HackingRetail & ConsumerRetailStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedTargetedPIIIDENTITY_BASICIDENTITY_GOVERNMENTBIOMETRICBEHAVIORMediumContained
Stiiizy Inc
bd_3408bc4c56c5ec17 · schema v1 · pii pii-v1
Full breach record for Stiiizy Inc →Stiiizy Inc. (cannabis dispensary) reported a breach affecting 212 Maine residents (380,000 total). Oct 10–Nov 10, 2024: an organized cybercrime group compromised a third-party POS vendor serving CA retail locations. Data exposed: names, addresses, DOB, driver's license/passport numbers, photos, signatures, medical cannabis cards, transaction histories. Notified Jan 8, 2025; 12-month credit monitoring offered via Cyberscout/TransUnion.
Maine clockDiscovered Nov 20, 2024 → Filed with AG Jan 9, 202550d ⏱ ME AG >30d7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by everest about this victim predates this filing by 45 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_3d72d8f2b6dda778Leak Siteeverestfiled 2024-11-24(45d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_99313b432eacb90bCalifornia State AGfiled 2025-01-08(1d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/b106a1e2-b6d3-48f8-828a-a578bfff5582.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 9, 2025
- Raw hash
- b366256cbb5d600fb14b926bbbc561cfbf7c544261ab530289e4facd2a5fa5b6
Reporting entity
- Name
- Stiiizy Incnorm: stiiizy
- Domain
- stiiizy.com
- Industry
- Cannabis retail dispensary
Victim entity
- Name
- Stiiizy Incnorm: stiiizy
- Domain
- stiiizy.com
- Industry
- Cannabis retail dispensary
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Nov 20, 2024
- Materiality determined
- —
- Notification sent
- Jan 8, 2025
- Affected individuals
- 212
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTBIOMETRICBEHAVIOR
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- ME AG >30d · 50dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Nov 20, 2024→ Filed with AG: Jan 9, 202550d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.