the FTC's aggressive efforts to ensure that companies are protecting consumers' data and that careless CEOs learn from their data security failures. Last year, the Commission secured its first order requiring a firm to minimize data collection and has worked in subsequent orders to ensure companies only collect what they need to conduct their business. The Commission is also taking steps to bolster security market-wide, including by finalizing updates to the Safeguards Rule, issuing a policy statement on the Health Breach Notification Rule, and initiating an advance notice of proposed rulemaking on commercial surveillance and lax data security practices. The FTC voted 4-0 to issue the proposed administrative complaint and to accept the consent agreement with Drizly and Rellas. Commissioner Christine Wilson voted yes but dissented in part as to the inclusion of Rellas as an individual defendant and issued a separate statement. Chair Lina M. Khan and Commissioner Alvaro Bedoya issued a joint concurring statement and Commissioner Rebecca Kelly Slaughter issued a separate concurring statement. The FTC will publish a description of the consent agreement package in the Federal Register soon. The agreement will be subject to public comment for 30 days after publication in the Federal Register after which the Commission will decide whether to make the proposed consent order final. Instructions for filing comments will appear in the published notice. Once processed, comments will be posted on Regulations.gov. NOTE: The Commission issues an administrative complaint when it has "reason to believe" that the law has been or is being violated, and it appears to the Commission that a proceeding is in the public interest. When the Commission issues a consent order on a final basis, it carries the force of law with respect to future actions. Each violation of such an order may result in a civil penalty of up to $46,517. The Federal Trade Commission works to promote competition and protect and educate consumers. Learn more about consumer topics at consumer.ftc.gov, or report fraud, scams, and bad business practices at ReportFraud.ftc.gov. Follow the FTC on social media, read consumer alerts and the business blog, and sign up to get the latest FTC news and alerts. Press Release Reference FTC Strengthens Security Safeguards for Consumer Financial Information Following Widespread Data Breaches FTC Warns Health Apps and Connected Device Companies to Comply With Health Breach Notification Rule FTC Explores Rules Cracking Down on Commercial Surveillance and Lax Data Security Practices Contact Information Media Contact Juliana Gruenwald Henderson Office of Public Affairs 202-326-2924 Staff Contacts Jamie Hine Bureau of Consumer Protection 202-326-2188 Elizabeth Averill Bureau of Consumer Protection 202-326-2993 Related Cases Drizly, LLC., In the Matter of Related actions Statement of Chair Lina M. Khan Joined by Commissioner Alvaro M. Bedoya In the Matter of Drizly Concurring and Dissenting Statement of Commissioner Christine S. Wilson in the Matter of Drizly, Inc. Statement of Commissioner Rebecca Kelly Slaughter, In the Matter of Drizly For Consumers Blog: Have you been affected by a data breach? Read on Password Checklist For Businesses Blog: Data security forecast: Drizly with a 100% chance of far-reaching order provisions Data Security Topics Privacy and Security Enforcement Advice for Consumers Data Security Return to top Menu Secondary Menu * Report Fraud * Sign Up for Consumer Alerts * Search the Legal Library Main navigation * Enforcement + Cases and Proceedings + Premerger Notification Program + Merger Review + Anticompetitive Practices + Rulemaking + Statutes + Competition and Consumer Protection Guidance Documents + Warning Letters + Consumer Sentinel Network + Criminal Liaison Unit + Recent FTC Cases Resulting in Refunds + Notices of Penalty Offenses + Competition Matters Blog * Policy + Advocacy and Research + Advisory Opinions + Cooperation Agreements + Federal Register Notices + Reports + Public Comments + Studies + Testimony + Policy Statements + International * Advice and Guidance + Consumer Advice + Military Consumer + Consumer.gov + Business Guidance + Competition Guidance + Bulk Publications * News and Events + News + Events + Features + Topics + Data and Visualizations + Stay Connected * About the FTC + Mission + History + Commissioners and Staff + Bureaus and Offices + Budget and Strategy + Office of Inspector General + Careers at the FTC + Contact Footer * Privacy Policy * Policy and Notices * FOIA * No FEAR Act * Office of Inspector General * USA.gov