Thousands of Irish passports exposed in unsecured Spanish cannabis club database
An online database used by Spanish cannabis clubs left up to 12,000 Irish passports publicly accessible, raising concerns over data security.
A security researcher uncovered that a cloud-based platform used by Spanish cannabis clubs exposed personal documents, including up to 12,000 Irish passports, to anyone with the URL. The software, provided by Cannabis Club Systems (also known as Nefos Solutions), allows club staff to upload IDs for member verification. After the flaw was reported, the firm temporarily shut down backend services, fixed the identified vulnerabilities and claims no outsider accessed the data beyond the researcher who reported it.
The Irish Data Protection Commissioner has opened an investigation, though no formal finding of wrongdoing has been issued. The breach potentially puts members at risk of scams or blackmail, especially because health-related data may also be involved under GDPR rules. Experts warn that such lapses are common when developers store secret keys insecurely, and companies could face substantial fines for non-compliance.
Why it matters
Exposed passports can lead to identity theft, scams, and legal risks for individuals and highlight gaps in data-security practices.
In this story
