Data leak
Stiiizy Cannabis Retailer POS Provider Breach (380K Customers)
Primary Source βIncident Details
Stiiizy, a major California-based cannabis brand and retailer, disclosed in January 2025 that a breach via its unnamed third-party POS system provider in approximately October 2024 had exposed records for approximately 380,000 customers. Because cannabis retailers are required to verify customer age and identity, the POS system stored particularly sensitive data including customer names, dates of birth, addresses, driver’s licenses, government-issued ID documents, passports, and cannabis purchase cards/medical marijuana cards. The nature of the data β identity documents tied to regulated cannabis purchases β creates unique reputational and safety risks for affected customers.
Technical Details
- Initial Attack Vector
- Threat actors compromised Stiiizy's third-party point-of-sale (POS) system provider, gaining access to customer purchasing records that include highly sensitive government-issued identity documents
Timeline
- 2024-10-01 Breach occurred
- 2025-01-15 Publicly disclosed
- 2025-01-15 Customers notified