Everest Ransomware Group Reportedly Claims STIIIZY Breach With 420,000 Customer Records

Everest claims to have breached cannabis company STIIIZY, alleging the theft of approximately 420,000 customer records containing identity documents and medical cannabis cards.
Screenshot of a cybercrime forum post in which the Everest ransomware group claims to have breached STIIIZY, alleging the theft of approximately 420,000 customer records, government-issued documents, and medical cannabis cards.
Forum post from the Everest ransomware group claiming responsibility for an alleged breach of STIIIZY, asserting it stole approximately 420,000 customer records, including government-issued identification documents and medical cannabis cards.

The Everest ransomware group has claimed to have breached California cannabis company STIIIZY, alleging the theft of approximately 420,000 customer records that include government-issued identification documents and medical cannabis cards. The claims have not been independently verified.

According to a post published on a cybercrime forum, the threat actor is offering what it describes as a full database from stiiizy.com. The post claims the stolen data includes customer accounts, government-issued documents, and medical cannabis cards, but does not provide publicly viewable samples of the alleged customer records.

Customer and medical records allegedly targeted

STIIIZY is a California-based cannabis company known for its cannabis products, retail dispensaries, and medical cannabis offerings. In the forum post, Everest claims the alleged breach resulted in the theft of approximately 420,000 records associated with the company’s customers.

The actor specifically alleges the dataset contains customer account information alongside government-issued identity documents and medical cannabis cards. If authentic, the combination of identity documents and medical cannabis information could expose highly sensitive personal and health-related data.

Latest claim from Everest

Everest is an established ransomware and data extortion group that regularly publishes alleged victims while attempting to pressure organizations into paying ransom demands. BreachNews previously covered the group’s alleged breach of Rehab Clinics Group, where Everest claimed to have stolen addiction treatment records and other sensitive information.

Unlike some recent extortion posts that include screenshots or sample documents, this listing contains only a brief description of the alleged breach, an image referencing STIIIZY, and a cryptographic hash that purportedly identifies the archived data. BreachNews has not downloaded or verified the alleged dataset.

Medical cannabis records raise privacy concerns

If the claims are accurate, exposure of customer accounts together with government-issued identification documents and medical cannabis cards could present significant privacy risks. Such information could potentially be used for identity theft, targeted phishing, or other forms of fraud, while medical cannabis documentation may also reveal sensitive health-related information.

STIIIZY had not issued any public statement regarding the alleged breach at the time of publication. BreachNews will update this article if the company confirms or disputes the claims or if additional evidence becomes available.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site