Nearly 985,000 passport images and photo IDs belonging to cannabis club members were left unprotected on the public internet, accessible to anyone who knew a simple URL pattern, security researcher Sammy Azdoufal revealed in June 2026.
The exposed data was tied to an Irish software company called Cannabis Club Systems (CCS), formally known as Nefos Solutions, which provides membership management and ID verification software to cannabis clubs in Spain. Receptionists at those clubs routinely uploaded members’ identity documents to Nefos’ cloud servers — but those files were stored at publicly guessable web addresses with no password or access controls in place.
Azdoufal discovered the vulnerability after decompiling PuffPal, a companion app Nefos offered for faster club entry via QR code. Inside the app, he found a Stripe payments secret key stored in plain text, the ability to pull up any member’s profile by changing a single number, and passport images sitting at simple public URLs. Beyond the ID images, exposed data included passport numbers, phone numbers, home addresses, email addresses, and cannabis consumption records. Azdoufal says the database included visitors from 30 countries, including roughly 30,000 from the United States, as well as celebrities. Clubs were uploading approximately 5,000 new photo IDs per day through the insecure system.
Nefos co-founder Andreas Nilsen attributed the vulnerable APIs to 9Series, an outsourcing firm he says was responsible for developing PuffPal. Nilsen says Nefos is parting ways with 9Series and plans to rebuild the app with independent security verification. Nefos has since shut down PuffPal and the vulnerable APIs, and Nilsen confirmed the company is in contact with Ireland’s Data Protection Commission about the breach.
The response was slow, however. Nefos took five days to reply after being contacted, temporarily re-exposed passport images after clubs complained, and failed to meet the EU’s 72-hour breach disclosure requirement — a violation Nilsen acknowledged will likely result in fines. As of June 10, 2026, Azdoufal’s tests indicate the passport images and personal data are no longer publicly accessible.
Source: The Verge