More than 50,000 British nationals were reportedly listed in records caught up in the cannabis club identity-document security scare. Credit: Max_555 / Shutterstock
If you have ever handed over your passport to join a cannabis club in Spain, you may want to pay attention to this.
More than 50,000 British nationals and around 12,000 Irish passport holders appear in records caught up in a huge security scare after almost one million passport and identity document scans were reportedly left accessible online.
A security researcher investigating the system identified 50,113 British nationals in the database, while fresh reporting by The Journal revealed that around 12,000 Irish passports were also among the records potentially exposed.
For anyone who remembers handing over their passport at one of these clubs, the obvious question is: was yours among them?
Why Spain is at the heart of the passport scare
Cannabis social clubs are particularly common in Spain, with estimates cited by The Journal putting their number at between 1,000 and 2,000 nationwide.
Unlike Amsterdam-style coffee shops, they generally operate as private associations. Prospective members may therefore be asked to register and prove their identity and age, sometimes by handing over a passport or another form of identification.
Some clubs used membership technology supplied by Cannabis Club Systems (CCS), an Irish-registered company formerly known as Nefos Solutions. Reception staff could upload customers’ identity documents to the system for verification, creating an enormous central collection of personal information.
Security researcher Sammy Azdoufal says the affected system contained 985,841 identity-document scans, including passports, identity cards and driving licences. His published account of the investigation lists 50,113 member records with British nationality.
However, not every British or Irish document necessarily came from a club in Spain. The researcher says the software was used by 377 clubs across Spain, the UK, Ireland, South Africa and elsewhere, although many were based in Spain.
How were the passports exposed?
According to the researcher, identity-document images were stored at predictable web addresses that did not require a login, password or security token. Anyone who understood the address pattern could potentially view the documents using an ordinary web browser.
That does not establish that criminals downloaded or misused the files. CCS disputes descriptions of the incident as a confirmed public data leak, saying it has found no verified evidence that personal information was extracted, published or distributed. Its investigation into the historical extent of any unauthorised access remains ongoing. The company says the reported vulnerabilities have been fixed and that the previously identified access points are no longer publicly accessible.
The Journal reported that Ireland’s Data Protection Commission is engaging with the Irish-registered company. The regulator has not made any finding of wrongdoing.
Spain has already warned about copying IDs
The case echoes something Spanish authorities have already been warning consumers about. As Euro Weekly News previously reported, businesses retaining complete copies of passports or identity cards can create risks that people may not consider when handing them over.
Spain’s Data Protection Agency says that, as a general rule, a complete copy of an identity document is not necessary simply to verify someone’s identity when entering a contract. However, it notes that sector-specific laws, including anti-money-laundering rules, can require copies in some circumstances.
One worrying aspect of the exposure is that passport details falling in to the wrong hands can make identity fraud and targeted scams considerably more convincing. Whilst another obviously sensitive element in this case is that the documents were connected to cannabis club memberships, potentially linking identifiable individuals with membership of a cannabis association.
Cybersecurity specialist Brian Honan told The Journal that such information could be exploited for scams or blackmail if it fell into the wrong hands.
Should British or Irish passport holders do anything?
There has been no reported blanket instruction telling affected British or Irish citizens to replace otherwise valid passports. Anyone who believes they may be affected should contact the club or CCS through official contact details rather than following links in unexpected messages. The UK’s National Cyber Security Centre advises people concerned about a data breach to remain alert for suspicious communications and check their accounts for unauthorised activity.
Be particularly cautious about unexpected emails, calls or messages containing genuine personal information. Never provide banking details, passwords or security codes simply because the person contacting you appears to know who you are.
If a physical passport has actually been lost or stolen, British citizens should use the government’s official lost or stolen passport service, while Irish citizens in Spain can follow the Embassy of Ireland’s guidance.
But for people whose passport is still safely sitting at home, the concern is different. 50,113 British nationals. Around 12,000 Irish passports. Almost one million identity document scans.
If you remember handing your passport across the reception desk at a cannabis club, you may now be wondering the same thing: Was yours one of them?