Security/ data breach · privacy · identity · cannabis

A Cannabis Club App Exposed Nearly 1 Million ID Documents

A cannabis club verification platform stored members' passports and driver's licenses at public URLs with no access control, exposing close to a million people.

A Cannabis Club App Exposed Nearly 1 Million ID Documents

A cannabis club membership platform left roughly a million passport scans and driver's license photos sitting at public URLs - no login required, no access token, nothing.

The platform handled identity verification for cannabis clubs, which collect government-issued IDs to satisfy age and membership regulations. Someone with a browser and a little patience could pull up the documents of complete strangers - passports from Germany and Spain, driver's licenses with faces visible - simply by navigating to the right address. No credentials stood in the way. Sammy Azdoufal, connected to the operation, acknowledged the urgency when contacted: "We have to do something about it as fast as possible, because people will find this and resell it. It will do damage."

The harm here is unusually durable. You can reset a password in thirty seconds; you cannot issue yourself a new face or a new passport number. Anyone who harvested these files has permanent material for identity fraud. Cannabis clubs sit on a dense pool of sensitive documents precisely because regulators require ID checks - and that compliance burden, combined with typically lean security budgets, produces an obvious weak point.

Exposing documents at guessable URLs with no access control is among the most preventable breach categories in existence. That it keeps happening at this scale, years after cloud security basics became standard practice, is less a story about sophisticated attackers than about vendors who treat identity documents as someone else's problem.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →