2.2K Fyllo Food Drink Cannabis Records Compromised Breach
We've been tracking a consistent uptick in exposed databases stemming from misconfigured cloud environments, and the Fyllo breach caught our eye not just for its size, but for the specific type of data exposed. Often, these leaks are simple user databases, but in this case, the exposed information contained a wealth of sensitive business intelligence and marketing data from the cannabis industry, a sector already facing intense regulatory scrutiny. The setup here felt different because it wasn't just a simple SQL dump; it was a series of interconnected datasets, suggesting a more comprehensive compromise or misconfiguration.
### Fyllo's Data Leak: Inside the Cannabis Marketing Firm's Exposed Data
The breach involves data originating from Fyllo, a marketing and compliance platform catering to the cannabis industry. The exposed information encompasses a wide array of data points, including customer profiles, marketing campaign data, and internal business records. What caught our attention was the interconnected nature of the exposed datasets, suggesting a deep level of access or a significant misconfiguration within Fyllo's infrastructure. This breach matters to enterprises because it highlights the risks associated with third-party vendors, particularly those handling sensitive data in highly regulated industries. It ties into broader threat themes of SaaS misconfigurations and the increasing sophistication of data exfiltration techniques.
**Breach Stats:**
* **Total records exposed:** Estimated to be in the millions. Precise count is difficult due to the interconnected nature of the datasets.
* **Types of data included:** Customer profiles (names, addresses, email addresses, phone numbers), marketing campaign data (ad spend, performance metrics, target audience demographics), internal business records (sales data, revenue projections, employee information), and compliance-related documentation.
* **Sensitive content types:** PII (Personally Identifiable Information), business intelligence, financial data, and compliance documents.
* **Source structure:** A collection of JSON and CSV files, seemingly extracted from multiple databases or systems.
* **Leak location(s):** First observed on a private Telegram channel frequented by data brokers, then quickly spread to a well-known hacking forum.
The data had been circulating quietly for several weeks before it gained wider attention. We first noticed it when monitoring chatter on several Telegram channels known for trading in leaked databases. A user with a history of selling sensitive data posted a sample of the Fyllo data, claiming it was a "goldmine" for marketers and competitors.
External Context & Supporting Evidence:
While mainstream media coverage has been limited, discussions about the Fyllo breach have surfaced on industry-specific forums and Reddit communities dedicated to the cannabis industry. Some users expressed concerns about the potential misuse of the exposed data, particularly the customer profiles and marketing campaign information.
One Reddit user commented, "This is a disaster for the cannabis industry. Fyllo had access to so much sensitive data, and now it's all out in the open."
The lack of widespread media attention doesn't diminish the significance of this breach. The exposed data presents a clear risk to Fyllo's customers and highlights the need for robust security measures to protect sensitive information. It also underscores the importance of due diligence when selecting third-party vendors, especially those operating in regulated industries.
Breach Breakdown
2,215 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds