NetFlorist Data Breach: How South Africa's Oldest Online Store Left Customer Records Open

By Ubuntu Guard Cyber | 10 May 2026

NetFlorist has been South Africa's oldest active e-commerce platform since it accidentally launched on Valentine's Day in 1999. Twenty-seven years of orders. Millions of customers. Flowers, hampers, jewellery, personalised gifts delivered same-day across the country.

And for a stretch of time this year, anyone with a browser and a bit of curiosity could have read through the entire customer database.

MyBroadband reported this week that a NetFlorist customer discovered two unsecured API endpoints. One returned user profiles. The other returned the address book. Both handed back private customer information to anyone who asked. No login required. No authentication check.

The endpoints used sequential integers as identifiers. That means moving from one record to the next was as simple as changing a number in the URL from 1001 to 1002 to 1003. Indefinitely. Anyone with basic scripting knowledge could automate that in an afternoon.

The exposed data included full names, usernames, email addresses, telephone numbers, gender, and physical addresses. That part is already serious. The address book exposure is worse. That endpoint did not only return information about registered NetFlorist customers. It also returned the details of people who received deliveries from NetFlorist. People who may have never signed up for anything. People who gave no consent to the platform. People whose details were collected only because someone sent them flowers.

This type of vulnerability has a name. Insecure Direct Object Reference, or IDOR. It sits at the top of OWASP's list of broken access control flaws because it is so common, and so entirely preventable. The fix is to check that the person making the request is actually authorised to view the record they are requesting. That is day-one web security. The fact that a platform of NetFlorist's age and scale was running unauthenticated, sequentially enumerable API endpoints in 2026 is the part that should sit uncomfortably with everyone reading this.

What the managing director said about the NetFlorist data breach

The customer who found the flaw disclosed it to NetFlorist on 30 April. When MyBroadband contacted managing director Ryan Bacher for comment, his initial response was that there was no vulnerability. His security team, he said, had checked and found the endpoints "restricted" with no outside access.

MyBroadband confirmed independently that the endpoints were still live and still returning private data at the time of publication. Bacher then updated his position. His security team would be "adding an extra layer of security on those links at the end of next week as an extra precaution." Not immediately. Next week. As a precaution. Despite being shown the actual data leaking out.

His team's advice to him was that there were "no impending vulnerabilities via this route."

That advice was wrong. Whether the cause is training, communication, or something else entirely is for NetFlorist to answer.

Why this NetFlorist data leak is dangerous for customers

This is not a case where a password hash leaked and the damage is abstract. The data exposed here, names, phone numbers, email addresses, home addresses, is exactly what a spear phishing campaign runs on.

Spear phishing is targeted. It is not the spray-and-pray scam email that lands in your junk folder. It uses specific information about you to make the approach convincing. Your name. Your delivery address. Maybe a reference to the gift someone recently sent you. The platform that sent the flowers becomes the hook.

South African banking fraud losses hit R3.9 billion in 2025, up 23% from the year before, with phishing the single largest contributor. The data sitting in those NetFlorist endpoints is the raw material that fuels exactly that kind of fraud.

The address book exposure makes it worse. Non-customers, the people who received gifts, had no opportunity to consent to their data being processed. They had no way to know it was sitting in an enumerable API. Under POPIA, a person who receives a delivery is still a data subject. Their information must be protected. Condition 7 of POPIA requires responsible parties to put in place reasonable technical and organisational safeguards. An unauthenticated endpoint returning records by sequential ID is not a reasonable safeguard.

What POPIA section 22 requires after a breach like this

A NetFlorist customer filed a formal complaint with the Information Regulator of South Africa, the body that enforces POPIA, over the exposed data. When MyBroadband asked Bacher whether NetFlorist intended to notify the Regulator themselves, he had not replied by the time of publication.

That is a problem. Under section 22 of POPIA, where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, the responsible party must notify the Information Regulator as soon as reasonably possible after discovering the compromise. There is no minimum size threshold. There is no "but we do not think anyone actually exploited it" exception. POPIA does not have a materiality threshold. Even a single confirmed or suspected unauthorised access triggers the obligation.

The Information Regulator has previously conducted a POPIA compliance assessment on NetFlorist. They are already on the radar. For a plain-language walkthrough of section 22 timelines and what counts as a notifiable breach, see our POPIA data breach notification guide.

What NetFlorist customers should do right now

If you have ever placed an order on NetFlorist, or received a delivery from someone who did, your details may have been exposed.

What this NetFlorist case means for every other SA e-commerce business

NetFlorist has been running for 27 years. The accidental origin story, launched as a Valentine's Day experiment in 1999 and never intended to become a business, is genuinely one of the better SA tech founding stories. None of that changes what happened here. The vulnerability was preventable. The initial denial made things worse. The timeline for a fix was not treated with the urgency the situation called for.

The data of customers and innocent third-party recipients sat open on the internet. That is the fact that matters.

If you run an e-commerce platform, a customer portal, an API, or any application that exposes customer records over the web, this is the moment to ask the question NetFlorist's team apparently did not ask in time. Can someone reach a record they should not be able to see, simply by changing a number in a URL? If you do not know the answer, you are due for a web application security assessment. Book one at /services/cybersecurity-assessment/.

Reach us at [email protected].

Sources


© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za

Could a stranger read your customer database?

Ubuntu Guard's cybersecurity assessment finds the IDOR flaws, broken access controls, and exposed APIs before someone else does. Book yours today.

Book a Cybersecurity Assessment

Questions? Reach us at [email protected]