Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

1.08M cannabis users data leaked in PuffPal disclosure

A data breach at PuffPal, a cannabis-focused social platform, has leaked records of over 1.08 million users, including personal details and cannabis consumption data.

Background

- PuffPal is a social-tracking app that lets cannabis users log their consumption, share strain reviews, and connect with other users. - The breach exposed 1.08 million users' personal data, including email addresses, usernames, geolocation data, and consumption logs (strain preferences, frequency, etc.). - Cannabis-related data is particularly sensitive because cannabis remains illegal at the U.S. federal level (though legal in many states); a data leak could expose users to legal risk, employment discrimination, or social stigma. - The disclosure was made via GitHub (repository "because-i-got-high") by a security researcher or whistleblower posting the breach details publicly — a tactic used to force a response when the company fails to notify affected users or patch vulnerabilities.

Related stories

  • PuffPal, an app used by Spanish cannabis clubs for age verification, leaked over one million users' passport photos and personal data due to weak security. A researcher found hardcoded API keys and publicly accessible image URLs. The breach exposed celebrities and international visitors, highlighting risks of using high-value credentials in low-security systems.