One Million Passport Scans Leaked After Cannabis Dispensary System Hacked
Passport scans from people worldwide were exposed online after a system used by cannabis dispensaries was breached, putting personal identification at risk.
Source
Schneier on Security
Original headline: One Million Passports Leaked Online
Plain-English summary by GetCyberRight. Read the full report at the source above.
A database containing nearly one million passport scans from people around the world was leaked online. The passports were collected by cannabis dispensaries in the United States for age verification purposes. When customers wanted to prove they were old enough to purchase cannabis legally, they showed their passports, which were scanned and stored digitally. Hackers broke into this database and now those passport images are publicly available.
If you have ever visited a cannabis dispensary in the U.S. and showed your passport for identification, your passport scan may be in this leak. Your passport contains highly sensitive information including your full name, date of birth, passport number, photograph, and sometimes your address. This information could potentially be used for identity theft or to create fake documents.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
Even if you do not use cannabis, this story is important because it shows how your sensitive documents can end up in unexpected places.
Here is what you should do right now:
- If you used your passport at a cannabis dispensary, assume your information was exposed.
- Monitor your credit reports closely for any suspicious activity. You can get free credit reports at AnnualCreditReport.com.
- Consider placing a fraud alert on your credit file by contacting one of the three credit bureaus.
- Watch for phishing emails or calls from people who might have your personal information and try to trick you into giving them more.
- If you notice any suspicious use of your identity, report it immediately to local law enforcement and the Federal Trade Commission at IdentityTheft.gov. The bigger lesson here is to think carefully before handing over high value identification like passports. Whenever possible, use a driver's license instead of a passport for everyday verification like age checks at stores. Your passport is a powerful document meant for international travel, not routine transactions. Once someone scans it and stores it digitally, you have no control over how well they protect that information. Companies with low security standards can put your most important credentials at risk.
Curated from trusted cybersecurity sources by GetCyberRight
Source: Schneier on SecurityStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Signal Backup Keys: The New Target in Phishing Scams
Russian intelligence groups are phishing for Signal backup keys to access your message history. Here's what you need to know to protect your private conversations.
4 min readJaguar Land Rover Cyberattack Cost UK Economy $2.5 Billion
A single ransomware attack on a car manufacturer caused massive economic damage, affecting thousands of businesses and driving car production to historic lows.
2 min readMassive Jaguar Land Rover Cyberattack Cost Billions and Affected Thousands of Businesses
A ransomware attack on one car company had ripple effects across 5,000 businesses and damaged an entire country's economy. Here's the larger lesson.
2 min read
Russian Hackers Are Targeting Signal Backup Keys to Read Your Messages
Intelligence agencies warn that Signal users are being phished for backup recovery keys, giving attackers access to encrypted message history.
4 min read