Almost a Million Exposed Passports: The Software Flaw for European Cannabis Clubs
Almost a million identity documents, passports, and driver’s licenses were left accessible without any protection on public URLs managed by Nefos Solutions (formerly Cannabis Club Systems), an Irish company that provides management software to European cannabis clubs. The breach was discovered by security researcher Sammy Azdoufal by decompiling PuffPal, Nefos's optional app for managing club access.
The starting point was PuffPal itself: during the decompilation, Azdoufal found a Stripe secret key in plaintext within the app's code. The investigation revealed a chain of vulnerabilities. The identity documents uploaded by users were reachable via URLs with a trivial structure, requiring no form of authentication for access. At a rate of 5,000 new documents uploaded per day, the exposed database was constantly growing.
Cascade Vulnerabilities
Access to passports was only the visible part; even more problematic was the fact that all user profile data could be retrieved with a simple curl command structured in such a way as to include, among the arguments, the ID related to each user's profile. By simply modifying the ID number, one could access passport numbers, phone numbers, email addresses, home addresses, and cannabis consumption preferences for all members.
I joined a weed club in Barcelona. They handed me an app and said "it's more convenient." By sunrise I was looking at 1,082,680 strangers' passports. Convenient indeed. Thread🧵
— Sammy Azdoufal (@n0tsa)
June 10, 2026
The Nefos admin portal was accessible via public internet, clubs used weak passwords theoretically crackable in minutes with a modern GPU, and private messages between clubs and users through PuffPal were also vulnerable. The responsibility for developing PuffPal and the faulty APIs lies with 9Series, the outsourcing company to which Nefos had entrusted the work.
Response and Current Situation
Azdoufal discovered the vulnerabilities in May. Azdoufal's analysis reconstructs how Nefos took five days to respond and initially attempted to patch the gaps rather than addressing the risks to users. On June 4th, Azdoufal verified that his passport was online again without protection. On June 9th, even after Nefos had added access tokens to the images, all other profile data remained easily accessible.
As of June 10th, Azdoufal's tests yielded different results: passports and personal data were protected. Nefos is shutting down the entire PuffPal system and the vulnerable APIs pending a consolidation, has notified local authorities, and the Ireland Data Protection Commission, and has terminated the relationship with 9Series. Co-founder Andreas Nilsen stated that there is no evidence that third parties, besides Azdoufal, accessed the data and acknowledged that EU regulations required notification within 72 hours of discovering the breach.
For users of European cannabis clubs who uploaded documents via the Nefos system, the breach involves particularly sensitive data: an official document linked to home addresses and substance use information forms a profile that exposes them to tangible risks, even if the access surface is now closed. Nefos plans to launch a new independently verified app within a few months.