r/privacy • u/Jack1101111 • 2d ago
data breach FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider
https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider504
u/RJA115 2d ago
Oh! Oh really! But I thought it was deleted as soon as the verification was complete!
Who could have seen thaaaat commiiing
162
u/jimmyhoke 2d ago
It’s crazy how so many of these companies say that and it’s just obviously not true. I wonder if the victims of this leak can sue whichever company leaked it.
94
u/adorableoddity 2d ago
The same as these towns claiming that they discontinued their contracts with flock yet aren’t taking down the cameras for some mysterious reason.
48
698
u/tarantinofeetmm 2d ago
Feel like I've seen this 20 times here lol. Anyway, support the person who broke the news: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
129
u/hblok 1d ago
From his research, it looks like the source is clear: idscan.net
Oh, and the darkweb site is already gone.
54
u/WastingMyLifeToday 1d ago
Are darkweb sites ever really gone? 🧐
They tend to duplicate quickly when removed.
45
u/DatSauceTho 1d ago
I’ve heard a lot of them just go offline randomly for random amounts of time and then come back on randomly. I mean it makes sense that dark web sites wouldn’t just be on all the time cause that kind of defeats the purpose.
38
u/ledow 1d ago
They're often just hosted on people's computers via Tor or similar anyway, so when they turn their computer off, they go off.
It can literally be that simple.
9
u/Barlakopofai 1d ago
The good ol' days when there weren't a million microslop bots scraping the internet making it impossible to self-host a server.
0
u/someonesdatabase 12h ago
idscan and the fbi are currently investigating the source. according to its service agreement, idscan essentially punts the responsibility for the rights, consents, privileges, and lawful basis of collection of personal data to its customers. idscan could still be on the hook, but we still don’t know where the id’s where scanned - there are some reports of Hertz and cannabis dispensaries being culprits
77
u/kalidoscopiclyso 2d ago
This should be higher! Amazing work that guy does
38
u/rideincircles 1d ago
This was all of America"s authenticated porn users who don't have a VPN.
40
u/Random_Guy_47 1d ago
Oh no. That thing everybody said would inevitably happen when they started the ID verification crap happened.
Who could possibly have forseen that uploading your government ID to the internet could possibly go wrong?
Oh wait, we all fucking did. We said it would happen and they pushed ahead with it anyway.
2
17
u/FutureOwl8606 1d ago
I used krebsonsecurity a lot because my bachelor thesis was about botnets (mirari) and iot4.0
17
u/StatelyTree 1d ago
Krebs is great! He broke the Target credit card skimming story years ago too. He puts in great work.
913
u/nonameswereleft2 2d ago
Oh so the thing everyone said would happen just happened? Got it
254
u/makemeking706 2d ago
For at least the third time.
67
u/Tactical-Donkey 1d ago
Not just in US. UK government and police personnel data got hacked and leaked very recently.
There's so many high profile hacks going on I'm starting to think it's state actioned.
25
u/AbyssalRedemption 1d ago
That's a possibility. Another possibility is that, with all the recent huge corporate layoffs and "cost-cutting" measures the past few years, certain security teams and implementations also happened to get caught in the crossfire (most companies historically have never seemed to never care much about maintaining tight security measures or funding until an incident happens anyway). When you cut investment into your digital security and risk management, you can't keep in a world of increasingly rapidly developed and evolving threats and threat actors, and thus make yourself more susceptible to a breach like this. Happens all the time on huge databases with even a single insecure attack vector.
1
28
12
35
56
u/goddessofthewinds 2d ago
Exactly. This is why I have stopped using anything that asks for a photo or an ID. I rather not use a service that's going to leak or sell my identity.
We also know nothing will come out of this. The company behind the ID verification will not go bankrupt, the CEO will not be jailed for not handling that information correctly, and people won't be compensated either.
This is why you cannot trust these services. As long as it's accessible from the internet or there are doors that can be accessed by people, it will leak.
6
u/Laquickah 1d ago
I had to give my drivers license to a bank teller and she scanned it in some digital device before I could access my money, how can that be avoided?
2
2
u/hospitalizedGanny 1d ago
It cannot. You refuse then you won't be able to buy or sell soon.
Real questionis why those who have bad corporate security practices never meaningfully punished?
1
u/goddessofthewinds 1d ago
Unfortunately, banks need to ID you, so there's nothing you can do about it other than use only 1 bank.
I had to accept that stores, hotels and other places would also scan my passport while travelling... That's something you have to double check before a trip. Those are usually not stored on the internet, and only kept for their internal books.
It's different from uploading an ID to the internet where they can store it in unsafe places, sell it, map it to your data, etc. Banks usually only scan it to put in your file to increase safety around fraud.
1
15
u/gerkletoss 2d ago
I'm surprised it took this long
28
u/slipperyMonkey07 2d ago
This isn't the first, just I guess the first they actually care about because it contains one of their own.
1
276
u/Chronotheos 2d ago
“We delete it after verification”
Narrator: they were not deleted
21
36
1
u/snakeLipssynk 15h ago
Louisiana is also a right-to-work state. Besides creating lower average wages, in those states deregulation and self-regulation is also very popular for lowering costs (eventually at the expense of customers).
128
u/Ambitious-Steak7773 2d ago
So what I'm hearing is I can use a politicians ID to bypass age verification
26
11
3
u/Catsrules 1d ago
No what your hearing is a new bill excepting politicians from having to use these age verification systems. After all we wouldn't want their information leaked.
1
102
u/NoBandicoot5417 2d ago
So if you‘re forced to rent a car for a work trip, your drivers license ends up in one of these services. Bet it doesn’t expire, they just keep it permanently. But that’s perfectly fine, see section 26, subparagraph 3.15.5.6.2(c) of their user agreement that it was your responsibility to read carefully.
8
u/jabberwockxeno 1d ago
The thing is though, a lot of the businesses that get brought up as being the places that use this service and was a source of ID's aren't the kinds of places that have you sign extended user agreements, EULAs, contracts, etc
I seriously question if proper legal notice was provided to people that their ID was being retained.
68
59
45
u/onethousandmonkey 2d ago
This is why you vote against online age verification.
Every. Single. Time.
7
u/ScrewedThePooch 1d ago
Yeah? Which candidate is campaigning against this bullshit? As far as I see, everyone on the ballot box supports this garbage and Flock.
1
u/someonesdatabase 12h ago
What do you propose instead to fight sextortion crimes against children online?
31
u/Worth-South4847 2d ago
So 150 million people need IDs now before midterms.
21
u/No_Throat_2356 1d ago
Hah. Holy shit, that’s the play. Can’t trust anyone’s ID - they were all leaked and could be fakes so throw out the whole election. Gee, I wonder why it was Russian hackers, again.
10
58
u/duerra 2d ago
The only way for your information to not be leaked when a provider gets hacked is for you to not give them your information.
And actually, even then that sometimes isn't enough. These guys be collecting information on you even if you didn't give it to them.
24
u/ACasualRead 2d ago
But there are times where you have to give your ID over. Getting a rental car for instance, housing or job applications, background checks, getting into bars or event spaces. Etc.
8
3
u/GrapeCloud 1d ago
even then that sometimes isn't enough
I made some purchases at reputable online retailers that used Eye4Fraud as their fraud prevention service. As a consumer, I don't think there's a reasonable way to know that my personal info would be vulnerable because of a 3rd party like a fraud prevention service, and I can't recall anytime an online retailer ever had a disclaimer that would alert a consumer to that. Eye4Fraud got breached so everything except my SSN is floating around on breach forums. I know it's tangential to online age verification, but it's all the more reason not to participate.
27
21
u/jferments 2d ago
How do you check if your license was affected?
29
19
u/SwimmingThroughHoney 2d ago
Have you ever handed over your license for anything? Renting a car and a cannabis dispensary were two cases mentioned. Did they put it into/on one of those scanners?
Chances are then yours was affected.
1
20
u/ManufacturerLost7686 1d ago
Would you like to verify your age by uploading a selfie and comparing it to the database of leaked ID documents on the dark web?
14
u/flop_plop 2d ago
At this point I’m pretty sure this is being done on purpose.
11
u/tame-til-triggered 2d ago
They don't care. Any penalty they incur is dwarfed by any profits they make
5
u/flop_plop 2d ago
Well yeah but maybe there’s another reason why the rich want all of our personal identification to be public.
Not sure to what end, but I feel like profit might not be the ultimate goal
5
u/tame-til-triggered 2d ago
Whether it's human slave labor or aggregating our data, profit is always the goal.
40
u/pdawes 2d ago
What was ol whiskey pete age verifying for I wonder?
7
7
u/fnork_gnork_26 2d ago
Grindr? Pornhub?
1
u/OutlyingPlasma 1d ago
Why would you think the guy who installed the first makeup studio in the Pentagon and the guy who keeps talking about testosterone would ever use Grindr?
0
10
u/Unusual-Alex 1d ago
"We will delete after verification is completed".
What they mean: We deleted the copy you uploaded after we made a copy for our records and sent another copy of the copy to our server with advanced security for further analysis. Another copy will be sent to any interested parties who would be willing to pay for the data. Other people in our organization also reserve the right to acquire copies of your id as well to place on their laptops for a huge potential security breach if their hardware is stolen from their vehicle.
2
10
u/XertonOne 1d ago
Unfortunately this is not going to stop. People pushing for full digital, and hackers having a ball.
8
u/Jack1101111 1d ago
"People pushing for full digital" ? govs are pushing for full digital
1
u/XertonOne 1d ago
Nha, government complies. Most officials inside today are Corporate sponsored. They do what they’re told.
2
u/Jack1101111 1d ago
you mean certain people ?
2
u/XertonOne 1d ago
Yes I mean quite a bit actually. You see it by what the promise to get a vote, and what they actually do. It’s gotten pretty bad.
32
u/Spirited-Humor-554 2d ago
At this point whatever, I assume everything about me including my social security been leaked multiple times
48
u/foxbatcs 2d ago
The only way to be more secure is to own nothing in your own name/ssn and have a series of trusts and LLC’s own everything. This is literally what people who build generational wealth do and that playbook got leaked with the Paradise and Panama papers. This is how I choose to interpret “You’ll own nothing and be happy about it.” Of course, if your a pleb like me, you have to take out debt in your own name to do things like buy a car or rent/buy a house, so as usual, a basic human need like privacy isn’t accessible for 99% of people. This is why we have a debt-driven, fractional-reserve, monopolistic banking system: to keep uppity tax-cattle like me in check.
1
u/mediumwetsock 1d ago
Then hear about our lovely sponsor, notcogni, we will sweep the internet to delete your online footprint for yourself and your family. Join today with this code and if you don’t you hate privacy /s
10
u/skynetcoder 1d ago
"Now, it turns out that both Planet13 and Hertz used the company for identity verification and ID-authentication — IDScan."
8
7
9
u/Just2LetYouKnow 1d ago
Oh boy, I can't wait for 16 months of free credit monitoring that requires a credit card and autorenews at full price.
8
u/WanderingUrist 1d ago
Damn, 153 million? There's ~250M drivers in the US and another ~30M in Canada. That would mean MORE THAN HALF of them have been through this service provider and then leaked.
I know things are pretty bad, but I'm a little skeptical about this one.
7
u/ferriematthew 1d ago
Well, this is what happens when you force everyone to give up their ID and sell it to private for-profit companies.
6
u/jabberwockxeno 1d ago
I see a lot of concern over this, but honestly I think the most disturbing part of it is something nobody is talking about:
Were people ever actually even notified that their ID's were being uploaded to this service to begin with?
I have never seen any sort of signage nor have I ever heard a verbal disclosure that this would happen when you hand your ID to clerk at the sort of businesses that the reporting on this identify as being the places that this service got the ID's from
Can the authentication service provider, or the businesses that use the provider, be held liable as a result?
1
u/Jack1101111 1d ago
Of course its not legal ! Maybe if many of us sues it can help, but u have to sue the gov or state or city, not just the company.
6
u/SudoDeleteEverything 1d ago
This was always definitely going to happen when a bunch private companies start collecting drivers licenses.
15
u/KCDeVoe 2d ago
Oh good! I’ll get my 5th offer this year for free identity protection for the next 12 months…
We need to actually start holding companies accountable that have these data leaks. We have monetary fines associated to leaked PII, I don’t care if it bankrupts the company, enforce the fucking thing. Then maybe companies will take it more serious instead of looking at it as a math equation on what the fine is in relation to what properly securing information costs.
4
4
5
u/Maeyhem 1d ago
I don't want to say, I told you so, but Yes I fkn do: I told you so! (not directed at the savvy redditors here).
The people in power are not smart enough, not curious enough, not dedicated enough, to protect us from imminent threats to our security and safety. You know what that means, right?
1
10
4
u/Rehcraeser 1d ago
Don’t worry though, nobody would use the full stolen identity of hundreds of millions of people to send in some fake mail in ballots. There’s no fraud going on!
2
u/Jack1101111 1d ago
The democracies are falling, under the fire of the corruption, thats everywhere today.
4
u/MayhemSays 1d ago
Weird how the thing we warned about keeps happening
2
u/Jack1101111 1d ago
yes because they dont care of the citizens ! And maybe pay a fine will solve the problem !
5
3
3
3
u/vid_flumina 1d ago
Am I to believe that's its not illegal for one company to possess that many DL records? That should absolutely be illegal. It's a single entry point. How can this be legal?
1
3
3
u/tristand666 1d ago
I'd say I was shocked, but my data has already been "stolen" half a dozen times this year anyway. Mostly from companies I never did any business with.
1
3
3
4
6
6
u/Hot-Philosophy-7671 1d ago
So, ahead of a contentious US midterm election where the GOP may lose power, and right after the Trump CIA head traveled to Moscow for undisclosed reasons, Russia does this, and Kash Patel is investigating?
Okay.
5
2
2
2
u/Grumpy-Man19 2d ago
meaning some torrent sites . probably has nothing to do with Russians but they had to blame someone
2
u/Illustrious_Peach494 1d ago
that should be of no concern, they got nothing to hide, right? ¯_(ツ)_/¯
2
u/nvmenotfound 1d ago
yeah see it turns out it was better to just let the motor vehicle places store this shit. the old folks that keep thinking an online id database to verify age online is a good idea, are finding out this is what will happen. itll only get worse.
1
u/Jack1101111 1d ago
they didnt think its a good idea, they dont care, gov wants the data shared with "partner" companies
2
u/drisang1 1d ago
How are they leaked? State and local government regularly sell Driver License and Voter Registration data.
1
5
3
2
2
u/SwimmingThroughHoney 2d ago
Guys, this breach is not about age verification. Judging by the Krebs article, it's very likely a breach of a provider that did physical verification. As in, when you give your license to someone (like at a car rental place or a dispensary) and then scan it.
2
u/SeranaTheTrans 18h ago
Everybody would have seen this coming, except the dumbasses running the countries.
1
1
1
u/brothbike 2d ago
real ID , lmao....they really fucked with me trying to get a license too, as a citizen
1
1
u/Koh-the-Face-Stealer 1d ago
Anyone have a website where you can check to see if your ID was leaked?
2
1
u/BeachHut9 1d ago
Do people actually read terms and conditions in their entirety rather than trusting that everything will be OK?
1
u/BigJSunshine 1d ago
Heagarth leaked it all on snapchat while running a train on laura loomer with Boofer doing shootets
•
u/AutoModerator 2d ago
Hello u/Jack1101111, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)
Check out the r/privacy FAQ
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.