FTC v. Drizly, LLC & CEO James Cory Rellas (Personal Liability Consent Order)
Key Facts
- Legal Status: SETTLED in Federal Trade Commission Administrative Proceedings.
- Primary Target Sector: E-Commerce & Food Delivery.
- Documented Financial Loss: $15.0 million.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against E-Commerce & Food Delivery networks. Landmark Federal Trade Commission administrative enforcement action where the FTC held alcohol delivery marketplace Drizly and its CEO individually accountable for lax cybersecurity practices that exposed 2.5 million consumer records, requiring the CEO personally to implement comprehensive security programs at any company he leads for ten years.
Operational & Financial Fallout
Administrative compliance costs, corporate acquisition re-evaluations, and mandatory data deletion. Impacted E-Commerce & Food Delivery infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against E-Commerce & Food Delivery networks. Landmark Federal Trade Commission administrative enforcement action where the FTC held alcohol delivery marketplace Drizly and its CEO individually accountable for lax cybersecurity practices that exposed 2.5 million consumer records, requiring the CEO personally to implement comprehensive security programs at any company he leads for ten years.
Adversary Kill Chain Flow
1 Documented PhasesAn employee used their corporate GitHub account for personal projects, storing unencrypted AWS database credentials in a public GitHub repository.
Administrative compliance costs, corporate acquisition re-evaluations, and mandatory data deletion. Impacted E-Commerce & Food Delivery infrastructure and associated victim operations.
Procedural & Incident Timeline
Hacker accesses Drizly AWS environment and exfiltrates customer database.
FTC finalizes consent order binding both corporate entity and CEO personally across future corporate roles.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "An employee used their corporate GitHub account for personal projects, storing unencrypted AWS database credentials in a public GitHub repository." | FTC Complaint ¶ 11, Page 4 | reviewed |