{
  "id": "case-drizly-ftc-consent",
  "slug": "drizly-ftc-consent-order",
  "title": "FTC v. Drizly, LLC & CEO James Cory Rellas (Personal Liability Consent Order)",
  "summary": "Landmark Federal Trade Commission administrative enforcement action where the FTC held alcohol delivery marketplace Drizly and its CEO individually accountable for lax cybersecurity practices that exposed 2.5 million consumer records, requiring the CEO personally to implement comprehensive security programs at any company he leads for ten years.",
  "case_number": "FTC File No. 202-3185",
  "court": "Federal Trade Commission Administrative Proceedings",
  "district": "FTC Bureau of Consumer Protection",
  "country": "United States",
  "opened_at": "2022-10-24",
  "status": "settled",
  "victim_sector": "E-Commerce & Food Delivery",
  "victim_country": "United States",
  "loss_amount_usd": 15000000,
  "loss_amount_note": "Administrative compliance costs, corporate acquisition re-evaluations, and mandatory data deletion.",
  "first_seen_at": "2020-04-01T00:00:00Z",
  "last_updated_at": "2026-10-09T10:00:00Z",
  "actor_slug": "unattributed-cybercrime",
  "defendant_slugs": [
    "james-cory-rellas"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "An employee used their corporate GitHub account for personal projects, storing unencrypted AWS database credentials in a public GitHub repository.",
      "evidence_locator": "FTC Complaint \u00b6 11, Page 4",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "FTC Administrative Complaint in the Matter of Drizly, LLC",
      "source_url": "https://www.ftc.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2020-07-13",
      "description": "Hacker accesses Drizly AWS environment and exfiltrates customer database."
    },
    {
      "event_type": "consent",
      "event_date": "2023-01-10",
      "description": "FTC finalizes consent order binding both corporate entity and CEO personally across future corporate roles."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against E-Commerce & Food Delivery networks. Landmark Federal Trade Commission administrative enforcement action where the FTC held alcohol delivery marketplace Drizly and its CEO individually accountable for lax cybersecurity practices that exposed 2.5 million consumer records, requiring the CEO personally to implement comprehensive security programs at any company he leads for ten years.",
    "blast_radius": "Administrative compliance costs, corporate acquisition re-evaluations, and mandatory data deletion. Impacted E-Commerce & Food Delivery infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "An employee used their corporate GitHub account for personal projects, storing unencrypted AWS database credentials in a public GitHub repository.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}