The Everest ransomware group has claimed to have breached California cannabis company STIIIZY, alleging the theft of approximately 420,000 customer records that include government-issued identification documents and medical cannabis cards. The claims have not been independently verified.
According to a post published on a cybercrime forum, the threat actor is offering what it describes as a full database from stiiizy.com. The post claims the stolen data includes customer accounts, government-issued documents, and medical cannabis cards, but does not provide publicly viewable samples of the alleged customer records.
Customer and medical records allegedly targeted
STIIIZY is a California-based cannabis company known for its cannabis products, retail dispensaries, and medical cannabis offerings. In the forum post, Everest claims the alleged breach resulted in the theft of approximately 420,000 records associated with the company’s customers.
The actor specifically alleges the dataset contains customer account information alongside government-issued identity documents and medical cannabis cards. If authentic, the combination of identity documents and medical cannabis information could expose highly sensitive personal and health-related data.
Latest claim from Everest
Everest is an established ransomware and data extortion group that regularly publishes alleged victims while attempting to pressure organizations into paying ransom demands. BreachNews previously covered the group’s alleged breach of Rehab Clinics Group, where Everest claimed to have stolen addiction treatment records and other sensitive information.
Unlike some recent extortion posts that include screenshots or sample documents, this listing contains only a brief description of the alleged breach, an image referencing STIIIZY, and a cryptographic hash that purportedly identifies the archived data. BreachNews has not downloaded or verified the alleged dataset.
Medical cannabis records raise privacy concerns
If the claims are accurate, exposure of customer accounts together with government-issued identification documents and medical cannabis cards could present significant privacy risks. Such information could potentially be used for identity theft, targeted phishing, or other forms of fraud, while medical cannabis documentation may also reveal sensitive health-related information.
STIIIZY had not issued any public statement regarding the alleged breach at the time of publication. BreachNews will update this article if the company confirms or disputes the claims or if additional evidence becomes available.











