One Million Passports Leaked Online
A database of nearly one million passport images, collected by an ID verification system used by cannabis dispensaries, was exposed online. The breach illustrates how sensitive government-issued credentials end up stored in peripheral, lower-security systems far removed from the original purpose of the document.
Why this matters: Your passport is one of the most valuable pieces of ID you own. But you hand it over constantly — to apps, dispensaries, landlords, and other services that have no real obligation to protect it like a bank would. The security you get is whatever that third-party vendor bothered to build. This breach did not come from a government system. It came from a weed shop's ID scanner. That gap between the value of the credential and the security of the system holding it is where people get hurt. Anyone whose passport was scanned there now has that document floating around with no way to revoke it.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.