Eighty-eight thousand South Africans had their national ID documents and passport photos stored in a database that a security researcher could access by changing a single number in a web address, with no password, no login, and no hacking required. The database belonged to Cannabis Club Systems, a Dublin-registered software company that runs digital membership and compliance systems for cannabis dispensaries across Spain, the Netherlands, and other European markets. South Africa was the second-most-affected country out of 40. The company ignored four warning emails over 26 days.
What happened
Cannabis Club Systems provides point-of-sale and member management software to cannabis clubs across Europe. Because dispensaries in Spain and the Netherlands are legally required to verify member identity before granting access, the platform collects what amounts to a KYC (Know Your Customer) file on every member: full name, phone number, ID or passport number, a photograph of that document, and a record of monthly cannabis consumption.
In April 2026, French security researcher Sammy Azdoufal discovered that records in the PuffPal member management platform, Cannabis Club Systems' customer-facing product, were exposed through an Insecure Direct Object Reference (IDOR) vulnerability, a well-documented and entirely preventable class of security flaw where an application uses predictable identifiers to retrieve records with no authentication check on whether the person making the request is authorised to see them. Azdoufal changed a single digit in a URL, pulled back a complete stranger's profile, wrote a script, ran it overnight, and had 1,082,680 records by morning. He sent Cannabis Club Systems four emails over 26 days with no response. CCS states it acted on the information upon receipt; the company's statement does not address the period of non-response.
Each exposed record contained a full name, ID or passport number, phone number, a photograph of the relevant document, and monthly cannabis consumption data. Cannabis Club Systems is registered in Dublin, which means the General Data Protection Regulation (GDPR) governs the breach rather than the Protection of Personal Information Act (POPIA). CCS has confirmed it notified the Irish Data Protection Commission as part of its response. The Information Regulator of South Africa has no direct jurisdiction over the company, and South Africans affected have no recourse through their own regulator.
Why this hits harder here
South African identity documents are the keys to proving who you are in almost every formal system. Banks use them for KYC checks when opening accounts or approving loans, activating a SIM card under the Regulation of Interception of Communications Act (RICA) requires one, and everything from vehicle finance applications to medical aid onboarding and business registrations runs through the same documents. A leaked copy of your ID or passport combined with your phone number and a photograph gives a fraudster most of what they need to impersonate you on paper.
The underlying fraud environment makes this exposure more serious than it would be in most other countries. TransUnion's 2024 research flagged a 153% year-on-year increase in synthetic identity fraud in South Africa, where fraudsters combine real elements from multiple people's profiles to construct false identities for credit applications. The South African Banking Risk Information Centre (SABRIC) 2024 Annual Crime Statistics reported that digital banking fraud incidents rose 86% in a single year, with gross losses rising 74% from the previous year. The Information Regulator received 2,374 security compromise notifications in the 2024/25 financial year, with monthly averages climbing a further 40% into early 2026, according to figures published at the regulator's media briefing in November 2025.
The exposed records include cannabis consumption data alongside identity documents, which means a fraudster or data broker now holds both your identifying information and a personal lifestyle detail you almost certainly did not intend to share widely. GDPR classifies health-related personal data as a special category requiring extra protection. Cannabis Club Systems applied none.
For business owners reading this, the POPIA implication runs differently. If your company collects ID documents through any third-party platform, whether for KYC, RICA compliance, access control, or any other purpose, you are a responsible party under POPIA for the personal information you hand to that operator. If the operator does not maintain adequate safeguards, your obligation to notify affected data subjects after a breach remains. The Cannabis Club Systems exposure is a reminder that the security posture of every platform in your processing chain is your concern, not just the platform provider's.
What to do this week
- Pull your free annual credit report from TransUnion or Experian South Africa. Both offer one free report per year. Look for credit enquiries, new accounts, or loan applications you did not initiate. A leaked ID document combined with a phone number is enough to pass many application checks, and early detection is what allows you to dispute fraudulent accounts before they damage your credit profile.
- Contact your bank and ask whether any credit applications have been submitted against your ID number in the last 90 days. Call the fraud line directly. You do not need to have lost money to make this call.
- If you have ever signed up for a European cannabis club or dispensary platform, treat your ID documents as potentially in scope. Cannabis Club Systems has published a statement confirming the vulnerabilities existed and are now remediated. The company disputes that data was extracted or distributed publicly, though that investigation remains open. Absence of a confirmed extraction does not confirm your records were unaffected during the period the vulnerability was active.
- Place a fraud alert on your credit profile through TransUnion or Experian. A fraud alert requires lenders to take additional verification steps before approving new credit in your name. It takes one call or a short online form to activate, and you can remove it once you are satisfied the risk has passed.
- If you believe your documents are already being used fraudulently, report the matter to the South African Police Service (SAPS) and to the Information Regulator at inforegulator.org.za. The regulator cannot act directly against Cannabis Club Systems, but a formal record of the harm supports any downstream dispute or legal process and creates the paper trail that fraud investigations need.
Where Ubuntu Guard fits
If you received a breach notification, suspect your ID documents are already circulating, or want to understand what third-party platforms your business uses to process staff or client identity data, our incident response service starts with a clean assessment of your actual exposure and a plain-language report on what to do next. We work from verified facts, not guesswork, and we know what POPIA requires of you and by when.
Think your ID is already out there? WhatsApp us now. We respond fast: wa.me/27791595040
Cybersecurity Made Simple
© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za