Skip to main content

The Money Overview

One data-breach settlement pays up to $7,500, or a no-proof cash payment, before September 10

A single class-action settlement now on the table pays as much as $7,500 to people who can document their losses, or a smaller no-proof cash payment to those who cannot, but only for claims filed before September 10. The money comes from a $2.95 million fund set aside after a retailer’s customer records were exposed, and like most settlements of its kind, much of it will go unclaimed simply because eligible people never file. For a retiree watching every dollar, an unclaimed payout is the rare case of free money that requires nothing more than a form and a deadline met on time.

Inside the $2.95 Million STIIIZY Data-Breach Settlement

The fund stems from a data-security incident at STIIIZY, a cannabis retailer whose customers received notices that their personal information may have been compromised in a breach dating to late 2024. Anyone who got such a notice, or who believes their data was caught up in the incident, falls within the class the agreement is meant to compensate. The settlement does not require a court finding of wrongdoing, which is typical of these resolutions, and it closes the matter in exchange for the payments and protections it lays out.

The payout structure gives claimants a choice. Those who can show out-of-pocket losses traceable to the breach may recover up to $7,500, while everyone else can take a flat or pro-rata cash payment without documentation, along with two years of credit monitoring, according to the official settlement administrator’s answers to common questions. The dollar figures and the process are also summarized in a rundown of the $2.95 million agreement. The claim deadline is September 10, with a final approval hearing set for later in the fall.


Free retirement updates: Enrollment and claim windows come and go, and missing one can cost you real money. The free Retirement Shield newsletter keeps you ahead of the deadlines that matter. Sign up free.

Why So Much Settlement Money Goes Unclaimed

Data-breach settlements routinely pay out a fraction of the money set aside, and the reason is rarely eligibility. It is inertia. Notices arrive by email or postcard, get mistaken for junk, and land in the trash before anyone reads the fine print. The no-proof option exists precisely because most people cannot tie a specific dollar of harm to a specific breach, so the flat cash payment is designed to be claimed with little more than a name, an address, and a confirmation that a notice was received.

The documented tier rewards those willing to gather receipts. Bank fees, fraudulent charges that had to be reversed, the cost of a credit-monitoring service bought after the breach, or hours spent untangling a fraudulent account can all count toward the higher amount, provided the paperwork backs it up. Some settlements also compensate documented time at a set hourly rate, so a written log of the phone calls and letters it took to fix the problem can turn otherwise unpaid effort into part of the claim. Keeping the notice, along with any statements showing suspicious activity, is what separates a token payment from a meaningful recovery.

Credit monitoring bundled into the deal carries value that the cash figure understates. Two years of watching a credit file can flag a new account opened in a victim’s name before it snowballs, an early warning that often matters more to a retiree’s finances than the check itself.

The Real Risk Is the Data, Not the Deadline

A settlement compensates for a breach that already happened, but the exposed information does not expire when the fund closes. Names, contact details, and account data can circulate for years, feeding scam calls, phishing emails, and attempts to open credit in someone else’s name. Older Americans are targeted disproportionately in these schemes, which makes the defensive steps after any breach as important as the claim itself.

The strongest free protection is a credit freeze. The Federal Trade Commission’s guidance on credit freezes and fraud alerts explains that a freeze blocks new lenders from pulling a report, which stops most fraudulent accounts cold and costs nothing to place or lift at each of the three major bureaus. A fraud alert is a lighter-touch alternative for those who expect to apply for credit soon.

Anyone who spots misuse rather than just exposure has a direct route to recovery. The government’s identity-theft recovery service walks victims through reporting the theft and building a personalized action plan, and it produces the official documentation banks and creditors ask for when disputing fraudulent charges. Using it early tends to shorten the cleanup.

The STIIIZY fund is one open window among many, and the pattern behind it is the lesson worth keeping. Settlement money sits waiting for people who read their mail and act before the date, while the exposed data that triggered the payout keeps working against them long after the checks clear.

The open question for any household is not whether a breach will touch it, but whether the response will stop at cashing a modest payment or extend to locking down the credit file that the breach put at risk. The deadline handles the first part; only the freeze handles the second.

This article was produced with AI assistance and reviewed against primary sources by The Money Overview editorial team.

More Financial Reading