Skip to content
Safety · Jun 26, 2026

Nearly one million passports exposed in online database leak

A database containing passport images and personal data was left unsecured, highlighting systemic risks in identity verification systems.

Trust79
HypeLow hype

2 sources · cross-referenced

ShareXLinkedInEmail
TL;DR
  • A database containing images of nearly one million passports from multiple countries was exposed online without authentication or encryption.
  • The leak originated from a third-party identity verification system used by cannabis dispensaries, illustrating how low-value authentication chains can compromise high-value credentials.
  • The breach was discovered by a French security researcher and reported to affected authorities, including Ireland’s Data Protection Commission.

A database containing images of nearly one million passports from multiple countries was left exposed on the open internet without authentication or encryption, according to a report by Schneier on Security. The leak was discovered by French security researcher Sammy Azdoufal and linked to a third-party identity verification system used by cannabis dispensaries.

The exposed data included passport images and associated personally identifiable information, which were stored with no access controls, audit trails, or encryption. Security experts characterized the storage practices as negligent, noting that such sensitive credentials require the same level of protection as financial vaults.

The software company Nefos, which provided the identity verification service, confirmed to The Verge that it is communicating with Ireland’s Data Protection Commission (DPC) about the breach. Nefos stated it is notifying individuals potentially affected and is ending its relationship with the vendor 9series, which developed the vulnerable APIs. The company acknowledged potential penalties under EU law for failing to disclose the breach within 72 hours.

The incident highlights the risks of using high-value identity documents, such as passports, in low-value authentication systems. Security analysts argue that organizations handling such sensitive data must implement robust access controls, encryption, monitoring, and incident response plans to prevent misuse and erosion of public trust.

Sources
  1. 01Schneier on SecurityOne Million Passports Leaked Online
  2. 02The VergeCompany behind passport leak says it’s notifying regulators and affected individuals
Also on Safety

Stories may contain errors. Dispatch is assembled with AI assistance and curated by human editors; despite the trust-score filter, mistakes happen. We correct publicly — every article links to its revision history. Nothing here is financial, legal, or medical advice. Verify before relying on any claim.

© 2026 Dispatch. No ads. No sponsorships. No paid placement. Reader-supported via Ko-fi.

Built by a person who cares about honest AI news.