2026 Florajet — 1.4M orders, intimate messages exposed
Data compromised
Recipient names, addresses, phone numbers, personal messages
Technical writeup
Florajet discovered unauthorized access to its B2B tool on March 3, 2026. Exposed 1.4M customer orders (2023-2026), ~136 GB. Recipient names, delivery addresses, phone numbers, and personal messages written by senders. No banking data or passwords. Intimate message context (birth announcements, condolences) creates high risk for phishing, identity theft, social engineering, harassment.
Root cause
Unauthorized access to B2B tool