Nearly a Million Passports and Photo IDs Exposed Unprotected on the Public Internet
Nearly a Million Passports and Photo IDs Exposed Unprotected on the Public Internet
By Decode Today News
In a stark reminder of persistent vulnerabilities in digital data handling, nearly a million identity documents, including passports and driver's licenses, were left openly accessible on the public internet. This critical security lapse, uncovered by a leading researcher, exposed sensitive personal information belonging to individuals worldwide, highlighting an urgent need for enhanced data protection practices across the digital landscape.

The astonishing discovery involved over 985,000 photo IDs sitting at public URLs, devoid of any password protection or access controls. These documents included the passports of individuals from Germany and Spain, along with the front and back images of various national driver's licenses. The sheer scale of the exposure meant that these highly personal identifiers were just a few clicks away for anyone with the right link, posing a significant risk of identity theft and privacy breaches.
The alarm was first raised by security researcher Sammy Azdoufal, known for his previous work in identifying critical flaws in devices like DJI Romo robot vacuums and a million baby monitors and security cameras. Using automated tools, Azdoufal was able to catalog the vast repository of unprotected documents. "We have to do something about it as fast as possible, because people will find this and resell it. It will do damage," Azdoufal warned in May.
The Source of the Leak: Cannabis Club Systems
The compromised data primarily originated from an Irish company named Cannabis Club Systems (CCS), formally Nefos Solutions. Nefos develops and provides the software used by numerous cannabis clubs, particularly in Spain, for operations ranging from sales and accounting to admissions. A key feature of their system is an ID verification process where club receptionists upload members' identity documents and selfies to Nefos's cloud for storage and retrieval.
Traditionally, club visitors would present their ID upon each entry. However, the Nefos system allowed clubs to pull up stored identity documents and verify faces, streamlining the process. An optional companion app, PuffPal, further simplified entry through QR code scanning. It was through the decompilation of this PuffPal app that Azdoufal unearthed the shocking extent of the security failures.
Within the PuffPal app, Azdoufal found a secret key for the Stripe payments platform stored in plain text, a critical oversight. More alarmingly, he discovered that by simply altering a single numerical digit, he could access any member's profile. These profiles often contained highly sensitive details: phone numbers, home addresses, passport information, preferred cannabis strains, and even monthly consumption amounts. Celebrities and visitors from around the globe, including an estimated 30,000 from the United States, were among those whose data was exposed.
Public URLs and Weak Security
The most egregious flaw was how the identity documents themselves were stored. Passport and driver's license images were hosted at publicly accessible URLs, following a simple, predictable pattern like https://ccsnubev2.com/v8/images/_{club}/ID/{user_id}-front.jpg. This structure meant that anyone who could guess or infer the necessary parameters could directly access these images without any authentication whatsoever. Azdoufal reported that these clubs were uploading approximately 5,000 new photo IDs to these insecure URLs every single day.
Further investigations revealed an admin portal for the cannabis clubs was also accessible via the public internet. The security protecting these club accounts was equally trivial, with passwords that could theoretically be cracked within minutes using modern computing power. Even private chat messages exchanged between clubs and members through the PuffPal app were found to be vulnerable, adding another layer to the extensive privacy breach.
Company Response: A Delayed and Faltering Fix
Initially, Nefos Solutions proved slow to respond to Azdoufal's findings. It took roughly a month after Azdoufal’s initial outreach, and five days after media inquiries, for the company to begin taking meaningful action. Nefos co-founder Andreas Nilsen told media that he has since been in communication with Ireland's Data Protection Authority (DPC), a fact confirmed by a DPC spokesperson.
Nefos claims it is now shutting down its entire PuffPal system and vulnerable APIs until necessary fixes can be implemented. Azdoufal's most recent tests indicated that passport images and personal data indeed seemed more secure. Nilsen stated that the company will take responsibility for the fixes, pay any applicable fines, and notify affected users. He also asserted that there is currently no evidence of any outside access to the data beyond Azdoufal's research.
However, the path to resolution was not straightforward. Early attempts by Nefos to patch the vulnerabilities were incomplete. At one point, after initially locking down image access, Nefos temporarily re-enabled it because clubs complained that the images weren't showing up correctly. Nilsen claimed the images were locked down "70 percent of the time," but this prioritization of business functionality over critical security exposed users for longer. Furthermore, even after image access was tokenized, other crucial user profile data—including passport numbers, phone numbers, email addresses, and home addresses—remained easily accessible through simple command-line queries.
Nilsen attributes much of the blame for the initial security failings to 9Series, an outsourcing firm he claims was responsible for developing the PuffPal app and its vulnerable APIs. Nefos has stated it is parting ways with 9Series and plans to launch a new, independently verified secure application within a few months. Nilsen is aware that under EU law, his company was legally obligated to disclose the breach within 72 hours and expects to face penalties for not doing so.
The Broader Implications for Internet Security
This incident serves as a stark warning about the pervasive challenges in maintaining data security in the digital age. The exposure of nearly a million identity documents underscores how easily critical personal information can be left vulnerable when software development lacks a robust security-first approach. The ramifications for those affected are severe, ranging from potential identity theft and financial fraud to unwanted public exposure of private activities.
The situation with Nefos Solutions is not an isolated one. Just last month, the UK Visa Portal similarly exposed at least 100,000 passports to anyone who could guess a URL. These recurring incidents highlight a systemic problem: many organizations, despite handling highly sensitive data, often fail to implement fundamental security protocols, leaving vast amounts of information unprotected on the open internet.
A Wake-Up Call for Corporate Responsibility
The extensive breach orchestrated through Nefos's systems calls into question the responsibility of companies that collect and store sensitive user data. While outsourcing development can offer efficiency, the ultimate burden of ensuring robust security and regulatory compliance remains with the primary service provider. Companies must adopt proactive security measures, conduct regular audits, and establish clear incident response plans to protect their users.
For individuals, this news reinforces the importance of vigilance. While users cannot directly control a company's security practices, understanding the risks associated with sharing personal data, even with seemingly legitimate services, is crucial. This incident should prompt a broader conversation about how personal data is managed, the legal frameworks governing data protection, and the severe consequences when these protections fail.
The Path Forward for Digital Security
The Nefos data breach is a potent example of how quickly and broadly sensitive information can be compromised when basic security measures are overlooked. While Nefos has pledged to rectify the situation, including working with authorities and developing a new secure platform verified by independent researchers, the incident has already inflicted considerable damage to user trust and privacy.
This episode serves as an unequivocal call to action for every organization operating online. The constant evolution of cyber threats demands continuous vigilance, investment in advanced security technologies, and a culture that prioritizes data protection at every stage of software development and data management. Only through such commitment can the global internet community hope to safeguard the digital identities of its users against increasingly sophisticated threats.