Cannabis users’ sensitive data leaked in “serious” breach

Internet privacy researchers at vpnMentor have discovered a data breach in point-of-sale software used in the cannabis industry

The team, led by Noam Rotem and Ran Locar, identified an unsecured data repository owned by THSuite, which contained sensitive data from numerous marijuana dispensaries across the United States.

Among the leaked data were names, addresses, government and employee IDs and further personally identifiable information.

THSuite offers software to cannabis dispensaries across the US. In order to comply with state laws, dispensaries have to collect a large amount of data from each individual transacting. 

The THSuite platform is used to manage all of this data, plugging into each state’s traceability system through an API, making the process quicker and easier.

Over 85,000 files were found to have been leaked in the data breach, 30,000 of which included sensitive, personally identifiable information. According to vpnMentor, the leak also included scanned government and company IDs. 


READ MORE: Millions of fingerprints leaked in latest high-profile data breach


In a blogpost detailing the report, vpnMentor said: “The leaked bucket contained so much data that it wasn’t possible for us to examine all the records individually.

“In the sample of entries we checked, we found information related to three marijuana dispensaries in different locations around the US.”

Amedicanna Dispensary, Bloom Medicinals and Colorado Grow Company were among the worst-hit companies, but the breach affected many more dispensaries. vpnMentor even goes so far as to say that it is possible for all THSuite clients and customers to have had their data leaked.

“As a result of this data breach, sensitive personal information was exposed for medical marijuana patients, and possibly for recreational marijuana users as well. This raises some serious privacy concerns.

“Medical patients have a legal right to keep their medical information private for good reason. Patients whose personal information was leaked may face negative consequences both personally and professionally.

Under HIPAA regulations, vpnMentor state that it is a federal crime in the US for a health service provider to expose personal information. Violations can result in fines of up to $50,000 for each leaked record.

There is still a stigma around cannabis use. Some workplaces even prohibit it entirely. vpnMentor fears that individuals using cannabis either recreationally or for medical purposes may face consequences at their place of work, or even at home.


vpnMentor has contacted THSuite. At the time of publication, they had not yet received a reply. 

Luke Conrad

Technology & Marketing Enthusiast

The Hidden Cost of MFT Vulnerabilities

Dario Perfettibile • 08th December 2025

When a critical deserialisation vulnerability was found in a popular Managed File Transfer (MFT) License Servlet last month, security teams around the world likely experienced a familiar sinking feeling. Another critical vulnerability. Another emergency patch cycle. Another race against ransomware operators. But this latest maximum-severity flaw revealed something more troubling than a coding error. It...

5 Signs Your ERP System is Holding You Back!

Adam Palmer • 05th December 2025

For a modern business, an ERP system should be a powerful enabler. One that drives agility, delivers real-time insights, and helps drive strategic growth — not something teams feel the need to work around. Yet too often, legacy ERP systems quietly drag down performance and decision-making. Instead of supporting the business, they can create friction,...

How AI Is Rewriting the Rules of Shopping

Sue Azari • 09th October 2025

The shift toward AI-native commerce is already underway. While mainstream adoption may take time, the complexity of building the right foundation means that early movers will gain a clear advantage. The question is no longer whether AI will reshape shopping, but whether your organisation will be ready when it does. This article outlines what you...

Data Centre Demand Growth Continues to Surge

Brad Legge • 02nd October 2025

The proliferation of digital technologies has thrust data centres into the spotlight as linchpins of modern business infrastructure. From cloud computing to artificial intelligence (AI), these facilities support critical operations across industries. The growing interest in generative artificial intelligence (AI) has triggered a race to develop technology, driving demand for high-density data centres and significantly...

5 Signs Your ERP System is Holding You Back

Adam Palmer • 11th September 2025

Is your ERP helping you move forward — or slowing you down? For a modern business, an ERP system should be a powerful enabler. One that drives agility, delivers real-time insights, and helps drive strategic growth — not something teams feel the need to work around. Yet too often, legacy ERP systems quietly drag down...

Why Wind River is serious about moving from VMware

Paul Miller • 09th September 2025

For IT departments with limited manpower and budgets, improving the efficiency of operational management of distributed IT infrastructure is a pressing issue. Organizations burdened with licensing costs, such as the VMware issue, will want to start optimizing costs and IT resources immediately. We interviewed a vendor that is working on this trend using open technology....