🏳️‍⚧️ trans rights are human rights 🏳️‍⚧️
Theme

STIIIZY had a data breach of 387,555 people’s personal information

TL;DR

  • Cannabis retailer STIIIZY, Inc. suffered a data breach around October 2024, disclosed on January 7, 2025, exposing the private information of 387,555 people, including 232,578 California residents.
  • The stolen data included personally identifiable information and private health information from people buying a federally illegal but state-legal product, information that carries real-world risk if leaked.
  • STIIIZY agreed to a $2,950,000 settlement fund that pays for everything: victim payments, credit monitoring, notice costs, attorney fees, and service awards.
  • The company denies all wrongdoing and admits no liability, a standard settlement escape hatch that closes the case with no finding of fault.
  • Lawyers can take up to $983,333 in fees plus $30,000 in expenses, meaning roughly a third of the fund can leave before a single victim is paid.

The fund covers 387,555 people, but the entire settlement is worth about $7.61 per exposed person before the lawyers and administrators take their cut.

The Non-Financial Ledger

People handed STIIIZY their names and personal details to buy cannabis, a product still illegal under federal law even where states permit it. That trust turned into exposure when their information was stolen and their identities put at risk.

The settlement itself confirms what was on the line. It expressly covers “claims of psychological harms and emotional distress” tied to the breach, an acknowledgment that this was not a harmless clerical slip but something that caused real fear about identity theft, fraud, and being tied on a stolen list to a federally controlled purchase.

The people affected did nothing wrong. They shopped at a store and expected their records to be kept safe. Instead, 387,555 of them now live with the knowledge that their private information is loose, and the company that lost it walks away denying it did anything wrong at all.

Legal Receipts

“Stiiizy represents that it caused notice of the Data Security Incident to be sent, via direct mail and/or electronically, to 387,555 individuals, of which 232,578 were California residents at the time of the Data Security Incident.”

  • This is the company’s own count of how many people it exposed: 387,555 individuals.
  • A majority, 232,578, were California residents, which is why California claims are worth double under the settlement.
  • The figure sets the true scale of the harm against the size of the fund meant to fix it.

“For avoidance of doubt, ‘Released Claims’ does not include bodily injury claims. But it does include claims of psychological harms and emotional distress based on, relating to, or arising out of the Data Security Incident.”

  • The settlement itself recognizes the breach caused psychological harm and emotional distress, not just financial loss.
  • By releasing these claims, victims give up the right to sue over that distress separately, in exchange for the settlement’s limited payouts.

“Defendant has denied and continues to deny each and every claim and contention alleged in the Action. Stiiizy asserts that it has complied with all applicable provisions of federal and state statutory and common law.”

  • STIIIZY admits no fault while paying nearly $3 million to end the case.
  • This clause means no court ever ruled the company failed to protect the data.
  • It lets the company treat a large payout as a cost of doing business rather than an admission of a security failure.

“The Settlement Agreement is not an admission of liability by Defendant, nor is this Order a finding of the validity of any allegations or of any wrongdoing by Defendant.”

  • The proposed final order bakes the no-liability shield directly into the court’s judgment.
  • The record will show a resolved case with no finding of wrongdoing, which limits future accountability.
“Stiiizy… caused notice of the Data Security Incident to be sent… to 387,555 individuals.”

Regulatory Gray Zones

This case sits at the collision point of state-legal cannabis retail and federal drug prohibition, a gap that shapes both the risk to consumers and the accountability of the company.

  • The stolen records tie identifiable people to a federally illegal product, which multiplies the danger of a leak beyond ordinary retail data, yet the settlement treats it as a routine consumer data breach.
  • The Consolidated Complaint invoked the California Confidentiality of Medical Information Act (CMIA), signaling that some of the exposed data functioned as private health information deserving heightened protection.
  • Because cannabis operates in a patchwork of state rules without a unified federal data-security regime, there is no single agency clearly responsible for policing how a company like STIIIZY guards customer records.
  • The settlement’s “Equitable Relief” requires security improvements described only in a confidential declaration that may be filed under seal, keeping the specifics of what went wrong and what was fixed out of public view.

The Settlement Isn’t Justice

A $2,950,000 fund sounds substantial until you divide it by the number of people it must cover and subtract what leaves before victims are paid.

  • The gross fund is $2,950,000 spread across 387,555 exposed people, or roughly $7.61 per person before any deductions (calculated from source figures: $2,950,000 divided by 387,555).
  • Attorney fees can reach $983,333 plus $30,000 in expenses, and service awards add $15,000, all paid out of the same fund before class members.
  • Notice and claims administration costs also come out of the fund, further shrinking what is left for actual victims.
  • STIIIZY admits no wrongdoing, so the settlement buys finality for the company without any judicial finding that it failed its customers.
  • Settlement checks go void 90 days after issuance, with re-issuance cut off six months after the Effective Date, a structure that lets unclaimed money slip away from the people it was meant for.
Where the $2.95M Fund Goes Before Victims Are Paid $3.0M $1.5M $0 $2.95M Gross Fund $983K Atty Fees $30K Expenses $15K Svc Awards

Public Deception

The way the breach is described shifts depending on which document you read, blurring when it actually happened.

  • STIIIZY publicly announced the incident on January 7, 2025, yet the settlement’s own loss-eligibility window opens on or after October 10, 2024, and notices describe an “October 2024 data breach.”
  • Consumers were told about the breach in January, but the settlement acknowledges the underlying compromise was months earlier, meaning affected people may have been exposed for a substantial period before they knew.
  • STIIIZY continues to deny it violated any law even while agreeing to fund credit monitoring, identity theft insurance, and cash payments tied directly to that breach.
What You Were Told vs. The Reality What You Were Told The Reality Breach “announced Jan 7, 2025″ Losses eligible from Oct 10, 2024 onward “Complied with all applicable law” Paying $2.95M & funding credit monitoring “No admission of liability” Releases emotional distress claims from breach

How Capitalism Exploits Delay: Time as a Corporate Weapon

The gap between when the harm began and when accountability arrives stretches across more than two years, and every stage is structured to run on the company’s clock.

Harm Onset vs. Resolution Timeline Harm Timeline ~Oct 2024 Breach occurs Jan 7, 2025 Disclosed Legal Timeline Jan 2025 Suits filed Nov 17, 2025 Mediation Apr 2026 Settlement signed
  • Roughly 18 months passed between the approximate breach date of October 2024 and the signed settlement of April 2026, during which victims carried the risk.
  • The settlement funds the payout in three installments, with the final $1,100,000 not due until September 30, 2026, deferring the company’s full payment more than a year and a half after disclosure.
  • Even after final approval, checks stay valid for only 90 days and re-issuance ends at six months, using deadlines to quietly shed obligations to slow or unaware claimants.

Societal Impact Mapping

Public Health

The exposed records included information treated as private health data, carrying consequences beyond ordinary retail leaks.

  • The Consolidated Complaint alleged violation of the California Confidentiality of Medical Information Act, indicating the breach touched protected health-related information.
  • The settlement releases psychological harm and emotional distress claims, confirming a documented mental-health toll on those affected.
  • Because the data links people to cannabis purchases, exposure creates ongoing stress about being identified in connection with a federally controlled substance.

Economic Inequality

The financial structure of the settlement pushes the real cost onto the individuals least able to absorb it.

  • Documented-loss claims require receipts and third-party records, and self-prepared documents are insufficient alone, a burden that filters out people without the time or paperwork to prove harm.
  • The pro rata cash payment is whatever remains after fees, expenses, administration, credit monitoring, and documented losses, meaning ordinary claimants are paid last and least.
  • Non-California class members receive a single share while California residents receive two, splitting the already-thin fund unevenly across the 387,555 people harmed.

The “Cost of a Life” Metric

$7.61 The gross settlement value per exposed person, calculated from source figures ($2,950,000 fund divided by 387,555 notified individuals), before attorney fees, expenses, service awards, and administration costs are deducted.

This Is the System Working as Intended

Every structural feature of this settlement channels risk toward victims and finality toward the company, which is the predictable output of how data-breach litigation is resolved.

  • STIIIZY exits with no admission of liability and a court order stating there is no finding of wrongdoing, converting a mass exposure of 387,555 people into a closed file.
  • The security fixes are described in a confidential declaration that can be sealed, so the public and future customers never learn what failed or whether it was truly fixed.
  • Claim deadlines, voided checks, and a documentation burden mean much of the fund can go unclaimed, with leftovers routed to a cy pres recipient rather than expanding victim payments automatically.
  • Nearly a third of the fund can be consumed by attorney fees alone, a ratio built into the model that treats breach cases as a business transaction rather than deterrence.

What a Legitimate Fix Looks Like

The core failure this case exposes is that a company can lose the private and health-linked data of hundreds of thousands of people, deny all fault, seal the details, and settle for pennies per victim. The following are editorial recommendations, not findings of the source document.

Regulatory Track

  • Require cannabis retailers holding health-linked purchase data to meet mandatory, published data-security standards with independent third-party audits, given the CMIA exposure documented here.
  • Prohibit sealing of remediation declarations in breach settlements so customers can see what failed and what was fixed, as a general industry-standard transparency measure.
  • Mandate prompt breach notification tied to the actual date of compromise, closing the gap between the October 2024 onset and the January 2025 disclosure seen in this case.

Legislative Track

  • Enact statutory minimum per-person compensation for breaches involving health-linked data, so payouts cannot collapse to a few dollars each.
  • Require that unclaimed settlement funds redistribute to claimants before any cy pres diversion, ensuring victims capture the full fund.
  • Cap or scrutinize attorney fee percentages in breach settlements where per-victim recovery is minimal, preventing a third of the fund from leaving before victims are paid.

Corporate Governance Track

  • Require board-level accountability for data security at companies handling sensitive consumer and health data, with named executive responsibility.
  • Tie executive compensation to verified security compliance rather than settlement-driven cost containment.
  • Make the multi-year security improvements in this settlement publicly reportable and time-verified rather than confidential.

What Now?

Direct your attention to the company that lost the data and the agencies positioned to hold breach-prone firms accountable.

  • If you received a STIIIZY breach notice, file your claim before the deadline and elect the two years of credit monitoring and up to $1 million identity theft insurance you are entitled to.
  • Watchlist: the FTC for consumer data-protection enforcement and the California Attorney General, given 232,578 affected California residents and CMIA claims.
  • Watchlist: the DOJ and state Attorneys General who receive CAFA notice of this settlement and can scrutinize its adequacy.
  • Support local digital-privacy and consumer-rights organizations pushing for stronger breach-notification and minimum-compensation laws.
  • Organize with fellow class members to submit objections if you believe the per-person recovery or fee structure is unfair; the settlement allows written objections before the deadline.

The source document for this investigation is attached below.

Explore by category

01

Antitrust

Monopolies and anti-competition tactics used to crush rivals.

View Cases →
02

Product Safety Violations

When companies sell dangerous goods, consumers pay the price.

View Cases →
03

Environmental Violations

Pollution, ecological collapse, and unchecked greed.

View Cases →
04

Labor Exploitation

Wage theft, worker abuse, and unsafe conditions.

View Cases →
05

Data Breaches & Privacy

Misuse and mishandling of personal information.

View Cases →
06

Financial Fraud & Corruption

Lies, scams, and executive impunity that distort markets.

View Cases →
07

Intellectual Property

IP theft that punishes originality and rewards copying.

View Cases →
08

Misleading Marketing

False claims that waste money and bury critical safety info.

View Cases →
Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2064