NetFlorist has been South Africa's oldest active e-commerce platform since it accidentally launched on Valentine's Day in 1999. Twenty-seven years of orders. Millions of customers. Flowers, hampers, jewellery, personalised gifts delivered same-day across the country.
And for a stretch of time this year, anyone with a browser and a bit of curiosity could have read through the entire customer database.
MyBroadband reported this week that a NetFlorist customer discovered two unsecured API endpoints. One returned user profiles. The other returned the address book. Both handed back private customer information to anyone who asked. No login required. No authentication check.
The endpoints used sequential integers as identifiers. That means moving from one record to the next was as simple as changing a number in the URL from 1001 to 1002 to 1003. Indefinitely. Anyone with basic scripting knowledge could automate that in an afternoon.
The exposed data included full names, usernames, email addresses, telephone numbers, gender, and physical addresses. That part is already serious. The address book exposure is worse. That endpoint did not only return information about registered NetFlorist customers. It also returned the details of people who received deliveries from NetFlorist. People who may have never signed up for anything. People who gave no consent to the platform. People whose details were collected only because someone sent them flowers.
This type of vulnerability has a name. Insecure Direct Object Reference, or IDOR. It sits at the top of OWASP's list of broken access control flaws because it is so common, and so entirely preventable. The fix is to check that the person making the request is actually authorised to view the record they are requesting. That is day-one web security. The fact that a platform of NetFlorist's age and scale was running unauthenticated, sequentially enumerable API endpoints in 2026 is the part that should sit uncomfortably with everyone reading this.
What the managing director said about the NetFlorist data breach
The customer who found the flaw disclosed it to NetFlorist on 30 April. When MyBroadband contacted managing director Ryan Bacher for comment, his initial response was that there was no vulnerability. His security team, he said, had checked and found the endpoints "restricted" with no outside access.
MyBroadband confirmed independently that the endpoints were still live and still returning private data at the time of publication. Bacher then updated his position. His security team would be "adding an extra layer of security on those links at the end of next week as an extra precaution." Not immediately. Next week. As a precaution. Despite being shown the actual data leaking out.
His team's advice to him was that there were "no impending vulnerabilities via this route."
That advice was wrong. Whether the cause is training, communication, or something else entirely is for NetFlorist to answer.
Why this NetFlorist data leak is dangerous for customers
This is not a case where a password hash leaked and the damage is abstract. The data exposed here, names, phone numbers, email addresses, home addresses, is exactly what a spear phishing campaign runs on.
Spear phishing is targeted. It is not the spray-and-pray scam email that lands in your junk folder. It uses specific information about you to make the approach convincing. Your name. Your delivery address. Maybe a reference to the gift someone recently sent you. The platform that sent the flowers becomes the hook.
South African banking fraud losses hit R3.9 billion in 2025, up 23% from the year before, with phishing the single largest contributor. The data sitting in those NetFlorist endpoints is the raw material that fuels exactly that kind of fraud.
The address book exposure makes it worse. Non-customers, the people who received gifts, had no opportunity to consent to their data being processed. They had no way to know it was sitting in an enumerable API. Under POPIA, a person who receives a delivery is still a data subject. Their information must be protected. Condition 7 of POPIA requires responsible parties to put in place reasonable technical and organisational safeguards. An unauthenticated endpoint returning records by sequential ID is not a reasonable safeguard.
What POPIA section 22 requires after a breach like this
A NetFlorist customer filed a formal complaint with the Information Regulator of South Africa, the body that enforces POPIA, over the exposed data. When MyBroadband asked Bacher whether NetFlorist intended to notify the Regulator themselves, he had not replied by the time of publication.
That is a problem. Under section 22 of POPIA, where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the responsible party must notify the Information Regulator as soon as reasonably possible after discovering the compromise. There is no minimum size threshold. There is no "but we do not think anyone actually exploited it" exception. POPIA does not have a materiality threshold. Even a single confirmed or suspected unauthorised access triggers the obligation.
The Information Regulator has previously conducted a POPIA compliance assessment on NetFlorist. They are already on the radar. For a plain-language walkthrough of section 22 timelines and what counts as a notifiable breach, see our POPIA data breach notification guide.
What NetFlorist customers should do right now
If you have ever placed an order on NetFlorist, or received a delivery from someone who did, your details may have been exposed.
- Be suspicious of any message that references a NetFlorist order, delivery, or account, even if the details feel specific and correct. That specificity may come from the leak.
- Do not click links in emails or SMSes that claim to be from NetFlorist, courier companies, or payment processors without verifying through the official site directly.
- If you receive a call that mentions personal details you only shared with NetFlorist, treat it as a potential social engineering attempt. Hang up and call the company back on a number you find independently.
- If you believe your information has been misused, lodge a complaint with the Information Regulator at inforegulator.org.za.
What this NetFlorist case means for every other SA e-commerce business
NetFlorist has been running for 27 years. The accidental origin story, launched as a Valentine's Day experiment in 1999 and never intended to become a business, is genuinely one of the better SA tech founding stories. None of that changes what happened here. The vulnerability was preventable. The initial denial made things worse. The timeline for a fix was not treated with the urgency the situation called for.
The data of customers and innocent third-party recipients sat open on the internet. That is the fact that matters.
If you run an e-commerce platform, a customer portal, an API, or any application that exposes customer records over the web, this is the moment to ask the question NetFlorist's team apparently did not ask in time. Can someone reach a record they should not be able to see, simply by changing a number in a URL? If you do not know the answer, you are due for a web application security assessment. Book one at /services/cybersecurity-assessment/.
Reach us at [email protected].
Sources
- MyBroadband: Reporting on NetFlorist API exposure (Published: May 2026)
- OWASP: Top 10: Broken Access Control and IDOR (Accessed: 2026)
- Information Regulator South Africa: POPIA Section 22 Breach Notification Guidance (Published: 2024-2026)
- SABRIC: 2025 Annual Crime Statistics (Published: 2026)
- South African Government: Protection of Personal Information Act 4 of 2013 (Published: 2013)
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za