{"id":626030,"date":"2026-09-16T04:00:12","date_gmt":"2026-09-16T04:00:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/626030\/"},"modified":"2026-09-16T04:00:12","modified_gmt":"2026-09-16T04:00:12","slug":"thousands-of-irish-passports-linked-to-spanish-cannabis-clubs-were-freely-viewable-online","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/626030\/","title":{"rendered":"Thousands of Irish passports linked to Spanish cannabis clubs were &#8216;freely viewable&#8217; online"},"content":{"rendered":"<p>VULNERABILITIES FOUND IN an online database may have seen as many as 12,000 Irish passports sitting in the open and at risk of being picked up by hackers.<\/p>\n<p>The passports are believed to have belonged to users of so-called \u2018cannabis members-only clubs\u2019 in Spain. They are understood to be among almost one million passports and photo IDs that could be publicly accessed for a period in May and June, and potentially longer.<\/p>\n<p>An Irish-registered software company called Cannabis Club Systems (CCS), also known as Nefos Solutions, was in charge of the data.<\/p>\n<p>The Data Protection Commisisoner\u2019s office told The Journal that it has been engaging with the company after the concerns came to light.<\/p>\n<p>The company has said there was no evidence that any outsider accessed the data after the initial vulnerability was reported.\u00a0<\/p>\n<p>CCS develops and provides the software that Spanish cannabis clubs use for everything from sales to membership admissions. This includes a system where receptionists upload IDs to a cloud system for additional verification.<\/p>\n<p>Cannabis clubs are somewhat common in cities across Spain, with some estimates putting the number at between 1,000 and 2,000.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2026\/09\/1789531212_263_.JPEG\"  alt=\"an-interior-view-of-the-420-smokers-club-in-barcelona-spain-27-december-2015-the-city-of-barcelona-is-concidering-steps-to-regulate-the-consumption-of-cannabis-hashish-and-marijuana-photo-ger\" class=\"alignnone inline-image\" \/><br \/>\n            An interior view of a cannabis club in Barcelona, from December 2015.                    Alamy Stock Photo<\/p>\n<p>    Alamy Stock Photo\n<\/p>\n<p>Unlike commercial dispensaries or the open coffee shops found in Amsterdam, these clubs operate on a membership-only model. You need to register with the club and show proof of age before you can consume cannabis on the premises.<\/p>\n<p>However, this has meant that the details of some 985,000 club members may have been jeopardised by the recent leak.<\/p>\n<p>A listing compiled by a security researcher testing the database\u2019s security collected the number of nationalities involved \u2013 it included 12,000 Irish passports, along with 30,000 from the US.\n<\/p>\n<p>What CCS said<\/p>\n<p>CCS has been contacted on a number of occasions by The Journal in recent weeks, but has not responded in time for publication.\u00a0<\/p>\n<p>The company, which was incorporated in Ireland ten years ago, has an address listed at an office at Harcourt Street in Dublin 2.<\/p>\n<p><a href=\"https:\/\/cannabisclub.systems\/en\/noticias-en\/statement-from-cannabis-club-systems\/\" rel=\"nofollow noopener\" target=\"_blank\">In a statement on its website in June<\/a>, its chief technology officer Andreas Nilsen said that it had \u201ctemporarily suspended\u201d backend services for its platform while it reviewed its security.<\/p>\n<p>Nilsen said that \u201cvulnerabilities were identified and remediated\u201d, but that CCS had not found any evidence that personal information was publicly leaked, published, or distributed.<\/p>\n<p>\u201cInvestigations into the historical extent of any unauthorised access remain ongoing,\u201d he said at the time. The company has not issued a public update since, including when contacted by The Journal.<\/p>\n<p>He stressed that \u201creported vulnerabilities have been remediated and the previously identified endpoints are no longer accessible\u201d by members of the public.<\/p>\n<p>CCS \u201ctakes the privacy and security of personal information extremely seriously\u201d, Nilsen continued.<\/p>\n<p>The senior executive said that CCS has worked with regulated cannabis organisations across multiple jurisdictions for over 12 years, and understands that it operates within a \u201chighly sensitive compliance environment\u201d.<\/p>\n<p>\u201cProtecting confidential information remains one of our highest priorities, and we continue to invest in strengthening our security infrastructure and governance processes,\u201d Nilsen said.<\/p>\n<p>There has been no finding of wrongdoing by the DPC in the case.\u00a0<\/p>\n<p>Reporting by US media<\/p>\n<p>In June, <a href=\"https:\/\/www.theverge.com\/tech\/947157\/passports-data-breach-cannabis-club-systems-nefos-puffpal\" rel=\"nofollow noopener\" target=\"_blank\">US tech website The Verge<\/a> reported that hundreds of thousands of passports for people who used cannabis clubs in Spain could be accessed via a \u2018backdoor\u2019 into its database.<\/p>\n<p>The issue came to light after a security researcher allegedly discovered the multitude of passports and IDs sitting unprotected at public URLs, reportedly with no password access required.<\/p>\n<p>This happened, according to The Verge, because a \u2018secret key\u2019 for processing payments was sitting inside an app used by the cannabis clubs.<\/p>\n<p>Brian Honan, a Dublin-based security expert who works across the public and private sector, told The Journal that this can be an all too common occurrence in instances where data was inadvertantly shared.\u00a0<\/p>\n<p>\u201cIt\u2019s basically like somebody has put the key under the doormat, but anybody with access to the doormat can get in. It isn\u2019t good practice to have your key stored in the application,\u201d Honan said, referring to the report containing the allegations.<\/p>\n<p>Nilsen had said in the initial report that there was no evidence that any outsider accessed the data other than the security researcher who discovered the open database.<\/p>\n<p>He added to that the company would \u201ccommunicate to everyone that was potentially exposed\u201d.<\/p>\n<p>GDPR risks<\/p>\n<p>Honan, the data security analyst, warned that companies could face hefty fines if data is found unsecured, as passport leaks could place people at the mercy of scammers.<\/p>\n<p>Honan noted that the use of the cannabis could be categorised as for medicinal purposes, which Spanish cannabis clubs include as part of their membership.<\/p>\n<p>Under GDPR legislation, Honan said that the health data would be deemed to be particularly sensitive, especially if it was \u201cfreely available on the internet\u201d.<\/p>\n<p>\u201cThere is obviously a lot of sensitive, personal data stored in that system. People\u2019s IDs give a lot of information and that can be of use to criminals for scams,\u201d Honan said.<\/p>\n<p>Given the Spanish system allows people to buy cannabis, their country of origin and the laws in place around drug use in those jurisdictions could also be a factor in any risk.<\/p>\n<p>\u201cThe individuals themselves could be at risk, either potentially from scammers who could blackmail you because they have that information, or authorities who could come across that information,\u201d Honan added.<\/p>\n<p>The EU\u2019s GDPR laws can carry tough punishments for health data breaches, with penalties of up to \u20ac20 million or 4% of global annual turnover a danger to a company.<\/p>\n<p>When asked how common such alleged data breaches, as seen in the Spanish cannabis clubs can be, Honan said they remain an issue for many companies handling sensitive information.<\/p>\n<p>\u201cThe challenge we have is that we have many developers who are very good at writing code, but writing secure code is not as widespread as it should be,\u201d Honan said.<\/p>\n<p>\u201cThe onus is not just on the company developing an application or software securely, but under GDPR the company providing the application and the company requesting the development are required to build in privacy and security by design.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"VULNERABILITIES FOUND IN an online database may have seen as many as 12,000 Irish passports sitting in the&hellip;\n","protected":false},"author":2,"featured_media":626031,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[11314,265783,103867,61,60,39347,2846,112,11259],"class_list":["post-626030","post","type-post","status-publish","format-standard","has-post-thumbnail","category-sports","tag-cannabis","tag-cannabis-social-clubs","tag-drug-use","tag-ie","tag-ireland","tag-security-concerns","tag-spain","tag-sports","tag-the-morning-lead"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/626030","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=626030"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/626030\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/626031"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=626030"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=626030"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=626030"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}