Florajet Cyberattack: 1.4 Million Order Details Stolen

Florajet Cyberattack Exposes Personal Messages of Over 1.4 Million Customers

San Francisco, CA – A significant data breach at Florajet, a leading online flower delivery service, has compromised the personal information of over 1.4 million customers, including intimate messages written to accompany floral gifts. The breach, revealed on March 3, 2026, has sparked concerns about privacy and potential risks of phishing, identity theft, and blackmail. While financial data appears to be unaffected, the exposure of personal messages represents a deeply unsettling violation of trust for many users.

The cyberattack targeted an internal B2B tool used by Florajet’s partner florists, according to a company statement. Hackers gained unauthorized access to PDF copies of order confirmations, which contained not only recipient names, addresses, and phone numbers, but also the heartfelt messages customers penned alongside their bouquets. These messages, often containing deeply personal sentiments, are now circulating on dark web forums, specifically BreachForums, a popular marketplace for stolen data. The compromised data covers orders placed between 2023 and 2026, representing a substantial period of vulnerability.

Details of the Breach and Data Exposed

According to reports from Le Figaro and Generation-NT, the stolen data amounts to approximately 136 gigabytes in total. The sheer volume of compromised information underscores the severity of the attack. The data includes the names and addresses of both senders and recipients, along with nearly 952,000 unique phone numbers. However, it is the exposure of the personal messages that has caused the most distress. These messages, intended for a single recipient, are now potentially accessible to a wide range of malicious actors.

Florajet has confirmed the unauthorized access and stated that no banking details or passwords were compromised. However, the potential for misuse of the exposed personal information remains significant. Cybercriminals could leverage the data for targeted phishing campaigns, attempting to extract further sensitive information from affected individuals. The intimate nature of the messages also creates a risk of emotional blackmail or extortion.

What is Florajet and Who is Affected?

Florajet is a prominent player in the French flower delivery market, connecting customers with a network of affiliated florists. The company facilitates the ordering and delivery of bouquets for a wide range of occasions, from birthdays and anniversaries to expressions of sympathy and love. The breach impacts customers who placed orders through Florajet’s platform during the 2023-2026 timeframe. The company has not yet released a comprehensive list of affected individuals, but estimates the number exceeds 1.4 million.

The incident highlights the growing vulnerability of businesses to cyberattacks, even those seemingly focused on traditional services like flower delivery. The increasing reliance on digital platforms for personal transactions creates a larger attack surface for malicious actors, and the consequences of a successful breach can be far-reaching.

Potential Risks and What Customers Should Do

The exposure of personal data in the Florajet breach presents several potential risks for affected customers:

  • Phishing Attacks: Cybercriminals may use the stolen information to craft highly targeted phishing emails or text messages, attempting to trick recipients into revealing further sensitive data, such as login credentials or financial information.
  • Identity Theft: The exposed personal details could be used to commit identity theft, opening fraudulent accounts or making unauthorized purchases.
  • Blackmail and Extortion: The intimate nature of the messages creates a risk of blackmail or extortion, where individuals are threatened with the public disclosure of their private communications.
  • Social Engineering: Attackers could use the information to build trust and manipulate individuals into divulging sensitive information or performing actions that compromise their security.

Florajet has advised customers to remain vigilant and be cautious of any unsolicited communications requesting personal information. Security experts recommend the following steps for affected individuals:

  • Be wary of suspicious emails and text messages: Do not click on links or open attachments from unknown senders.
  • Monitor your financial accounts: Regularly check your bank and credit card statements for any unauthorized activity.
  • Change your passwords: Although passwords were not directly compromised in the breach, it is always a good practice to update your passwords for online accounts.
  • Report any suspicious activity: If you suspect you have been targeted by a phishing attack or identity theft, report it to your local law enforcement agency and relevant consumer protection organizations.

Broader Implications for Data Security

The Florajet data breach is the latest in a series of high-profile cyberattacks targeting businesses of all sizes. It underscores the importance of robust cybersecurity measures, including data encryption, access controls, and regular security audits. Companies must prioritize the protection of customer data and invest in technologies and practices that mitigate the risk of breaches.

The incident also raises questions about the adequacy of data protection regulations and the enforcement of penalties for data breaches. The General Data Protection Regulation (GDPR) in Europe sets strict standards for data privacy and security, but enforcement can be challenging. The Florajet breach may prompt renewed scrutiny of data protection practices and calls for stronger regulatory oversight.

A tweet highlighting the Florajet data breach. (Source: X/Twitter)

What Happens Next?

Florajet has stated it is working with cybersecurity experts to investigate the breach and implement measures to prevent future incidents. The company has also notified relevant data protection authorities. As of March 8, 2026, the full extent of the damage and the long-term consequences of the breach remain to be seen. Customers are advised to monitor official updates from Florajet and remain vigilant against potential threats. Further investigation by law enforcement agencies may reveal the identity of the perpetrators and lead to criminal charges.

The incident serves as a stark reminder of the ever-present threat of cyberattacks and the importance of protecting personal information in the digital age. As consumers increasingly rely on online services, it is crucial for businesses to prioritize data security and transparency.

Have you been affected by the Florajet data breach? Share your experiences and concerns in the comments below.

Leave a Comment