> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# BudBoard Storage Bucket Allegedly Left Public, Exposing 18 Dispensaries and a Production POS Integration Key
- URL: https://darkwebinformer.com/budboard-storage-bucket-allegedly-left-public-exposing-18-dispensaries-and-a-production-pos-integration-key/
- Published: 2026-08-05T17:14:45.000Z
- Updated: 2026-08-05T17:14:45.000Z
- Author: Dark Web Informer
- Tags: Leaks

Breach Report ![United States flag](https://flagcdn.com/w40/us.png)United States Cannabis Tech / SaaS Reported Live 

## BudBoard Storage Bucket Allegedly Left Public, Exposing 18 Dispensaries and a Production POS Integration Key

An actor posting as **exfilar** claims that **BudBoard**, a US cannabis digital signage platform providing dispensary screen management and point-of-sale integration, left its cloud storage bucket **publicly readable with no authentication**. The bucket is said to contain **two full database export snapshots from 2024**, covering **58 staff accounts across 18 dispensary and brand clients** in the United States, Canada, and Australia, along with client configurations, addresses, and subscription data. The actor states the bucket also held a **screenshot displaying a production API key for a major cannabis POS platform**, which if valid would reach beyond BudBoard into its clients' retail systems. Access is reported as **still live**. The claim is **unverified**.

Severity CRITICAL 

StatusReported live

Client firms18

Staff accounts58

Actorexfilar

### ▣Post details

TargetBudBoard

Country![United States flag](https://flagcdn.com/w40/us.png)United States

SectorCannabis retail technology

ListingReply or upgrade to unlock

Volume500+ files / 212MB

CauseClaimed misconfiguration

ObservedAug 5, 2026

Actorexfilar

### !Allegedly included

- Staff email addresses
- Display names
- Account identifiers
- Permission roles
- Dispensary client names
- Dispensary addresses
- Location coordinates
- Subscription & billing tier
- Payment bypass flags
- Product display settings
- Potency configuration
- Screen layouts
- Integration endpoints
- POS API key screenshot

### ◱Screenshots

[ ![BudBoard cannabis signage platform data exposure forum post screenshot, August 2026 (1 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598723.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598723.png) [ ![BudBoard cannabis signage platform data exposure forum post screenshot, August 2026 (2 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598724.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598724.png) [ ![BudBoard cannabis signage platform data exposure forum post screenshot, August 2026 (3 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598725.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/459278659872659872365987236498762598725.png) 

### ⚠Potential impact

Fifty-eight accounts understates this. The consequential item is the **exposed integration key for a downstream POS platform**: if valid, it would reach the retail systems of every dispensary using that integration, where inventory, sales, and **state seed-to-sale compliance records** are held. It should be stated plainly that **the post evidences an exposed key, not confirmed access to any dispensary's systems**, and that distinction matters. The sector sharpens the stakes. Cannabis purchase records carry consequences that ordinary retail data does not, touching employment, firearms eligibility, benefits, and immigration status, and dispensaries are **regulated operators whose compliance data has legal weight**. Client configurations also expose commercial terms and a payment bypass flag.

### iStatus

Unverified 

The post includes an infrastructure map, retrieval paths, and staff credentials, **none of which Dark Web Informer is reproducing while the exposure is reported as unremediated**. The actor claims the platform's cloud provider sent automated insecurity warnings for roughly two years without response, which is uncorroborated. This is described as the fourth of 25 releases from the same automated scanning tool behind a separate disclosure published today. Named dispensaries are **clients of the platform, not the breached party**. The claim is **unverified**.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE