Netflorist hit by major customer data security flaw

South Africa’s oldest online gifting retailer, NetFlorist, has been hit by a critical security vulnerability that exposed sensitive customer information online.

According to a report by MyBroadband, unsecured API endpoints on the platform allowed access to private user information, including full names, usernames, email addresses, cellphone numbers, genders, and physical addresses.

The flaw reportedly stemmed from API endpoints using sequential numerical IDs, making it possible for anyone to scrape customer information simply by increasing the identifier number.

Customer and recipient data exposed

The vulnerability extended beyond registered users, with address book data also reportedly accessible. This means personal details belonging to gift recipients — many of whom may never have signed up with Netflorist — could also be viewed online.

Cybersecurity experts have warned that exposed personal information can be used in targeted phishing and fraud attacks, commonly known as spear phishing.

The report cited Visa and Discovery Bank’s SpendTrend26 South African Consumer Survey, which found that 41% of respondents experienced phishing attempts through email or SMS during 2025.

Netflorist reportedly alerted before publication

MyBroadband said it was first alerted to the issue by a Netflorist customer who allegedly discovered the vulnerable API endpoints and disclosed the matter to the company on 30 April.

Netflorist managing director Ryan Bacher reportedly said the company took the report seriously but maintained there was no exploitable vulnerability in its systems.

Bacher told the publication that Netflorist’s security team had reviewed the issue and believed the endpoints were restricted and not accessible externally.

However, MyBroadband said it independently verified that the endpoints remained publicly accessible at the time of publication and that customer data could still be viewed.

POPIA complaint reportedly filed

The customer who identified the flaw has reportedly lodged a formal complaint with South Africa’s Information Regulator under the Protection of Personal Information Act (POPIA).

Bacher also reportedly said Netflorist’s security team planned to add “an extra layer of security” to the affected links by the end of next week, although he maintained there was no immediate threat.

At the time of publication, Netflorist had reportedly not confirmed whether it intended notifying the Information Regulator about the potential exposure of customer data.

Read about Netflorist

Share the Post:

Read More

Top 16 YOBA

The Top 16 Youth-Owned Brands Awards announce new categories

Brands on The Rise

Brands on The Rise – Embedded

Business

2023 Reflections: My Top 5 Business Lessons

Trevor Noah

Business

Spotify is set to debut a fresh, original podcast featuring Trevor Noah on Thursday, November 9th.

Technology

Green Scooter Is Moving At Electric Pace

Lifestyle

Krispy Kreme Teams Up with Nestle

Trends

Lerato Agency Celebrates 2nd Anniversary

Technology

A new online bartering platform, CirculateIt launches in South Africa

Lifestyle, Trends

KFC’s Kentucky Town Warms Up Cape Town This Winter

Lifestyle, Trends

Outfits That Brought the Honey From the Durban July

Lifestyle, Top 16 YOBA

MTN Pulse Helps MDU Cleaning Services with R50 000 To Help Rebuild Store

Top 16 YOBA

Pat On Brands donates R5 000 to a youth-owned cleaning service company in Soweto

Lifestyle, Top 16 YOBA, Uncategorized

Siwela Wines crowned the Top Beverage Brand – Sponsored by Black Crown

Lifestyle, Trends

Nando’s Brings Exciting #PeriTricks to The Heart of Braam

Top 16 YOBA

Tshepo Jeans crowned the Overall Top Brand at the inaugural Top 16 Youth-Owned Brands Awards

Top 16 YOBA trophy

Top 16 YOBA

Winners of the inaugural Top 16 Youth-Owned Brands Awards announced

Technology, Top 16 YOBA

MTN Pulse becomes the official category sponsor of the inaugural Top 16 Youth-Owned Brands Awards

Top 16 YOBA

Kgotso Pati Designs the 1st Top 16 Youth-Owned Brands Awards Trophy

Lifestyle, Top 16 YOBA, Trends

Pat On Brands Announce Executive Judges For The Inaugural Top 16 Youth-Owned Brands Awards.

Lifestyle, Trends

Black Crown expands into Gin & Dry Lemon with Marula

Lifestyle

Over Half A Million Rand In Tips Raised For Bar Staff Over Workers’ Day Weekend

Thebe Ikalafeng

Lifestyle, Trends

Brand Africa endorses the inaugural Top 16 Youth-Owned Brands Awards

Lifestyle, Trends

Comedians Stuck in a Flying Fish Billboard on William Nicol Drive

Lifestyle, Trends

Y launches a thrilling drama series, called Tequila AF, exclusively on the YFM app

Brand News

Checkers fixes Xtra Savings surname bug

Brand News

WhatsApp to Drop Support for Older Android Phones

Brand Collabs

Tropika Blends Culture and Flavour in a New Collab with Dr Esther Mahlangu

Suzuki Dzire

Motoring

2026 Suzuki Dzire Review: A Smart Sedan That Understands the South African Buyer