logo

STIIIZY data breach exposes cannabis buyers’ IDs and purchases

ID: 49048a41-3b31-5133-a533-afa204919024

STIX ID: report--49048a41-3b31-5133-a533-afa204919024

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-01-10

Date Updated: 2026-03-27

Author: Lawrence Abrams

...
...

STIIIZY disclosed a data breach stemming from a compromise of its point-of-sale vendor between Oct 10–Nov 10, 2024 (vendor notified STIIIZY on Nov 20); attackers exfiltrated sensitive customer PII—government IDs (drivers' licenses, passport numbers, photos), medical cannabis cards, signatures, and transaction histories—and the Everest ransomware gang claimed the incident and posted sample data, while STIIIZY said the impact was limited to purchases at four specific store locations and will offer affected customers credit monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.