Skip to content

BudBoard Storage Bucket Allegedly Left Public, Exposing 18 Dispensaries and a Production POS Integration Key

Breach Report United States flagUnited States Cannabis Tech / SaaS Reported Live

BudBoard Storage Bucket Allegedly Left Public, Exposing 18 Dispensaries and a Production POS Integration Key

An actor posting as exfilar claims that BudBoard, a US cannabis digital signage platform providing dispensary screen management and point-of-sale integration, left its cloud storage bucket publicly readable with no authentication. The bucket is said to contain two full database export snapshots from 2024, covering 58 staff accounts across 18 dispensary and brand clients in the United States, Canada, and Australia, along with client configurations, addresses, and subscription data. The actor states the bucket also held a screenshot displaying a production API key for a major cannabis POS platform, which if valid would reach beyond BudBoard into its clients' retail systems. Access is reported as still live. The claim is unverified.

StatusReported live
Client firms18
Staff accounts58
Actorexfilar

Post details

TargetBudBoard
CountryUnited States flagUnited States
SectorCannabis retail technology
ListingReply or upgrade to unlock
Volume500+ files / 212MB
CauseClaimed misconfiguration
Observed
Actorexfilar

!Allegedly included

  • Staff email addresses
  • Display names
  • Account identifiers
  • Permission roles
  • Dispensary client names
  • Dispensary addresses
  • Location coordinates
  • Subscription & billing tier
  • Payment bypass flags
  • Product display settings
  • Potency configuration
  • Screen layouts
  • Integration endpoints
  • POS API key screenshot

Screenshots

Potential impact

Fifty-eight accounts understates this. The consequential item is the exposed integration key for a downstream POS platform: if valid, it would reach the retail systems of every dispensary using that integration, where inventory, sales, and state seed-to-sale compliance records are held. It should be stated plainly that the post evidences an exposed key, not confirmed access to any dispensary's systems, and that distinction matters. The sector sharpens the stakes. Cannabis purchase records carry consequences that ordinary retail data does not, touching employment, firearms eligibility, benefits, and immigration status, and dispensaries are regulated operators whose compliance data has legal weight. Client configurations also expose commercial terms and a payment bypass flag.

iStatus

Unverified

The post includes an infrastructure map, retrieval paths, and staff credentials, none of which Dark Web Informer is reproducing while the exposure is reported as unremediated. The actor claims the platform's cloud provider sent automated insecurity warnings for roughly two years without response, which is uncorroborated. This is described as the fourth of 25 releases from the same automated scanning tool behind a separate disclosure published today. Named dispensaries are clients of the platform, not the breached party. The claim is unverified.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest