United States
Cannabis Tech / SaaS
Reported Live
BudBoard Storage Bucket Allegedly Left Public, Exposing 18 Dispensaries and a Production POS Integration Key
An actor posting as exfilar claims that BudBoard, a US cannabis digital signage platform providing dispensary screen management and point-of-sale integration, left its cloud storage bucket publicly readable with no authentication. The bucket is said to contain two full database export snapshots from 2024, covering 58 staff accounts across 18 dispensary and brand clients in the United States, Canada, and Australia, along with client configurations, addresses, and subscription data. The actor states the bucket also held a screenshot displaying a production API key for a major cannabis POS platform, which if valid would reach beyond BudBoard into its clients' retail systems. Access is reported as still live. The claim is unverified.
▣Post details
United States!Allegedly included
- Staff email addresses
- Display names
- Account identifiers
- Permission roles
- Dispensary client names
- Dispensary addresses
- Location coordinates
- Subscription & billing tier
- Payment bypass flags
- Product display settings
- Potency configuration
- Screen layouts
- Integration endpoints
- POS API key screenshot
◱Screenshots
⚠Potential impact
Fifty-eight accounts understates this. The consequential item is the exposed integration key for a downstream POS platform: if valid, it would reach the retail systems of every dispensary using that integration, where inventory, sales, and state seed-to-sale compliance records are held. It should be stated plainly that the post evidences an exposed key, not confirmed access to any dispensary's systems, and that distinction matters. The sector sharpens the stakes. Cannabis purchase records carry consequences that ordinary retail data does not, touching employment, firearms eligibility, benefits, and immigration status, and dispensaries are regulated operators whose compliance data has legal weight. Client configurations also expose commercial terms and a payment bypass flag.
iStatus
UnverifiedThe post includes an infrastructure map, retrieval paths, and staff credentials, none of which Dark Web Informer is reproducing while the exposure is reported as unremediated. The actor claims the platform's cloud provider sent automated insecurity warnings for roughly two years without response, which is uncorroborated. This is described as the fourth of 25 releases from the same automated scanning tool behind a separate disclosure published today. Named dispensaries are clients of the platform, not the breached party. The claim is unverified.
DARK WEB INFORMER - THREAT INTELLIGENCE