Cannabis users’ sensitive data leaked in “serious” breach

Internet privacy researchers at vpnMentor have discovered a data breach in point-of-sale software used in the cannabis industry

The team, led by Noam Rotem and Ran Locar, identified an unsecured data repository owned by THSuite, which contained sensitive data from numerous marijuana dispensaries across the United States.

Among the leaked data were names, addresses, government and employee IDs and further personally identifiable information.

THSuite offers software to cannabis dispensaries across the US. In order to comply with state laws, dispensaries have to collect a large amount of data from each individual transacting. 

The THSuite platform is used to manage all of this data, plugging into each state’s traceability system through an API, making the process quicker and easier.

Over 85,000 files were found to have been leaked in the data breach, 30,000 of which included sensitive, personally identifiable information. According to vpnMentor, the leak also included scanned government and company IDs. 


READ MORE: Millions of fingerprints leaked in latest high-profile data breach


In a blogpost detailing the report, vpnMentor said: “The leaked bucket contained so much data that it wasn’t possible for us to examine all the records individually.

“In the sample of entries we checked, we found information related to three marijuana dispensaries in different locations around the US.”

Amedicanna Dispensary, Bloom Medicinals and Colorado Grow Company were among the worst-hit companies, but the breach affected many more dispensaries. vpnMentor even goes so far as to say that it is possible for all THSuite clients and customers to have had their data leaked.

“As a result of this data breach, sensitive personal information was exposed for medical marijuana patients, and possibly for recreational marijuana users as well. This raises some serious privacy concerns.

“Medical patients have a legal right to keep their medical information private for good reason. Patients whose personal information was leaked may face negative consequences both personally and professionally.

Under HIPAA regulations, vpnMentor state that it is a federal crime in the US for a health service provider to expose personal information. Violations can result in fines of up to $50,000 for each leaked record.

There is still a stigma around cannabis use. Some workplaces even prohibit it entirely. vpnMentor fears that individuals using cannabis either recreationally or for medical purposes may face consequences at their place of work, or even at home.


vpnMentor has contacted THSuite. At the time of publication, they had not yet received a reply. 

Luke Conrad

Technology & Marketing Enthusiast

What is a User Journey

Erin Lanahan • 19th April 2024

User journey mapping is the compass guiding businesses to customer-centric success. By meticulously tracing the steps users take when interacting with products or services, businesses gain profound insights into user needs and behaviors. Understanding users’ emotions and preferences at each touchpoint enables the creation of tailored experiences that resonate deeply. Through strategic segmentation, persona-driven design,...

From Shadow IT to Shadow AI

Mark Molyneux • 16th April 2024

Mark Molyneux, EMEA CTO from Cohesity, explains the challenges this development brings with it and why, despite all the enthusiasm, companies should not repeat old mistakes from the early cloud era.

Fixing the Public Sector IT Debacle

Mark Grindey • 11th April 2024

Public sector IT services are no longer fit for purpose. Constant security breaches. Unacceptable downtime. Endemic over-spending. Delays in vital service innovation that would reduce costs and improve citizen experience.

Best of tech to meet at VivaTech in May

Viva Technology • 10th April 2024

A veritable crossroads for business and innovation, VivaTech once again promises to show why it has become an unmissable stop on the international business calendar. With its expanding global reach and emphasis on crucial themes like AI, sustainable tech, and mobility, VivaTech stands as the premier destination for decoding emerging trends and assessing their economic...

Enabling “Farm to Fork” efficiency between supermarkets & producers

Neil Baker • 03rd April 2024

Today, consumers across the UK are facing a cost of living crisis. As a result, many retailers and supermarkets are striving to keep their costs down, so that they can avoid passing these onto shoppers. Within this, one area that is increasingly under scrutiny for many organisations surrounds how to improve supply chain efficiency. This...

Addressing Regulatory Compliance in Government-Owned, Single-Use Devices

Nadav Avni • 26th March 2024

Corporate-owned single-use (COSU) devices, also known as dedicated devices, make work easier for businesses and many government agencies. They’re powerful smart devices that fulfil a single purpose. Think smart tablets used for inventory tracking, information kiosks, ATMs, or digital displays. But, in a government setting, these devices fall under strict regulatory compliance standards.

Advantages of Cloud-based CAD Solutions for Modern Designers

Marius Marcus • 22nd March 2024

Say goodbye to the days of clunky desktop software chaining us to specific desks. Instead, we’re stepping into a new era fueled by cloud CAD solutions. These game-changing tools not only offer designers unmatched flexibility but also foster collaboration and efficiency like never before!