Cannabis Retail Customers Exposed: Sessions Cannabis Breach Leaked 2,700 Records
HEROIC analysts uncovered a database breach affecting Sessions Cannabis, a Canadian retail cannabis chain, with the leak dated July 27, 2023. The exposed dataset contained approximately 2,700 customer records pulled directly from the retailer's customer database. The breach is notable because it includes physical home addresses alongside contact details, a data combination that elevates risk well beyond what a typical ecommerce leak might produce.
Cannabis Retail Customers Face Targeted Phishing and Identity Fraud
Attackers holding this dataset have everything needed to launch convincing social engineering attacks. With full names, email addresses, phone numbers, and physical addresses in hand, they can craft phishing emails that reference the victim's real purchase history or location, send fraudulent delivery notifications, or make direct phone contact posing as Sessions Cannabis support. The physical address component is partcularly troubling because it can enable offline targeting and makes the breach useful for identity theft schemes that require proof of residence.
What Was Exposed in the Sessions Cannabis Breach
- Email addresses
- First names and last names
- Phone numbers
- Physical addresses
Why Cannabis eCommerce Breaches Carry Unique Risks
Cannabis retailers operate in a regulated environment where customers provide verified identity information to comply with age and purchase restrictions. That means breached records from platforms like Sessions Cannabis are more likely to contain accurate, validated personal details than those from unregulated services. Victims of this breach could recieve highly credible phishing attempts, face account takeover attempts on associated email accounts, or find their identity used in financial fraud schemes. The combination of a verified name, phone number, address, and email is also the standard profile sold to identity fraud operators on dark web markets.
How eCommerce Database Breaches Work
An eCommerce database breach typically occured when attackers identify and exploit a vulnerability in a retail platform's web application or backend infrastructure. Common entry points include unpatched content management systems, insecure third-party plugins, or compromised admin credentials. Once inside, attackers target customer tables because they aggregate verified personal information in a single accessable location. The exfiltrated data is then packaged and distributed or sold through dark web channels, often appearing in multiple places simultaneously to maximize attacker return.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion exposed records to determine whether your email address appears in the Sessions Cannabis breach or any other known data leak. Run your free scan today and take steps to protect your identity before someone else uses your information against you.
Breach Breakdown
507 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds