Back
Nearly a Million Passports and Photo IDs Left Unprotected Online
SiTech AI Team3 წთ. საკითხავი

Nearly a Million Passports and Photo IDs Left Unprotected Online

A security researcher found more than 985,000 passports and photo IDs sitting at public URLs with no password. The data belonged to members of Spanish cannabis clubs whose software provider, Nefos, has now shut the system down.

Nearly a million IDs, no password

Security researcher Sammy Azdoufal says he discovered more than 985,000 photo IDs — passports, driving licences and other identity documents — sitting at public URLs on the open internet, with no password or access control of any kind. "We have to do something about it as fast as possible, because people will find this and resell it. It will do damage," he told The Verge.

The documents belonged to members of cannabis clubs in Spain. The software behind them comes from an Irish company, Cannabis Club Systems (CCS), formally Nefos Solutions, which provides clubs with a verification system: receptionists upload a member's ID and selfie to Nefos' cloud, and an optional app called PuffPal lets clubs scan a QR code for faster entry.

How the data was exposed

After decompiling the PuffPal app, Azdoufal found that Nefos had no meaningful level of security. A secret key for the Stripe payments platform sat inside the app in plain text, and he could pull up any member's profile simply by changing one number. Those profiles held phone numbers, home addresses, cannabis strain preferences and monthly consumption figures — alongside the identity documents themselves, stored at public URLs as simple as https://ccsnubev2.com/v8/images/_{club}/ID/{user_id}-front.jpg. According to Azdoufal, clubs were uploading 5,000 new photo IDs to those insecure addresses every day.

He also found an admin portal reachable from the public internet, club accounts protected by passwords that could be cracked in minutes on a modern GPU, and private chat messages between clubs and members exposed. The people affected include visitors from around the world — roughly 30,000 from the United States — and celebrities who would rather not be known as cannabis consumers.

Shutdown, blame and the regulators

Nefos says it is shutting down the entire PuffPal system and its vulnerable APIs until they can be fixed. In Azdoufal's tests on June 10, passport images and personal data appeared secure, and cofounder Andreas Nilsen says the company has informed local authorities and will take responsibility for fixes, fines and notifying users. Ireland's Data Protection Commission, which Nilsen says he is in touch with, confirmed the contact.

The response was slow. Nefos took five days and the threat of a story to reply to The Verge, and on June 4 the company had re-opened the locked-down images because clubs complained they were not displaying properly. On June 9, everything else in the profiles was still retrievable with a single curl command to the company's userProfile.php endpoint; that hole was closed only after The Verge raised it. Nilsen points to outsourcing firm 9Series, which he says built the app and the vulnerable APIs, and says Nefos is parting ways with it. He acknowledges that EU law required disclosure within 72 hours, which did not happen, and expects penalties.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.