CASE DOSSIER settled

FTC v. Drizly, LLC & CEO James Cory Rellas (Personal Liability Consent Order)

Docket: FTC File No. 202-3185 Court: Federal Trade Commission Administrative Proceedings Opened: 2022-10-24 Sector: E-Commerce & Food Delivery

Key Facts

Status
SETTLED
Legal disposition
Loss Amount
$15.0 million
Administrative compliance costs, corporate acquisition re-evaluations, and mandatory data deletion.
Techniques
1
Verified mappings
Defendants
0
Named in charges
  • Legal Status: SETTLED in Federal Trade Commission Administrative Proceedings.
  • Primary Target Sector: E-Commerce & Food Delivery.
  • Documented Financial Loss: $15.0 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Landmark Federal Trade Commission administrative enforcement action where the FTC held alcohol delivery marketplace Drizly and its CEO individually accountable for lax cybersecurity practices that exposed 2.5 million consumer records, requiring the CEO personally to implement comprehensive security programs at any company he leads for ten years.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against E-Commerce & Food Delivery networks. Landmark Federal Trade Commission administrative enforcement action where the FTC held alcohol delivery marketplace Drizly and its CEO individually accountable for lax cybersecurity practices that exposed 2.5 million consumer records, requiring the CEO personally to implement comprehensive security programs at any company he leads for ten years.

Operational & Financial Fallout

Administrative compliance costs, corporate acquisition re-evaluations, and mandatory data deletion. Impacted E-Commerce & Food Delivery infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SETTLED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against E-Commerce & Food Delivery networks. Landmark Federal Trade Commission administrative enforcement action where the FTC held alcohol delivery marketplace Drizly and its CEO individually accountable for lax cybersecurity practices that exposed 2.5 million consumer records, requiring the CEO personally to implement comprehensive security programs at any company he leads for ten years.

Adversary Kill Chain Flow

1 Documented Phases
1
Phase 1: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

An employee used their corporate GitHub account for personal projects, storing unencrypted AWS database credentials in a public GitHub repository.

Artifacts & Tooling: T1078 Valid Accounts
Real-World Blast Radius & Operational Fallout

Administrative compliance costs, corporate acquisition re-evaluations, and mandatory data deletion. Impacted E-Commerce & Food Delivery infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2020-07-13 incident

Hacker accesses Drizly AWS environment and exfiltrates customer database.

2023-01-10 consent

FTC finalizes consent order binding both corporate entity and CEO personally across future corporate roles.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"An employee used their corporate GitHub account for personal projects, storing unencrypted AWS database credentials in a public GitHub repository." FTC Complaint ¶ 11, Page 4 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, FTC v. Drizly, LLC & CEO James Cory Rellas (Personal Liability Consent Order), No. FTC File No. 202-3185 (Federal Trade Commission Administrative Proceedings 2022), https://cybercaselibrary.com/cases/drizly-ftc-consent-order/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/drizly-ftc-consent-order" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>