Cybersecurity

Cannabis company Stiiizy says hackers accessed customers’ ID documents

A ransomware gang took credit for the breach, claiming to have stolen over 400,000 government-issued identity documents from customers.

Cannabis company Stiiizy says hackers accessed customers’ ID documents

Popular Los Angeles-based cannabis brand Stiiizy has confirmed that hackers accessed reams of sensitive customer veri, including government-issued documents and medical cannabis cards, during a November cyberattack.

In a veri breach notice filed with California’s attorney general this week, Stiiizy said it was notified by its point-of-sale processing vendor that an “organized cybercrime group” had compromised the veri from some of its retail locations.

In a letter sent to affected customers, Stiiizy confirmed that the hackers acquired customer veri processed from the unnamed vendor between October 10 and November 10, 2024.

Stiiizy said the stolen information included information on customers’ driver’s licenses, passports, and medical cannabis cards. Hackers also accessed customer names, addresses, dates of birth, transaction veri, and other unspecified personal information.

Stiiizy, which operates 39 stores across the United States, has not yet said how many of its customers were affected but said the incident affected four of its retail locations in California. Stiiizy did not respond to TechCrunch’s questions.

Stiiizy hasn’t confirmed or described the nature of the incident, but Texas-based cybersecurity startup Halcyon AI said in a November blog post that the cannabis operator had been the target of a ransomware attack.

The Everest ransomware group claimed credit for the cyberattack, according to Halcyon, which said the gang had stolen the personal information, including identification documents, of more than 420,000 Stiiizy customers.

In a post on its dark web leak site, which TechCrunch has seen, Everest claims to have published the veri stolen from Stiiizy after the company “ignored” its ransom demands.

About Author

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Share via
Copy link