Somewhere out there, a person handed over their passport to buy a bag of gummies. They were proving they were old enough to shop at a cannabis dispensary. That passport, along with almost a million others from around the world, is now sitting in a database that someone left open on the internet. A high-value government credential, scooped up by a low-value age-check system, exposed by the weakest link in the chain. If you needed a single image to explain why data minimization is a cybersecurity problem and not a paperwork problem, this is it.

Bruce Schneier flagged the leak this week, and the detail that matters isn’t the number. It’s the mismatch. The passport was never meant to live in an ID-verification tool for dispensaries. It ended up there because someone decided “scan your ID” was easier than building a real age gate. The system that got popped was the throwaway one. The credential it held was anything but.

The attacker decides what your data is worth

Here’s the part that trips up a lot of teams. You scope your defenses around what a system does. The dispensary verifier checks an age. Low stakes, low budget, low priority. So it gets a low-effort security posture, maybe a cloud bucket with sloppy permissions and an API nobody audited.

But an attacker doesn’t care what your system does. They care what it holds. A passport scan is a full identity kit: name, date of birth, document number, nationality, photo. That’s enough to open accounts, defeat knowledge-based verification elsewhere, and feed very convincing phishing. The criminal market priced that data a long time ago, and the price has nothing to do with how much you spent protecting it.

This is the same trap that produces breach after breach. A marketing tool holds millions of email-to-name mappings. A support portal caches session tokens. A dev assistant can be tricked into coughing up cloud credentials from a malicious repo, which is exactly the kind of flaw Amazon just had to patch in Q. The system looks boring. The contents are gold. Your threat model has to follow the data, not the org chart.

Stop collecting what you can’t protect

The cheapest cybersecurity control in existence is the data you never collect. There’s no encryption to manage, no retention policy to enforce, no incident response call at 2 a.m. when it leaks. It simply isn’t there.

Age verification is the perfect example because the actual requirement is tiny. The business needs one bit of information: is this person over the legal age, yes or no? Instead, the common implementation captures and stores a high-resolution image of a government document, often forever, because deleting things takes engineering effort and keeping them feels safe. It isn’t safe. Every stored record is a liability that sits on the books until the day it becomes a headline.

Defense in depth still matters, and a firewall and solid threat detection are table stakes. But layered defenses are damage control for assets you’ve chosen to keep. Minimization removes the asset. When the two strategies compete for budget, the one that shrinks the blast radius usually wins, because no amount of security hardening saves you from a breach of data you should have thrown away months ago.

What to actually do about it

If your organization collects, verifies, or stores identity documents, here’s the work. Some of it you can start today. Some of it is a standing program.

  • Inventory where identity documents actually live. Not where they’re supposed to live. Search object storage, ticketing systems, email attachments, and that “temporary” upload folder from a 2023 pilot. You can’t protect what you can’t find.
  • Verify, then discard. If a vendor or a flow only needs a yes/no on age or identity, design it to return that answer and delete the source document immediately. Store the result, not the raw material.
  • Set hard retention limits and enforce them with automation. A document scan should have a time-to-live measured in minutes or hours, not years. Manual cleanup never happens; make deletion the default the system performs on its own.
  • Lock down the boring systems. The low-value app holding high-value data needs the same baseline as your crown jewels: least-privilege access, encryption at rest, logging, and alerting on bulk reads. Brute-force protection and rate limits on any login or API in front of that store are non-negotiable.
  • Audit your vendors’ data handling, in writing. If a third party runs your age check, you own the breach when they leak. Ask exactly what they keep, for how long, and where. “We’re compliant” is not an answer.
  • Rehearse the document-leak scenario specifically. Generic incident response plans assume you can rotate the exposed thing. You can’t reissue a customer’s passport. Your playbook needs a notification and identity-protection track for credentials you cannot revoke.

That last point deserves emphasis. When a password leaks, you force a reset and move on. When a passport leaks, the victim is exposed for the life of that document, which could be a decade. There’s no rotation. That permanence should change how you weigh the risk of collecting it in the first place.

The age-verification trap is about to get worse

Regulators across multiple countries are pushing age-verification mandates for everything from adult content to social media to, yes, cannabis. The intent is reasonable. The implementation, if the dispensary case is any guide, is going to be a sprawl of small vendors standing up ID-collection systems with budgets and threat-protection postures that don’t match the data they’re suddenly holding.

Each one becomes a fresh honeypot. And because these systems are bolted onto businesses whose core competency is selling something else entirely, security is an afterthought handled by whoever was cheapest. The pattern is predictable: mandate appears, vendors rush in, documents pile up, one of them misconfigures a database, and a million credentials end up in a forum.

You can’t fix the regulatory landscape. You can refuse to be the next entry on the breach list. Push back on flows that collect more than they need. Favor verification methods that return an attestation instead of an image. And treat any system that touches a government ID as a high-value target from day one, because the people trying to break in already do. Good cyber security here looks less like buying another tool and more like having the discipline to not keep what you can’t defend.

The dispensary didn’t get hacked because someone wrote a brilliant exploit. It got hacked because it was holding something worth stealing and treating it like it wasn’t.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.