TL;DR: Nefos, the Irish software vendor behind PuffPal, an age and membership verification platform used by cannabis clubs and retailers across Europe, stored nearly one million passport scans and driver licenses on servers reachable by anyone with a URL. No password. No encryption. French security researcher Sammy Azdoufal found the cache and reported it on June 10, 2026. As of June 26, affected users had not been notified, and the EU’s 72-hour breach disclosure rule had either been missed or was being treated as a question. Bruce Schneier used his June 26 newsletter to point at the cache and call the underlying pattern what it is: a high-value credential (a passport) handed to a low-value system (cannabis age checks) that became a single breach away from identity fraud for almost a million people.
What Happened
Sammy Azdoufal, a French security researcher, found a publicly reachable directory containing roughly 985,000 passport photos and other photo IDs from multiple European countries [1]. The cache included full passport scans, driver licenses with photos, names, and identifying numbers. The full set was left open on the open internet, with no password protection and no encryption on the document storage layer.
The cache was not the result of a sophisticated intrusion. There was no zero-day, no phishing campaign, no extortion note. The documents were simply left there [1]. Anyone who knew or guessed the right URL could pull them.
Nefos, the Ireland-based software company whose PuffPal platform processes membership and age verification for cannabis clubs and retailers across Europe, is the data controller [1]. The vulnerability was in APIs that another vendor, 9series, built for the platform. Nefos told the press it is now in contact with Ireland’s Data Protection Commission and is parting ways with 9series [1]. No official statement from Nefos or any of the cannabis clubs using PuffPal has been published at the time of writing.
The Timeline
The exact date the documents first became reachable is not in the public reporting. Schneier picked the story up on June 26 and used it as the lead of that day’s newsletter [1].
Two facts stand out. First, the documents sat exposed for long enough that the cache is best understood not as a one-off bug but as the default state of the system. Second, affected users had not been notified as of late June 2026 [1]. Under the EU’s General Data Protection Regulation, a personal-data breach must be reported to the relevant supervisory authority within 72 hours of becoming aware of it, and affected data subjects must be informed “without undue delay” when the breach is likely to result in a high risk to their rights. A passport scan plus name plus date of birth plus driver license number is exactly the kind of data set that triggers the high-risk threshold. Whether Nefos met the 72-hour clock is one of the open questions the Irish Data Protection Commission is now positioned to answer.
Why This Is the Surveillance Story
It is tempting to file this under “breach of the week.” Don’t. This is the surveillance story of the week, and arguably of the year.
Every mandatory ID check, whether it is at a cannabis dispensary, an adult website, a social media platform, or a bank, asks the user to hand over the single highest-value identity document most people own. A passport is the credential you use to cross borders, open bank accounts, prove citizenship, and recover a stolen identity. Stolen passport data is the raw material for synthetic identity fraud, account takeover, immigration fraud, and impersonation at scale. There is no over-the-counter commodity in identity crime that is worth more per record.
The PuffPal leak put almost a million of those records on a server with no password. The reason that matters is the structural one Schneier named in his June 26 note: a high-value credential was used in a low-value authentication system, and it is the low-value system that got hacked [1]. Cannabis age verification is not border security. The threat model for a club door check is “is this person 18,” not “protect a top-tier government credential from nation-state attackers for the next forty years.” The system was built, configured, and operated to the threat model of the low-value use case. The data stored inside it belonged to the high-value one.
This is not a one-off. The same week, the Center for Democracy and Technology argued that the Texas App Store Accountability Act would force Apple and Google to verify every minor’s age at the app-store gate. EFF published a parallel warning that the FCC’s proposed “spam call” know-your-customer rules would graft a national identity layer onto every U.S. phone number. Each of these proposals does the same thing the PuffPal stack did: it builds a new ID checkpoint, concentrates high-value credentials in a small number of vendors, and assumes those vendors will hold up under attack. The PuffPal cache is what the assumption looks like when it fails.
Cory Doctorow made the structural case on Pluralistic on June 23, three days before Schneier’s note. Every age-gate mandate, Doctorow wrote, is also a mass-surveillance mandate, because it forces the construction of an identity database that becomes the next breach target. The PuffPal exposure is the first large-scale empirical confirmation of that argument in 2026.
The Vendor Stack and the Vendor-of-the-Vendor
The PuffPal architecture is a reminder that modern age verification is rarely a single product. It is a stack: the dispensary on one end, the platform vendor in the middle, and the API vendor under that. When the press asks “who is responsible,” the answer is usually that the platform vendor blames the API vendor, the API vendor blames the cloud configuration, and the user is left holding a passport scan that is now in someone else’s hands [1].
That diffusion of responsibility is itself a surveillance problem. Regulators in the EU can point at Nefos as the data controller and at 9series as the processor. Users cannot. The club they handed their passport to at the door does not know, and almost certainly never told them, that the verification flow routed through a third-party API vendor with a misconfigured storage layer. The consent screen said “verify your age.” It did not say “send a high-resolution scan of your passport to a vendor whose cloud storage has no password.”
Vendor concentration makes this worse, not better. The PuffPal pattern is identical across age-verification vendors: a small number of platforms serve a large number of retailers, and a smaller number of API vendors serve the platforms. One misconfigured bucket, one leaked API key, one reused password, and the credentials of an entire industry’s customer base land on a public URL. The vendors’ lawyers will negotiate who pays the fine. The users carry the identity fraud for the rest of their lives.
What to Watch
The Irish Data Protection Commission has now received the report. The Commission has authority to fine up to 4% of annual global turnover under GDPR, and breach-notification failures are an enforcement priority across the EU. Expect a formal inquiry, an order to notify affected users, and a fine that lands somewhere on the spectrum between nuisance and material.
Watch for class-counsel interest in Germany and Spain, the two jurisdictions where named documents were sampled. German data protection authorities have been aggressive on age-verification enforcement, and Spanish users have the right to bring civil claims under the LOPDGDD. The combination of named victims, named regulator, and a clear statutory duty is the recipe for litigation.
Watch the U.S. side too. Three of the cannabis clubs operating under PuffPal’s footprint serve U.S. travelers in Europe. If any of those travelers were among the 985,000, the leak crosses into U.S. state breach-notification statutes (California, New York, and Texas all have notification triggers for government-ID imagery). Expect U.S. plaintiffs’ firms to start sniffing around the vendor stack within a month.
The structural question is whether any of this changes the policy debate. It should. The Texas app-store age-verification bill, the FCC’s phone-KYC proposal, the UK Online Safety Act, and Australia’s under-16 social media ban are all variations on the same architectural mistake: build the gate, store the credential, hope the vendor holds. PuffPal is the answer to “what happens when the vendor doesn’t.” The answer is that almost a million people find out their passport is now someone else’s problem.