An online database vulnerability exposed nearly 985,000 passport images, driver’s licenses, and photo IDs belonging to members of Spanish cannabis clubs, according to reports from security researcher Sammy Azdoufal and technology website The Verge. The exposed documents—which included 12,000 Irish passports and 30,000 U.S. records—were left accessible at public URLs without password protection for months, prompting engagement from the Irish Data Protection Commission.
Software Developed by Irish-Registered Firm Left IDs Exposed
The affected data was managed by Cannabis Club Systems (CCS), an Irish-registered software company also known as Nefos Solutions, with an office listed on Harcourt Street in Dublin 2. According to security researcher Sammy Azdoufal, who decompiled the company’s PuffPal app in May, the software allowed club receptionists to upload member identity documents and selfies to cloud servers for verification. However, the files were stored at predictable URLs, such as https://ccsnubev2.com/v8/images/_{club}/ID/{user_id}-front.jpg, allowing anyone with the correct pattern to access them without authentication. Azdoufal estimated that clubs were uploading roughly 5,000 new photo IDs daily to these insecure locations.
Technical Flaws and Delayed Remediation Efforts
The security gaps extended beyond open URLs. Azdoufal discovered a Stripe payment platform secret key embedded in plain text within the PuffPal application, alongside a public-facing admin portal and club accounts secured by weak passwords. When The Verge and researchers first flagged the vulnerabilities, CCS co-founder Andreas Nilsen took five days to respond. In a June statement on the company website, Nilsen confirmed that backend services were temporarily suspended while vulnerabilities were remediated, adding that the company had not found evidence of unauthorized access beyond the initial discovery. However, Azdoufal found that data remained accessible even after initial patches; on June 4, passport images were unlocked again after cannabis clubs complained about app display issues, and on June 9, user profile details—including home addresses, phone numbers, and consumption preferences—could still be queried via the API.
GDPR Risks and Legal Fallout for CCS
Dublin-based security expert Brian Honan warned that the exposure of such records carries severe regulatory and criminal risks under the European Union’s General Data Protection Regulation (GDPR). Because Spanish cannabis clubs register members for medicinal or age-verification purposes, Honan noted that the data constitutes sensitive health information under EU law. Under GDPR provisions, organizations face potential penalties of up to €20 million or 4% of global annual turnover for failing to secure sensitive personal data. Nefos Solutions has contacted the Irish Data Protection Commission regarding the incident, while the DPC confirmed it is engaging with the company. CCS has since shut down the PuffPal system and vulnerable APIs entirely while parting ways with 9Series, the outsourcing firm that originally developed the app and its APIs.
Did you know?
Spanish cannabis clubs operate on a strict membership-only model distinct from open commercial dispensaries or Amsterdam coffee shops, requiring identity verification for entry.
Frequently Asked Questions
Who was responsible for securing the exposed cannabis club database?
Cannabis Club Systems (CCS), also known as Nefos Solutions, was responsible for the software and cloud infrastructure used to process member admissions and identity verifications for Spanish cannabis clubs.

How many people were impacted by the database vulnerability?
Security researcher Sammy Azdoufal estimated that approximately 985,000 photo IDs and user profiles were jeopardized, including records for 12,000 Irish citizens and 30,000 individuals from the United States.
Has the Irish Data Protection Commission taken action?
The Data Protection Commissioner’s office confirmed to The Journal that it has been engaging with CCS regarding the security concerns, though no formal findings of wrongdoing have been issued.
What types of data were accessible on the public internet?
Exposed records included passport images, driver’s licenses, phone numbers, home addresses, email addresses, and personal cannabis consumption preferences.
Stay Informed on Data Security
Subscribe to our newsletter for ongoing updates on cybersecurity incidents, GDPR enforcement, and privacy regulations.
Keep reading