Data leak

Stiiizy Cannabis Retailer POS Provider Breach (380K Customers)

πŸ“… 2024-10-01
Primary Source β†—

Incident Details

Stiiizy, a major California-based cannabis brand and retailer, disclosed in January 2025 that a breach via its unnamed third-party POS system provider in approximately October 2024 had exposed records for approximately 380,000 customers. Because cannabis retailers are required to verify customer age and identity, the POS system stored particularly sensitive data including customer names, dates of birth, addresses, driver’s licenses, government-issued ID documents, passports, and cannabis purchase cards/medical marijuana cards. The nature of the data β€” identity documents tied to regulated cannabis purchases β€” creates unique reputational and safety risks for affected customers.

Technical Details

Initial Attack Vector
Threat actors compromised Stiiizy's third-party point-of-sale (POS) system provider, gaining access to customer purchasing records that include highly sensitive government-issued identity documents

Timeline

  1. 2024-10-01 Breach occurred
  2. 2025-01-15 Publicly disclosed
  3. 2025-01-15 Customers notified