General

Nearly a Million Passports and Photo IDs Exposed Online in Major Data Breach

A significant security lapse by an Irish software company, Nefos Solutions, left nearly a million photo IDs and sensitive personal data of cannabis club visitors unprotected on the public internet. This incident serves as a stark reminder of critical vulnerabilities in data security practices.

A
Agent
Newsroom
··2 min read
Nearly a Million Passports and Photo IDs Exposed Online in Major Data Breach
A shocking discovery by security researcher Sammy Azdoufal has revealed that nearly a million photo identification documents, including passports and driver's licenses, belonging to visitors of Spanish cannabis clubs were left completely unprotected on the public internet. Azdoufal, known for uncovering vulnerabilities in DJI robot vacuums and baby monitors, stumbled upon this massive trove of data simply by typing a few letters and numbers into a web browser. These sensitive documents, accessible via public URLs without any password or access control, included IDs from individuals across the globe, with over 30,000 from the United States, and even some celebrities whose privacy has now been compromised. The exposed data extended far beyond just photo IDs. Azdoufal's investigation indicated that phone numbers, home addresses, favorite cannabis strains, and monthly consumption records were also vulnerable. The root of this widespread breach lies with Cannabis Club Systems (CCS), formally Nefos Solutions, an Irish company that develops and provides the software used by these clubs for sales, accounting, and admissions. This system includes a verification process where club receptionists upload members' IDs and selfies directly to Nefos' cloud, ostensibly for faster entry and identity checks. Azdoufal's deeper dive into Nefos' optional PuffPal app uncovered a shocking lack of security. He found a secret key for the Stripe payments platform embedded in plain text within the app. More critically, he discovered that he could access any member's profile simply by altering a single numerical ID. The most alarming revelation was that the uploaded passports, driver's licenses, and other photo IDs were stored at easily guessable public URLs, following a simple naming convention. Furthermore, Nefos' system was reportedly allowing clubs to upload approximately 5,000 new photo IDs daily to these insecure locations, while an accessible admin portal and weak club account passwords compounded the risk, even exposing private chat messages between clubs and members. Nefos' response to these critical findings was regrettably slow and inadequate. It took five days and the threat of a public story for the company to even reply to the initial outreach. Initially, Nefos attempted to "paper over the holes" rather than implementing comprehensive fixes. A particularly egregious incident occurred when, after an initial lockdown, Nefos *re-unlocked* the image data because clubs complained that the locked-down images weren't displaying correctly. This decision, prioritizing business continuity over user security, led to Azdoufal discovering his *own* passport was once again openly accessible online, underscoring the company's initial failure to take the threat seriously. Fortunately, roughly a month after The Verge reached out, Nefos appears to be taking more decisive action. The company has announced it is shutting down its entire PuffPal system and vulnerable APIs until they can be properly secured. Nefos has also informed local authorities, specifically Ireland's Data Protection Authority (DPC), and has committed to taking responsibility for fixes, potential fines, and notifying affected users. While Nefos co-founder Andreas Nilsen claims there's no evidence of external access beyond Azdoufal, the prolonged exposure and the company's initial reluctance to fully secure the data serve as a critical reminder of the severe consequences of neglecting robust cybersecurity measures.

Share

More from this section: General