A data-breach settlement tied to the cannabis brand STIIIZY is paying eligible people reimbursement for documented losses of up to $7,500, and the deadline to file a claim is closing soon. Anyone who received a notice that their personal information was exposed has until September 10, 2026, to submit a claim, after which the opportunity disappears. For older adults, who are frequent targets once stolen data reaches the resale market, the offer is a rare chance to recover real out-of-pocket costs rather than absorb them quietly.
What the STIIIZY settlement actually covers
The settlement resolves a lawsuit filed in the U.S. District Court for the Central District of California over a breach that exposed customer information. According to the official settlement administrator, the agreement establishes a fund of roughly $2.95 million to compensate people whose data was compromised, and it lays out two main forms of relief.
The first is reimbursement for documented, out-of-pocket losses fairly traceable to the breach, up to a cap of $7,500 per claimant. That category can include unreimbursed fraudulent charges, fees paid to reverse identity theft, costs of credit-freeze services, and the value of time spent cleaning up the fallout. The second is a period of credit monitoring, which watches for new accounts or inquiries opened in a person’s name and can flag misuse before it snowballs.
Claimants generally must have received notice that their information was involved, and documentation strengthens any request for the larger loss reimbursement. Keeping bank statements, receipts, and correspondence about disputed charges is what turns a claim from an estimate into a payable amount.
The two forms of relief serve different needs. The credit monitoring is forward-looking, watching for misuse that has not happened yet, and it is available to eligible class members even without a dollar of proven loss. The cash reimbursement is backward-looking, repaying costs already incurred. A person who has not yet suffered a fraudulent charge can still enroll in the monitoring, while someone who paid to freeze credit or spent hours on the phone disputing charges can document those costs and seek the reimbursement. Both flow from the same claim, so there is no reason to choose only one.
Free retirement updates: Miss an enrollment or claim deadline and it may be gone. Our free Retirement Shield newsletter keeps readers ahead of the ones that matter. Get the free newsletter.
Why the September 10 deadline is the part that matters
Class-action settlements run on fixed calendars, and the claim window is the hard edge. Once September 10, 2026 passes, late claims are generally rejected, and the unclaimed share of the fund does not get mailed out to people who missed the date. That structure is why so much settlement money goes unclaimed every year: eligible people set the notice aside, forget the deadline, and never file the short form that would have paid them.
The filing itself does not require a lawyer or a fee. Claims are submitted directly to the administrator, typically online or by mail, using the claim number or notice that arrived after the breach. A claimant who lost the mailing can often still file by confirming eligibility through the settlement website. The key is acting before the window shuts rather than waiting to see whether fraud shows up later, because the deadline does not move to accommodate a delayed problem.
The size of the fund makes the timing even more consequential. A settlement pool of roughly $2.95 million is divided among everyone who files a valid claim, so the pot is finite. If a large share of the class comes forward, individual payments for smaller categories may be adjusted, but people who never file receive nothing at all. Waiting also removes the option entirely once September 10 passes, and there is no appeal for a missed deadline. That combination — a fixed pool, a hard cutoff, and no late filing — is exactly why consumer advocates urge eligible people to submit early rather than let the notice sit unopened on a kitchen counter.
How exposed retirees can limit the damage now
Filing a claim addresses the money already spent, but it does nothing to stop future misuse of information that is now circulating. The federal government’s own guidance points to a few concrete steps that cost nothing and blunt most breach fallout. Placing a free credit freeze with each of the three major credit bureaus blocks new accounts from being opened, and it can be lifted temporarily whenever legitimate credit is needed.
The Federal Trade Commission’s consumer guidance also recommends monitoring existing account statements closely for charges that do not belong, since breached data is often tested with small transactions before larger fraud. Anyone who spots misuse can build a recovery plan and generate an official affidavit through the government’s identity theft recovery site, which walks a victim through disputing charges and correcting records.
Those protections pair naturally with a settlement claim. The reimbursement recovers what a breach already cost, while a freeze and active monitoring reduce what it can cost going forward. For a retiree whose Social Security deposits and savings sit in accounts that a thief would love to reach, the combination is worth the short time it takes to file. The one piece with an expiration date is the claim itself, and that clock runs out on September 10, 2026.
This article was created with AI assistance and was reviewed, edited, and fact-checked by The Financial Wire editorial team.
More Financial Reading
- What really happens to your joint savings account when you die?
- Bank statements: how long to keep them and when to toss them



