CRITICAL SEVERITYRetail

Blooms Today Data Breach

Blooms Today Online Florist Breach (2023): 3.2 Million Customer Records Including Partial Credit Card & Home Address Exposed

Online flower delivery service.

Verified by ObscureIQ Intelligence

8.0Severity
3.2MRecords
5Fields
2023Year

ObscureIQ Breach Intelligence Scores
6.3
Breach Risk Index
18
Data Value
25
Market Recency
601
days
Since Breach

Risk Interpretation

Exposure enables phishing, order fraud, delivery impersonation, and relationship-based targeting. Gift and recipient data may also reveal intimate or family relationships.

🎯 Impact & Downstream Threats

In April 2024 approximately 15 million records from Blooms Today were listed for sale on a hacking forum, with the most recent data in the corpus dating to November 2023. The exposed dataset contained 3.2 million unique email addresses alongside names, phone numbers, physical addresses, and partial credit card data — card type, last four digits, and expiration date. Blooms Today has not made prominent public statements about this breach. No class-action litigation or regulatory action specific t

Primary downstream threats:
  • Financial fraud using exposed financial profile data
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure

🔓 Threat Vectors

Card-present & card-not-present fraud
Card identification & social engineering
Phishing, credential stuffing & account takeover
Name-based social engineering
SIM swapping, vishing & SMS phishing
Physical stalking, mail fraud & identity verification

📋 Breach Intelligence

EntityBlooms Today
OrganizationPrivate Company • USA
Breach Date2023-11-01
HIBP Added2024-09-03
Records~3.2M (3,200,000 records)
Attack VectorUnknown
Data SubjectsCustomer: Direct
Breach PathwayDirect
SourceHave I Been Pwned / ObscureIQ
SensitivityStandard
Breach ID202.0
StatusConfirmed

📝 Executive Summary

Blooms Today, a U.S. online flower and gift delivery service, suffered a data breach affecting 3.2 million customers. In April 2024, approximately 15 million records from the company appeared for sale on a hacking forum. The most recent data in that set dated to November 2023. The method of the breach has not been publicly disclosed. The exposed data included customer names, email addresses, phone numbers, physical addresses, and partial credit card details. The card data consisted of card type, the last four digits of the card number, and the expiration date. While this is not enough to make fraudulent purchases, the combination of personal and address data creates real risk. Attackers can use it to craft convincing phishing emails, impersonate delivery services, or target customers based on gifting patterns. Because Blooms Today handles occasion-based gifts, the data may also reveal personal relationships, including family members and romantic partners. Blooms Today did not respond to press inquiries about the incident. No class-action lawsuits or regulatory actions tied to this breach have been publicly documented. Affected individuals should be alert to phishing attempts that reference past orders or deliveries, and should treat any unsolicited contact claiming to be from a florist or courier service with caution.

🏢 About Blooms Today

Blooms Today is an online flower and gift delivery service operating in the United States, offering floral arrangements, gift baskets, and occasion-based gifting products for home delivery. The company operates primarily through its e-commerce platform and competes in the direct-to-consumer floral delivery market alongside 1-800-Flowers and Teleflora.

Platform | Flower delivery services | E-commerce fulfillment network | USA
Private CompanyUSAbloomstoday.com

🗂 Why They Hold Your Data

Flower-delivery platforms collect customer identity, addresses, gift-order history, recipient details, payment-adjacent records, and delivery information across e-commerce fulfillment operations.

📰 Recent Developments

Blooms Today continues to operate as an online floral and gift retailer. No major organizational changes have been publicly reported in the period surrounding the breach.

🔍 Data Points Exposed

5 verified field types:
Email
Names
Partial credit card data
Phone numbers
Physical addresses

Exposure Categories

LocationPHYS ADDR
FinancialCCARD PARTIAL

Canonical Fields

credit_card:partial, email_address, full_name, phone_number, physical_address

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~3.2M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: Blooms Today Data Breach

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of Blooms Today
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

EmailPhoneAddressFinancial Data

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom