Data breach exposes nearly one million cannabis club members worldwide
By
Aurélien BERNARD
Summary
A cybersecurity researcher discovered that nearly a million members of cannabis social clubs and coffee shops had their personal data exposed online due to a vulnerability in CCS Nube, a SaaS platform developed by Cannabis Club Systems (CCS), a business unit of the Irish company Nefos Solutions Ltd. The platform is used by 377 establishments across over 40 countries to manage memberships, identities, and transactions. The breach was uncovered by researcher Sammy Azdoufal, who found the flaw in April 2026 after downloading his club's optional mobile application.
Source
Key quotes
· 3 pulledThe breach comes from CCS Nube, the SaaS platform developed by Cannabis Club Systems (CCS), the business unit of the Irish company Nefos Solutions Ltd, used by 377 establishments in over 40 countries to manage memberships, identities and transactions.
The Sammy Azdoufal, a cybersecurity researcher and himself a member of a Barcelona club, who discovered the flaw in April 2026 after downloading his club's optional mobile application.
Nearly a million cannabis social clubs and coffee shops had their personal data exposed on the Internet for several weeks.
You might also wanna read
Medical Cannabis Patient Data Breach Exposes Sensitive Health Records in Ohio
A security researcher discovered an unsecured database containing nearly a million sensitive medical records of Ohio medical cannabis patien
Unsecured Database Exposes 149 Million Login Credentials Without Protection
Security researcher Jeremiah Fowler discovered an unsecured database containing 149 million unique login credentials including emails, usern
Women's Dating Safety App 'Tea' Data Breach Exposes User Information
Users from 4chan discovered an exposed database belonging to the women's dating safety app Tea on Google's Firebase platform. Personal data
Tea App Data Breach Expands with Exposure of 1.1 Million Private Messages
The Tea app, a women-only dating safety platform, has suffered a significant data breach, with stolen data including 1.1 million private mes
Instagram Data Breach Exposes Personal Information of 17.5 Million Users
A data breach at Instagram exposed sensitive personal information of 17.5 million users, including usernames, physical addresses, phone numb
Substack Confirms Data Breach Affecting User Email Addresses and Phone Numbers
Substack has confirmed a data breach where an unauthorized third party accessed user data including email addresses, phone numbers, and inte
