Nearly a million passports and photo IDs were left unprotected on the public internet

Jun 11, 2026 04:55 AM - 2 months ago 58489

Typing a fewer letters and numbers into my web browser, I find myself gaping astatine the personality documents of complete strangers. The passport of a young female from Germany. The passport of a man from Spain pinch glasses resting connected his head. The beforehand and backmost of different man’s driver’s license, a stereotypically goofy look connected his face.

They were each sitting unprotected astatine nationalist URLs, pinch nary password aliases entree power of immoderate sort. If I sent you a link, you could person looked astatine someone’s passport.

“We person to do thing astir it arsenic accelerated arsenic possible, because group will find this and resell it. It will do damage,” Sammy Azdoufal told maine successful May.

Azdoufal is the information interrogator who utilized Claude Code to thief observe that every DJI Romo robot vacuum cleaner and a cardinal babe monitors and information cameras were embarrassingly easy to hack. This time, he says he discovered complete 985,000 photograph IDs sitting connected the nationalist net for immoderate half-decent hacker to steal.

If you’ve visited a cannabis nine successful Spain, Azdoufal says, chances are your photograph ID was among them — and perchance your telephone number, address, your favourite strains of cannabis, and really overmuch you consumed each period while there. Azdoufal says celebrities are successful the database, too, and visitors from each complete the world, including 30,000 from the United States. “They person celebrated people,” says Azdoufal. “People who don’t want everyone to cognize they fume weed.”

Here’s a unsmooth summary of the userbase that Azdoufal’s automated instrumentality was capable to see, and the names of immoderate of the clubs:

Image: Sammy Azdoufal

It’s not the clubs that didn’t protect these personality documents. An Irish institution called Cannabis Club Systems (CCS), formally Nefos Solutions, develops and provides the package these clubs usage for sales, accounting, and admissions, including a verification strategy wherever receptionists upload your IDs and selfies to Nefos’ cloud.

Traditionally, you’d request to supply a photograph ID each clip you wanted to get into a club. But pinch the verification system, the receptionist tin propulsion up your stored personality documents and cheque if your look matches. There’s besides an optional app called PuffPal that lets clubs scan a QR codification for faster entry.

But erstwhile Azdoufal decompiled that PuffPal app, he explains successful his report, he discovered that Nefos had nary meaningful level of security. He discovered a concealed cardinal for the Stripe payments level sitting wrong the app successful plain text. He discovered he could propulsion up immoderate member’s floor plan conscionable by changing 1 number. If those profiles included their telephone number, location address, passport, and weed preferences, he now had entree to them too.

And then, he discovered that those passports, drivers licenses, and photograph IDs were stored astatine nationalist URLs arsenic elemental arsenic this: https://ccsnubev2.com/v8/images/_{club}/ID/{user_id}-front.jpg

Those clubs were uploading 5,000 caller photograph IDs pinch these insecure URLs each day, Azdoufal tells me.

He besides recovered an admin portal accessible via the nationalist net — and that the cannabis clubs had a trivial level of information connected their ain accounts, utilizing passwords that could theoretically beryllium cracked successful minutes pinch a modern GPU. Private chat messages betwixt clubs and members done the PuffPal app were besides vulnerable.

The bully news: astir a period aft we reached retired to Nefos, the institution seems to yet beryllium taking meaningful action. The institution says it’s shutting down its full PuffPal strategy and susceptible APIs until they tin beryllium fixed — successful Azdoufal’s latest tests connected June 10th, passport images and individual information look to beryllium secure. Nefos has besides informed section authorities, and says it will return work to make fixes, salary fines, and show users what happened.

In a telephone interview, Nefos co-founder Andreas Nilsen tells The Verge that he’s successful touch pinch Ireland’s Data Protection Authority (DPC) astir the information breach — a truth that DPC spokesperson Evan O’Leary confirmed to america by email. “We person to pass to everyone that was perchance exposed,” Nilsen tells me, saying he hopes the DPC tin show his institution really to do that properly. Nilsen claims there’s presently nary grounds that immoderate outsider accessed the information different than Azdoufal.

But it took acold excessively agelong for Nefos to return the threat seriously. It took 5 days and the threat of a communicative earlier the institution replied to us, agelong aft Azdoufal reached out. Then, Nefos began by papering complete the holes alternatively of risking business.

I was prepared to constitute this communicative astatine the opening of June, aft Azdoufal told maine Nefos had yet locked down the passport images. But connected June 4th, I amazed Azdoufal by showing him that his very ain passport was online erstwhile again, without immoderate protection.

That’s because Nefos had not yet stopped cannabis clubs from utilizing the PuffPal app, and clubs were complaining the locked-down images weren’t showing up the measurement they utilized to — truthful Nefos simply unlocked the images again. While Nilsen claims the images were locked down “70 percent of the time” since Azdoufal and I sewage successful touch, it’s beautiful clear that Nefos made a determination to prioritize its customers alternatively of the threat.

On June 9th, Azdoufal discovered that moreover though Nefos had locked down the passport images and photograph IDs pinch tokens, everything else successful the personification profiles was still easy accessible: passport numbers, telephone numbers, email addresses, location addresses, everything.

All a hacker had to do was type “curl -X POST https://ccsnubev2.com/v8/api/userProfile.php -d “user_id=[NUMBER]&[CLUB NAME]=test&language=en” into a bid line, and the servers would freely springiness up a ream of individual information. After we brought this to Nefos’ attention, that hole, too, has been closed.

But really could the institution beryllium truthful careless? “I don’t want to put the blasted connected others because astatine the extremity of the time it resides pinch us,” Nilsen says. But he does constituent the digit at 9Series, an outsourcing patient he claims was responsible for processing the PuffPal app and creating each the susceptible APIs it utilized to propulsion unprotected information from Nefos’ personification database. (9Series did not person a consequence by people time.)

Now that PuffPal is down, Nefos is emailing each nine to fto them cognize their members won’t beryllium capable to usage those QR codes for introduction — but they tin still propulsion up IDs from Nefos’ servers aft scanning a member’s RFID paper aliases typing successful their telephone number, among different examples.

Nilsen claims his institution will not simply re-launch unsecured PuffPal if the clubs ask. “We’re going to show them we can’t,” he says. “We will make sure, aft this debacle, that this is verified by an independent information interrogator and guarantee that this is 100 percent secure.” He says Nefos is parting ways pinch 9Series, and hopes to person a caller app wrong a fewer months.

Nilsen says he’s alert that under EU law, his institution legally had to disclose the breach wrong 72 hours aliases salary important fines, thing the institution didn’t do. “I’m judge we’ll get immoderate benignant of punishment location is,” Nilsen says.

Just past month, a website called the UK Visa Portal similarly exposed astatine slightest 100,000 passports to anyone who could conjecture a URL. Let’s dream this is simply a wakeup call.

Follow topics and authors from this communicative to spot much for illustration this successful your personalized homepage provender and to person email updates.

More