HackingSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICBEHAVIORMediumContained
Stiiizy Inc
bd_99313b432eacb90b · schema v1 · pii pii-v1
Full breach record for Stiiizy Inc →Stiiizy Inc. notified customers of a data breach involving a third-party point-of-sale vendor. An organized cybercrime group compromised the vendor's accounts, acquiring personal information of Stiiizy customers between October 10 and November 10, 2024. Stiiizy was notified on November 20, 2024. Affected data includes government-issued ID details (driver's licenses, passports), medical cannabis cards, and transaction histories. Stiiizy is offering 12 months of free credit monitoring.
Leak gap clock⏱ Leak >30d7 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_3d72d8f2b6dda778Leak Siteeverestfiled 2024-11-24(44d gap)Verified
Regulatory filings (1) · sorted by filing gap
- bd_3408bc4c56c5ec17Maine State AGfiled 2025-01-09(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-597121
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 8, 2025
- Raw hash
- 3c23e09d2aa146c85ff5baf3645adac3dd2f1b81097170cfbd865e77430b6cf7
Reporting entity
- Name
- Stiiizy Incnorm: stiiizy
- Domain
- stiiizy.com
Victim entity
- Name
- Stiiizy Incnorm: stiiizy
- Domain
- stiiizy.com
Incident
- Discovered
- Nov 20, 2024
- Materiality determined
- —
- Notification sent
- Jan 8, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICBEHAVIOR
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Vendor of point-of-sale processing services
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- Leak >30dCA 60-day OK · 49d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 20, 2024→ Notified: Jan 8, 202549d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.