Skip to content
Back to Blog
low severity December 31, 2024 · 4 min read

Stiiizy Inc. Data Breach Notice (Oregon Attorney General)

If you received a notice from Stiiizy Inc., here’s what the filing says was exposed, and what to do about it.

Stiiizy Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on December 31, 2024.

Stiiizy Inc. Data Breach Notice (Oregon Attorney General)

The filing from Stiiizy Inc. means that personal information belonging to 380,000 people is now outside the company’s control. If you received a notification letter, some of your details are among them.

This is not a minor exposure. The record lists personal information as the category involved in the December 31, 2024 filing with the Oregon Department of Justice. Because the company operates in the cannabis sector — an industry that remains federally illegal — the permanent sensitivity of even basic customer records is higher than it would be for most retailers. Names paired with addresses, phone numbers, or email addresses can be used to build targeted profiles that carry risk long after the initial breach.

The Scale and What the Record Actually Shows

Stiiizy Inc. reported that the incident affected 380,000 individuals. The filing does not disclose the exact root cause, the attack vector, or whether data was copied and exfiltrated. It also does not mention any passwords, financial account numbers, Social Security numbers, driver’s license numbers, or medical details. No permanent government or biographic identifiers appear in the exposed categories.

That absence is meaningful. No passwords were exposed, so there is no need to change any Stiiizy account password because of this incident. The risk sits entirely with the non-credential personal information that cannot be rotated or replaced.

What This Exposure Enables for Those Affected

Customer records from a cannabis retailer can reveal patterns of purchase, location history, and inferred health or lifestyle details. Even without sensitive identifiers, the combination of name, contact information, and implied customer status can be valuable to marketers, fraud rings, or individuals seeking to embarrass or pressure someone. In a federally prohibited industry, the simple fact of being a customer can itself become leverage.

Because the filing does not state when the incident occurred, only the notification date of December 31, 2024, the letter you may or may not have received is the only practical way to determine whether your records were included. The company is required to notify affected individuals directly, usually by mail. If you have not received a letter at your current address, it is likely your information was not part of this group. However, anyone who has moved since the time the records were originally collected should contact Stiiizy directly to confirm their status.

Why Names and Contact Details Remain Sensitive Years Later

Unlike credit card numbers that can be canceled or passwords that can be changed, a name tied to a physical address or phone number does not expire. These details can be cross-referenced with other publicly available data to create persistent dossiers. For customers in a federally illegal industry, this creates an elevated and ongoing privacy burden that most retail breaches do not impose.

The record gives no indication that the company suffered a ransomware attack, involved a third-party vendor, or lost control of any password database. Those claims are not supported by the filing and should not be assumed. What matters is what was confirmed: personal information on 380,000 people left the company’s systems.

The Gap Between Incident and Notification

The filing reaches the Oregon Attorney General on the last day of 2024 but provides no separate incident date. Without that date it is impossible to measure how long the data may have been accessible. The absence of this detail is common in breach notifications, yet it leaves affected individuals without a clear timeline for when their information first became exposed.

Practical Steps Specific to This Exposure

  • Monitor your mail and contact Stiiizy if you have moved. The company must send individual notifications. Absence of a letter usually means you were not included, but changed addresses can break that channel.
  • Treat any unsolicited contact claiming to be from Stiiizy with suspicion. Scammers now have a confirmed list of customers and may use the breach as a pretext for phishing or fraudulent offers.
  • Be cautious about sharing cannabis-related purchase history or loyalty program details in the future. The exposure demonstrates that even basic customer records from this industry carry long-term privacy weight.
  • Review credit reports and bank statements for unusual activity. While financial data was not listed as exposed, identity-related fraud often begins with personal contact details that allow convincing social engineering.
  • Consider privacy-enhancing steps such as using a mailing address service or separate contact numbers for sensitive purchases. This incident shows that customer lists in federally restricted industries remain valuable targets even without passwords or government IDs.

The core reality is straightforward: 380,000 customer records containing personal information are now outside Stiiizy’s protection. No passwords or government identifiers were involved, which removes some immediate account takeover risks but does not eliminate the privacy implications of being identified as a customer in this sector. The letter remains the only reliable indicator of whether you are personally affected. Where that letter does not arrive, the safest assumption is that your records were not part of this particular filing.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed December 31, 2024
Last reviewed July 22, 2026
Affected 380000
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email