Brigette Honaker  |  August 11, 2020

Category: Data Breach

Top Class Actions’s website and social media posts use affiliate links. If you make a purchase using such links, we may receive a commission, but it will not result in any additional charges to you. Please review our Affiliate Link Disclosure for more information.

Assorted bottles of liquor and beer - Drizly alcohol delivery

 

A recent Drizly alcohol delivery class action lawsuit calls the company “oblivious” and negligent in relation to a data breach that occurred earlier this year.

According to plaintiff James Barr, 2.5 million accounts with Drizly’s alcohol delivery service were affected by a data breach that began in February. However, despite the data breach happening months earlier, Barr argues that he and other Drizzly alcohol delivery customers were not told of the breach for five months.

“As a result of Drizly’s failure to maintain reasonable security measures and protocols, Plaintiff and Class members were not provided adequate notice that their sensitive customer information was compromised for at least five months and were unable to take steps to proactively mitigate the harm caused by the Data Breach,” the Drizly alcohol delivery service class action lawsuit contends.

Late last month, Drizly alcohol delivery announced the data breach in an email to customers. According to the company’s email, a hacker accessed customer information without authorization – getting ahold of customer email addresses, dates of birth, passwords, and even delivery addresses associated with accounts.

Although 2.5 million accounts were reportedly affected by the data breach, Drizly notes that no payment information was stolen and delivery addresses were only compromised for under 2% of the records.

“Hashed passwords were taken, though we use BCrypt, an industry favored hashing algorithm, to encrypt the passwords,” Drizly alcohol delivery representative said in a statement to Forbes. “Because of the encryption, Drizly accounts should not be able to be accessed, though to be cautious we’ve encouraged users to nonetheless change their passwords.”

However, verification from Tech Crunch shows that Drizly’s optimistic outlook may not be accurate.

The company reportedly found that phone numbers, IP addresses and geolocation data from user accounts were also found in some of the obtained data. Additionally, the tech news company reportedly found that dark web listings posted in mid-February included credit card information and order history.

Barr argues that the “oblivious” Drizly alcohol delivery company mishandled the data breach both before and after the incident.

Wine bottles in a row in a wine rack - Drizly alcohol delivery

Before the data breach, Barr contends that Drizly should have better protected their customers’ data from unauthorized hackers.

The Drizly alcohol delivery class action lawsuit notes that data breaches are becoming increasingly common – meaning that the company should have been aware that they had a duty to protect customer data from criminals.

Additionally, Barr challenges how Drizly handled the data breach after the fact.

According to the plaintiff, Drizly should have informed consumers immediately after learning of the breach. Because the company failed to do so, Barr and other users were allegedly denied valuable time which could have been used to mitigate the risks surrounding the data breach.

Now, customers will reportedly be faced with fraud threats that “will persist for years,” forcing users “to vigilantly monitor their financial accounts ad infinitum.” Part of this threat reportedly stems from information listings on the dark web – the underground of “black market” part of the internet where criminals may sell illegally obtained information.

The Drizly alcohol delivery class action lawsuit also claims that the company should have offered customers credit monitoring and identity theft insurance – common remedies offered to affected customers following a data breach.

“Drizly has taken no affirmative steps — beyond notifying consumers of the data breach — to protect against these broad-based types of identity theft and fraud, such as offering free credit monitoring and identity theft insurance to all customers whose sensitive customer data was stolen in the data breach,” the Drizly alcohol delivery class action lawsuit alleges.

“Drizly’s efforts are wholly insufficient to combat the indefinite and undeniable risk of identity theft and fraud.”

Barr seeks a variety of relief from the court, including an order which would require Drizly to better protect customer security and provide credit monitoring to affected consumers.

Additionally, the Drizly alcohol delivery data breach class action seeks damages from the company that would compensate Barr and others for the injuries they may have sustained due to the data breach.

Were you affected by the Drizly alcohol delivery data breach? Share your experiences in the comment section below.

Barr and the proposed Class are represented by Jason M. Leviton and Jacob A. Walker of Block & Leviton LLP; Christian Levis, Amanda Fiorilla and Anthony M. Christina of Lowey Dannenberg PC; and Gary Lynch and Jamisen A. Etzel of Carlson Lynch LLP.

The Drizly Alcohol Delivery Data Breach Class Action Lawsuit is Barr v. Drizly LLC f/k/a Drizly Inc., et al., Case No. 1:20-cv-11492, in the U.S. District Court for the District of Massachusetts.

We tell you about cash you can claim EVERY WEEK! Sign up for our free newsletter.


51 thoughts onDrizly Class Action Lawsuit Says Alcohol Delivery Service Reported Breach 5 Months Late

  1. joseph dunwoody says:

    I was data breach on August 5,2020 by drizly my Email name date of birth and phone number thank you.

  2. FD says:

    The most egregious part of this by Drizzly is their lack of communication to their customers about the breach and no apology whatsever. That, coupled with the release of some personally identifying information is absolutely criminal. Data protection isn’t hard. Personally, had attempts at someone using my information. Folks: careless companies like Drizzly is why you should put a credit freeze on your bureaus and be vigilant in regularly updating your passwords.

  3. David Lussiano says:

    Add me to that list

  4. ANITA TEMPLE says:

    Please add me to this lawsuit, I to was sent a email asking for personal information to sign in to make a account. I was afraid to do that because my bank information was being used and I kept having to change cc’s .Not cool at all.

  5. John Censullo says:

    My identity was taken accounts opened closed reopened. Lexington law id protect i have and credit karma its on that my identity was taken and breeches what do I do next

  6. Theresa Damon says:

    Please add me also!!!

  7. Mushtaq N Al azzawi says:

    Yes OMG I was using Drizly when my account was hacked

  8. Eileen Reed says:

    Add me please!
    I, like many other commenters, am uneasy about entering my info on the website alcoholdeliverydatabreach.com
    Something raises my radar about the website and I am unsure whether it’s legit.

  9. Julian Evans says:

    Can anybody confirm if the email from is legit? ALCOHOL DELIVERY DATA BREACH SETTLEMENT
    I’m reluctant to provide them with my details. Please add me to the CA suit

  10. HASNA says:

    Please add me. I’ve been a customer since 2016 or 2017 and I’ve moved since. I know that it may be too late now, but I just removed my payment information from my account after seeing this notice. Thank you!

1 3 4 5

Leave a Reply

Your email address will not be published. By submitting your comment and contact information, you agree to receive marketing emails from Top Class Actions regarding this and/or similar lawsuits or settlements, and/or to be contacted by an attorney or law firm to discuss the details of your potential case at no charge to you if you qualify. Required fields are marked *

Please note: Top Class Actions is not a settlement administrator or law firm. Top Class Actions is a legal news source that reports on class action lawsuits, class action settlements, drug injury lawsuits and product liability lawsuits. Top Class Actions does not process claims and we cannot advise you on the status of any class action settlement claim. You must contact the settlement administrator or your attorney for any updates regarding your claim status, claim form or questions about when payments are expected to be mailed out.