STIIIZY says a company that handled point-of-sale processing for some of its retail shops was broken into by an organized cybercrime group. That vendor later told STIIIZY that customer records tied to certain store locations had been taken sometime between October 10, 2024 and November 10, 2024, though STIIIZY itself wasn’t notified until November 20, 2024. After launching its own review, STIIIZY confirmed that documents and personal details belonging to some of its customers were accessed by the attackers as part of this third-party vendor breach.
According to the notice, this only involves consumer profiles connected to four physical dispensary locations: STIIIZY Union Square and STIIIZY Mission in San Francisco, STIIIZY Alameda, and STIIIZY Modesto. If you never shopped at or checked in with an ID at one of these four stores during that window, you’re likely not part of this incident — but if you did, it’s worth taking the notice seriously given the type of documents involved.
What ended up in the hands of the attackers?
- Full name
- Home address
- Date of birth and age
- Driver’s license number
- Passport number
- Photograph from a government-issued ID
- Signature as it appears on an ID card
- Medical cannabis card details
- Dispensary transaction history
- Other personal information tied to your account
STIIIZY notes that not every category applies to every person — some customers may have had only a subset of this information exposed.
STIIIZY is offering affected customers a year of free Single Bureau Credit Monitoring, Credit Report, and Credit Score services, plus fraud assistance, through Cyberscout, a TransUnion company. To sign up, go to https://bfs.cyberscout.com/activate and enter the activation code printed in your individual letter — enrollment closes 90 days after the date on the notice, so don’t let it sit unopened for too long.
Steps worth taking given what was exposed
- Enroll in the free Cyberscout credit monitoring before the 90-day window closes, since it will flag new accounts or inquiries on your credit file.
- Because a driver’s license or passport number was likely involved, contact your state DMV or passport agency to ask about fraud alerts or replacement options if you’re concerned about misuse.
- Place a fraud alert or, better, a security freeze with Equifax, Experian, and TransUnion — this is one of the stronger protections against someone opening new credit in your name.
- Watch your bank and card statements closely for unfamiliar charges over the coming months, not just the next few weeks.
- Given that a government photo ID, signature, and medical cannabis card were involved, consider signing up for a service like Aura or LifeLock, which can alert you if your personal information turns up being misused elsewhere.
- Report any signs of identity theft to the FTC at IdentityTheft.gov or 1-877-438-4338, and file a police report if you find evidence someone used your documents.
If you have questions about whether you’re affected or how to enroll in monitoring, STIIIZY’s assistance line can be reached at 833-799-4284, Monday through Friday from 8:00 a.m. to 8:00 p.m. Eastern time.