An actor posting as exfilar claims BudBoard left a cloud storage bucket publicly readable, exposing database exports, client data, and other sensitive configuration details tied to 18 dispensary and brand clients. The alleged exposure also included a screenshot of a production POS API key, which could affect downstream retail systems if valid, though the claim remains unverified. #BudBoard #exfilar #POSAPIkey
Keypoints
- BudBoard is accused of leaving a storage bucket public with no authentication.
- The bucket allegedly contained two 2024 database exports and data for 58 staff accounts.
- Information tied to 18 dispensary and brand clients in the United States, Canada, and Australia may have been exposed.
- A screenshot reportedly showed a production API key for a major cannabis POS platform.
- The claim is unverified, but the alleged exposure is described as critical and still live.
DarkWebInformer.com Providing intel from some of the darkest places on the Dark Web & Clearnet. Breaches, Darknet Markets, Ransomware, Threat Alerts, & more!