RC RANDOM CHAOS

Nearly a million passports and IDs left on the open web by age-check platform

· via Hacker News

Original source

One million passports leaked online

Hacker News →

Close to one million passport scans and photo IDs from several European countries sat on public web servers with no password, encryption, or access controls, reachable by anyone who knew the URL. The Verge reports the documents stayed exposed for months before being pulled offline. There was no hack and no ransomware — just raw identity documents served up by default, a misconfiguration that security researcher Sammy Azdoufal warned would be scraped and resold before it could be fixed.

The data traces back to Nefos, operator of PuffPal, a platform that handles membership and age verification for cannabis clubs and retailers across Europe. Documents collected to prove customers’ ages — full passport and driver’s license scans with names, photos, and ID numbers — were stored with no authentication, no rate limiting, and no access logging, meaning the window of exposure and the volume of bulk downloads are unknown. Neither Nefos nor the clubs using the platform have issued a public statement.

The lasting damage is that government IDs can’t be reset like a password. Stolen passport and license scans feed identity theft, credit fraud, and account takeover, and victims face slow, cross-border reissuance processes while criminals can exploit the documents for years. The incident is a pointed reminder that any company hoarding identity documents for verification needs demonstrated technical controls, not a promise to ‘store them securely’ — and it leaves open whether EU regulators will pursue penalties or offer affected individuals any recourse.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.