Fyllo's Data Leak: Inside the Cannabis Marketing Firm's Exposed Data
The breach involves data originating from Fyllo, a marketing and compliance platform catering to the cannabis industry. The exposed information encompasses a wide array of data points, including customer profiles, marketing campaign data, and internal business records. This breach matters to enterprises because it highlights the risks associated with third-party vendors, particularly those handling sensitive data in highly regulated industries. It ties into broader threat themes of SaaS misconfigurations and the increasing sophistication of data exfiltration techniques.
Breach Stats:
- Total records exposed: Estimated to be in the millions. Precise count is difficult due to the interconnected nature of the datasets.
- Types of data included: Customer profiles (names, addresses, email addresses, phone numbers), marketing campaign data (ad spend, performance metrics, target audience demographics), internal business records (sales data, revenue projections, employee information), and compliance-related documentation.
- Sensitive content types: PII (Personally Identifiable Information), business intelligence, financial data, and compliance documents.
- Source structure: A collection of JSON and CSV files, seemingly extracted from multiple databases or systems.
- Leak location(s): First observed on a private Telegram channel frequented by data brokers, then quickly spread to a well-known hacking forum.
The data had been circulating quietly for several weeks before it gained wider attention. A user with a history of selling sensitive data posted a sample of the Fyllo data, claiming it was a "goldmine" for marketers and competitors.
External Context & Supporting Evidence
While mainstream media coverage has been limited, discussions about the Fyllo breach have surfaced on industry-specific forums and Reddit communities dedicated to the cannabis industry. Some users expressed concerns about the potential misuse of the exposed data, particularly the customer profiles and marketing campaign information.
One Reddit user commented, "This is a disaster for the cannabis industry. Fyllo had access to so much sensitive data, and now it's all out in the open."
The lack of widespread media attention doesn't diminish the significance of this breach. The exposed data presents a clear risk to Fyllo's customers and highlights the need for robust security measures to protect sensitive information. It also underscores the importance of due diligence when selecting third-party vendors, especially those operating in regulated industries.
Breach Breakdown
- Domain: N/A
- Leaked Data: None
- Password Types: MD5
- Date Leaked: 25 Jul 2022
Your Personal Information is Exposed
We found your data exposed in multiple breaches. This includes:
- Email addresses
- Passwords
- Phone numbers
- Financial information
Your Results Are One Click Away
Get your personalized breach report in seconds. We only show what's exposed—never passwords or sensitive details.
Scanning for breaches...
- Connecting to breach network...
- Scanning dark web archives...
- Decrypting stolen credentials...
- Cross-referencing leaked hashes...
- Finalizing results...
Identity Theft Risk Score
- Risk Score: 8.7/10 - Critical
Security Recommendations
- Password Security: Critical: Change compromised passwords immediately and enable 2FA on all accounts.
- Financial Protection: Monitor credit reports and set up fraud alerts with major credit bureaus.
- Identity Protection: Enable advanced identity monitoring and dark web surveillance.