Ireland's Data Protection Commission (DPC) is engaging with Dublin-registered software provider Cannabis Club Systems after security vulnerabilities exposed up to 12,000 Irish passport records and photo IDs on the open internet.
The exposed records were part of a wider security incident impacting nearly one million passport and identity records worldwide. Cannabis Club Systems, formally registered as Nefos Solutions Ltd, provides digital membership, verification, and management software used by hundreds of cannabis social clubs and dispensaries across Spain, the Netherlands, and other international jurisdictions.
The security flaws were initially uncovered by independent cybersecurity researcher Sammy Azdoufal during an analysis of PuffPal, a mobile application developed by the firm to manage club memberships. According to the researcher's published findings, the platform's backend infrastructure stored user identification images at unencrypted, publicly accessible web addresses and contained hardcoded credentials, allowing user profiles and uploaded documents to be accessed without authentication.
In response to the disclosure, Cannabis Club Systems stated that it took immediate action to remediate the identified vulnerabilities, temporarily suspended backend services for the PuffPal application, and launched an internal investigation. The company confirmed that it notified the Data Protection Commission in Ireland regarding the matter.
A spokesperson for the Data Protection Commission confirmed that the watchdog is in communication with the company to examine the circumstances of the incident under General Data Protection Regulation (GDPR) frameworks. Company representatives stated that while vulnerabilities were patched, investigations into the full extent of any unauthorized data access remain ongoing.
Discussion
Sign in with Google to comment