A journalist typing a few letters and numbers into a web browser pulled up the passport of a young woman from Germany. Then a Spanish man’s passport. Then another man’s driver’s license. All of it sitting on the public internet with no password, no encryption, no access control whatsoever [1].

Nearly a million passports and photo IDs from multiple countries were exposed across unprotected public URLs, accessible to anyone with a link. The exposure represents one of the largest identity document breaches in recent memory—and it happened because of a fundamental failure in data security practices [2]. The documents were hosted by systems used by cannabis clubs and a company called Nefos, which operates PuffPal, a platform that manages membership and age verification for cannabis retailers and clubs across Europe [3]. The infrastructure storing these identity documents—full passport scans, driver’s licenses with photos, names, and identifying numbers—was left completely unprotected on publicly accessible web servers.

According to guidance from the Federal Trade Commission, stolen passports and driver’s licenses fuel identity theft, document fraud, and account takeover attacks [4]. Research published in PMC’s cybersecurity analysis demonstrates that the healthcare sector continues to suffer some of the highest costs from data security breaches, with identity document exposure creating particularly severe long-term risks for affected individuals [5]. The NIST Computer Security Incident Handling Guide establishes baseline security requirements that were completely absent in this case—no password protection, no encryption, no access logs [6].

Sources

  1. https://cambridgeanalytica.org/surveillance-privacy/uk-age-verification-facial-photos-discord-breach-51199/
  2. https://cambridgeanalytica.org/data-breaches-scandals/amazon-ftc-identity-theft-fine-2-25-million-51189/
  3. https://cambridgeanalytica.org/tech-policy-law/sony-playstation-disc-games-2028-ownership-dmca-51214/
  4. https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business
  5. https://pmc.ncbi.nlm.nih.gov/articles/PMC9123525/
  6. https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-61r2.pdf