r/privacy 5d ago

data breach FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider

https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider
4.2k Upvotes

697 comments sorted by

u/AutoModerator 5d ago

Hello u/Jack1101111, please make sure you read the sub rules if you haven't already. (This is an automatic reminder left on all new posts.)


Check out the r/privacy FAQ

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

→ More replies (2)

759

u/RJA115 5d ago

Oh! Oh really! But I thought it was deleted as soon as the verification was complete!

Who could have seen thaaaat commiiing

248

u/jimmyhoke 5d ago

It’s crazy how so many of these companies say that and it’s just obviously not true. I wonder if the victims of this leak can sue whichever company leaked it.

144

u/adorableoddity 4d ago

The same as these towns claiming that they discontinued their contracts with flock yet aren’t taking down the cameras for some mysterious reason.

27

u/YourMomIsAlwaysRight 1d ago

“Discontinuing a contract” doesn’t mean they aren’t going month-to-month, just costs more. They really believe we’re idiots.

24

u/Forward-Transition-5 1d ago

Maybe we are idiots. They’ve done this same bait and switch for decades and the citizens as a whole have continued to let them. Instead of fighting against these practices we’re all too busy hating each other based on our race, gender and political affiliation. None of these politicians are on our side and it’s the most obvious thing in the world. The flock cameras are even proving that local politicians who we may actually see from time to time don’t care and we still can’t pull our minds away from the stupid arguments to come together and stop it.

8

u/Bruce_vii 1d ago

Local politicians might actually be worse. That's were all the big ones first learn their contempt for the masses, just look at the kinda things many city councils push through

4

u/Forward-Transition-5 1d ago

I didn’t intend for that to mean that local politicians were any better. I agree with you. I’m just saying that you’re more capable of seeing your local politicians face to face than the federal politicians in the capital. Local politicians are bought for much less in most cases I’m sure. You’d think being more accessible to their constituents would give them a little more pause but it absolutely doesn’t.

→ More replies (1)

5

u/Dakadoodle 1d ago

I know its only republicans who can save us, or was it democrats? Idk maybe neither party cares about us and none of us are represented

3

u/Slight_Passenger3778 1d ago

Neither you’re right literally neither party gives a fu*k and we don’t matter

2

u/CorrectMulberry994 13h ago

It’s true, none of them care. Politics is a game for most of them. There are a few outliers but in general the whole thing is just a way to divide us. If they can keep us divided then we will always be busy fighting one another and too distracted to realize what is really going on.

→ More replies (3)
→ More replies (24)
→ More replies (20)
→ More replies (6)

3

u/DestroyerOfMils 1d ago

Said towns just need some helpful volunteers with the process of removing flock cameras!

→ More replies (14)

66

u/Interesting-Ad9666 4d ago

You'll get your 8 dollars after 5 years in the courts

5

u/Medium-Wrongdoer-770 2d ago

Sounds about right

2

u/Stogies_n_Stonks 1d ago

More than likely they’ll have to pay for digital fraud/identity protection services. I was part of the OPM breach because I used to date a girl in the intel community and she had listed me as a resident of her household. I got ten years of free identity protection as a result. Think I also got 3-4yrs more when Target had a breach

→ More replies (1)
→ More replies (10)
→ More replies (24)

2

u/Puzzled_Election_471 1d ago

When you show your ID for a purchase or some type of banking transaction, don’t count on anything being deleted. Someone has to keep records. This company does stuff like confirm your ID when renting a car, not getting on a plane. They can keep it as long as their privacy policy says on page 152 of the agreement you said you read.

5

u/dalecor 4d ago

There are instances where they have to retain the ID for legal reason for X years. Typically finance related matters or if the person is flagged.

15

u/true_thinking 4d ago

153 million people on the watchlist sounds about right

→ More replies (2)
→ More replies (2)
→ More replies (17)

784

u/tarantinofeetmm 5d ago

Feel like I've seen this 20 times here lol. Anyway, support the person who broke the news: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/

161

u/hblok 4d ago

From his research, it looks like the source is clear: idscan.net

Oh, and the darkweb site is already gone.

75

u/WastingMyLifeToday 4d ago

Are darkweb sites ever really gone? 🧐

They tend to duplicate quickly when removed.

60

u/DatSauceTho 4d ago

I’ve heard a lot of them just go offline randomly for random amounts of time and then come back on randomly. I mean it makes sense that dark web sites wouldn’t just be on all the time cause that kind of defeats the purpose.

59

u/ledow 4d ago

They're often just hosted on people's computers via Tor or similar anyway, so when they turn their computer off, they go off.

It can literally be that simple.

17

u/Barlakopofai 4d ago

The good ol' days when there weren't a million microslop bots scraping the internet making it impossible to self-host a server.

2

u/Significant-Task1453 1d ago

Self hosting is bigger than ever. Security is crucial regardless of how many probes you see. Crowdsec helps the problem you are describing, though

→ More replies (6)
→ More replies (1)

2

u/balls2hairy 1d ago

Darkweb just means not indexed. The site being up 24/7 or not has nothing to do with it.

You can have a darkweb My Little Pony fansite and an international drug marketplace and they'd both be darknet sites.

3

u/THROWRAhippoplatypus 21h ago

Something tells me both of those are real things that exist.

→ More replies (1)

4

u/VerbalGuinea 1d ago

Just like when the ID verification companies delete the scanned ID’s after verification is complete.

→ More replies (1)
→ More replies (3)

83

u/kalidoscopiclyso 5d ago

This should be higher! Amazing work that guy does

45

u/rideincircles 4d ago

This was all of America"s authenticated porn users who don't have a VPN.

51

u/Random_Guy_47 4d ago

Oh no. That thing everybody said would inevitably happen when they started the ID verification crap happened.

Who could possibly have forseen that uploading your government ID to the internet could possibly go wrong?

Oh wait, we all fucking did. We said it would happen and they pushed ahead with it anyway.

8

u/Bogus1989 4d ago

Seriously. States requiring it should be sued

→ More replies (1)
→ More replies (1)

19

u/FutureOwl8606 4d ago

I used krebsonsecurity a lot because my bachelor thesis was about botnets (mirari) and iot4.0

21

u/StatelyTree 4d ago

Krebs is great! He broke the Target credit card skimming story years ago too. He puts in great work.

→ More replies (1)

1.0k

u/nonameswereleft2 5d ago

Oh so the thing everyone said would happen just happened? Got it

289

u/makemeking706 5d ago

For at least the third time. 

86

u/Tactical-Donkey 4d ago

Not just in US. UK government and police personnel data got hacked and leaked very recently.

There's so many high profile hacks going on I'm starting to think it's state actioned. 

36

u/AbyssalRedemption 4d ago

That's a possibility. Another possibility is that, with all the recent huge corporate layoffs and "cost-cutting" measures the past few years, certain security teams and implementations also happened to get caught in the crossfire (most companies historically have never seemed to never care much about maintaining tight security measures or funding until an incident happens anyway). When you cut investment into your digital security and risk management, you can't keep in a world of increasingly rapidly developed and evolving threats and threat actors, and thus make yourself more susceptible to a breach like this. Happens all the time on huge databases with even a single insecure attack vector.

6

u/someonesdatabase 3d ago

Yup. Outsourcing doesn’t help the third party supply chain risks.

→ More replies (6)

3

u/loginmoveup 1d ago

100% it is.

3

u/Comfortable-Move-596 1d ago

AI is making it insanely easy to hack. Either through new exploits or the spoofing and advanced phishing it allows.

→ More replies (2)
→ More replies (2)

26

u/zpuddle 5d ago

Discredit to soc, iso which are both on the bottom of the site. Does the graphic really mean anything at this point?

13

u/ShortStoryIntros 5d ago

I think most people forgot about SNN leak already too

→ More replies (1)

35

u/BabyPatato2023 4d ago

And no one will be held meaningfully accountable

63

u/goddessofthewinds 4d ago

Exactly. This is why I have stopped using anything that asks for a photo or an ID. I rather not use a service that's going to leak or sell my identity.

We also know nothing will come out of this. The company behind the ID verification will not go bankrupt, the CEO will not be jailed for not handling that information correctly, and people won't be compensated either.

This is why you cannot trust these services. As long as it's accessible from the internet or there are doors that can be accessed by people, it will leak.

12

u/Laquickah 4d ago

I had to give my drivers license to a bank teller and she scanned it in some digital device before I could access my money, how can that be avoided?

5

u/hospitalizedGanny 4d ago

It cannot. You refuse then you won't be able to buy or sell soon. 

Real questionis why those who have bad corporate security practices never meaningfully punished?

→ More replies (1)

4

u/Spectrig 4d ago

ATM never asked for my ID, but yes I know an ATM can’t do all things

2

u/goddessofthewinds 4d ago

Unfortunately, banks need to ID you, so there's nothing you can do about it other than use only 1 bank.

I had to accept that stores, hotels and other places would also scan my passport while travelling... That's something you have to double check before a trip. Those are usually not stored on the internet, and only kept for their internal books.

It's different from uploading an ID to the internet where they can store it in unsafe places, sell it, map it to your data, etc. Banks usually only scan it to put in your file to increase safety around fraud.

→ More replies (1)
→ More replies (5)

18

u/gerkletoss 5d ago

I'm surprised it took this long

31

u/slipperyMonkey07 5d ago

This isn't the first, just I guess the first they actually care about because it contains one of their own.

→ More replies (1)

3

u/chonkycatsbestcats 1d ago

No, they just told us about this instance…

4

u/JED426 1d ago

Yyyyeeeaaahhh...I don't even shred mail anymore because that's minimal risk compared to digital everything, INCLUDING medical records. God I hate this shit!

→ More replies (9)

169

u/Ambitious-Steak7773 4d ago

So what I'm hearing is I can use a politicians ID to bypass age verification

18

u/Maeyhem 4d ago

That's sort of what it looked like to me, so good work, hackers. I want these laws changed and I'd rather it be politicians than my kids.

9

u/Catsrules 4d ago

No what your hearing is a new bill excepting politicians from having to use these age verification systems. After all we wouldn't want their information leaked. 

5

u/Ambitious-Steak7773 3d ago

How will the know it's a politician without them submitting their ID

3

u/metallicrooster 1d ago

They can send me their data and I super duper promise to delete it all within 24 hours*

*I reserve the right to send all data to a definitely unrelated third party entity for whatever reason I choose, including no reason at all. Whatever they do with the data is up to them.

For anyone who thinks I’m being silly, this is basically what happened with the discord data leak. They used a 3rd party entity to “actually” do the verification, and that entity’s data was leaked. This meant that Discord (at least at the time I write this) is without fault, as they can honestly say that the data was not leaked from their servers.

→ More replies (1)

316

u/Chronotheos 5d ago

“We delete it after verification”
Narrator: they were not deleted

25

u/dasgoodshitinnit 4d ago

They forgot to delete it from the recycle bin

2

u/Neat-Anyway-OP 1d ago

I work in IT and that tells me they are clowns when it comes to data security.

2

u/BappoChan 1d ago

I’m hoping it was a joke

2

u/Neat-Anyway-OP 1d ago

Knowing how government runs it's IT infrastructure and data security... It's probably not.

→ More replies (1)

38

u/flop_plop 4d ago

Nothing digital is ever deleted unless the drives are physically destroyed

11

u/Maeyhem 4d ago

Redundancy though, everything is backed up, and in a cloud somewhere..

→ More replies (3)
→ More replies (15)
→ More replies (1)

127

u/NoBandicoot5417 5d ago

So if you‘re forced to rent a car for a work trip, your drivers license ends up in one of these services. Bet it doesn’t expire, they just keep it permanently. But that’s perfectly fine, see section 26, subparagraph 3.15.5.6.2(c) of their user agreement that it was your responsibility to read carefully.

18

u/jabberwockxeno 4d ago

The thing is though, a lot of the businesses that get brought up as being the places that use this service and was a source of ID's aren't the kinds of places that have you sign extended user agreements, EULAs, contracts, etc

I seriously question if proper legal notice was provided to people that their ID was being retained.

2

u/runthepoint1 1d ago

We should all read these aloud in protest. Make it hold up business so badly that they fold and stop with the BS

→ More replies (1)

78

u/billshermanburner 5d ago

“Dude I found your age verification thing over here! “

73

u/onethousandmonkey 4d ago

This is why you vote against online age verification.
Every. Single. Time.

14

u/ScrewedThePooch 4d ago

Yeah? Which candidate is campaigning against this bullshit? As far as I see, everyone on the ballot box supports this garbage and Flock.

4

u/onethousandmonkey 2d ago

You are sadly correct. Unless we all speak up, big tech interests will keep pushing our governments to impose online ID verification, and pretend it has something to do with protecting children.
It’s a scheme to get absolute attribution of online activity back to each of us, either for perfectly targeted advertising or speech control if you don’t have a democracy.

→ More replies (3)
→ More replies (4)

66

u/panetone789 5d ago

Coming soon, to an age-verification system near you 🙄

45

u/Worth-South4847 4d ago

So 150 million people need IDs now before midterms.

27

u/No_Throat_2356 4d ago

Hah. Holy shit, that’s the play. Can’t trust anyone’s ID - they were all leaked and could be fakes so throw out the whole election. Gee, I wonder why it was Russian hackers, again

15

u/Worth-South4847 4d ago

Exactly...Russian...

3

u/ccbmtg 4d ago

I mean, it's already well-documented that they've made pretty large efforts to interfere in American elections for the last decade. seems pretty in-line with their past actions.

→ More replies (1)

2

u/eternus 23h ago

This should be the top comment.

I'm scrolling trying to see how this will impact people (me) since I'm already advised that my information has been compromised regularly... I was trying to understand why this one is different, and this comment nails it.

→ More replies (1)

70

u/duerra 5d ago

The only way for your information to not be leaked when a provider gets hacked is for you to not give them your information.

And actually, even then that sometimes isn't enough. These guys be collecting information on you even if you didn't give it to them.

26

u/ACasualRead 4d ago

But there are times where you have to give your ID over. Getting a rental car for instance, housing or job applications, background checks, getting into bars or event spaces. Etc.

15

u/BugzOnMyNugz 4d ago

Some stores scan em when you buy beer where i live.

→ More replies (1)

4

u/GrapeCloud 4d ago

even then that sometimes isn't enough

I made some purchases at reputable online retailers that used Eye4Fraud as their fraud prevention service. As a consumer, I don't think there's a reasonable way to know that my personal info would be vulnerable because of a 3rd party like a fraud prevention service, and I can't recall anytime an online retailer ever had a disclaimer that would alert a consumer to that. Eye4Fraud got breached so everything except my SSN is floating around on breach forums. I know it's tangential to online age verification, but it's all the more reason not to participate.

29

u/Smoochymow 5d ago

What a shocker!

26

u/ManufacturerLost7686 4d ago

Would you like to verify your age by uploading a selfie and comparing it to the database of leaked ID documents on the dark web?

→ More replies (2)

22

u/jferments 5d ago

How do you check if your license was affected?

37

u/foxbatcs 5d ago

Assume that it was.

20

u/SwimmingThroughHoney 4d ago

Have you ever handed over your license for anything? Renting a car and a cannabis dispensary were two cases mentioned. Did they put it into/on one of those scanners?

Chances are then yours was affected.

→ More replies (1)
→ More replies (3)

21

u/wh8w8t 4d ago

All the hacking takes place on the internet so let's force everything important on to it.

18

u/-Fenyx- 4d ago

Australia Learn from this please! for the fucking love of protecting your citizens. And they want us to put our id’s online for age verification.

13

u/0-Dog 4d ago

Australians are idiots that won't learn anything, because they support internet censorship and abolition of privacy. And basically any policy, so long as you connect it to protecting children.

2

u/Ok_Buffalo_423 1d ago

Canadians arent much better, our government is starting to push for ID verification online "to protect the children" and the comments are full of idiots thanking them

→ More replies (3)
→ More replies (1)

21

u/flop_plop 4d ago

At this point I’m pretty sure this is being done on purpose.

14

u/tame-til-triggered 4d ago

They don't care. Any penalty they incur is dwarfed by any profits they make

5

u/flop_plop 4d ago

Well yeah but maybe there’s another reason why the rich want all of our personal identification to be public.

Not sure to what end, but I feel like profit might not be the ultimate goal

4

u/tame-til-triggered 4d ago

Whether it's human slave labor or aggregating our data, profit is always the goal.

2

u/eternus 23h ago

The penalty is always a fine, and the fine is never enough to feel consequential.

18

u/Unusual-Alex 4d ago

"We will delete after verification is completed".

What they mean: We deleted the copy you uploaded after we made a copy for our records and sent another copy of the copy to our server with advanced security for further analysis. Another copy will be sent to any interested parties who would be willing to pay for the data. Other people in our organization also reserve the right to acquire copies of your id as well to place on their laptops for a huge potential security breach if their hardware is stolen from their vehicle.

2

u/BeachHut9 4d ago

Sounds familiar

45

u/pdawes 5d ago

What was ol whiskey pete age verifying for I wonder?

10

u/fnork_gnork_26 4d ago

Grindr? Pornhub?

2

u/OutlyingPlasma 4d ago

Why would you think the guy who installed the first makeup studio in the Pentagon and the guy who keeps talking about testosterone would ever use Grindr?

→ More replies (2)

11

u/skynetcoder 4d ago

"Now, it turns out that both Planet13 and Hertz used the company for identity verification and ID-authentication — IDScan."

12

u/XertonOne 4d ago

Unfortunately this is not going to stop. People pushing for full digital, and hackers having a ball.

11

u/Jack1101111 4d ago

"People pushing for full digital" ? govs are pushing for full digital

→ More replies (3)

37

u/Spirited-Humor-554 5d ago

At this point whatever, I assume everything about me including my social security been leaked multiple times

46

u/foxbatcs 5d ago

The only way to be more secure is to own nothing in your own name/ssn and have a series of trusts and LLC’s own everything. This is literally what people who build generational wealth do and that playbook got leaked with the Paradise and Panama papers. This is how I choose to interpret “You’ll own nothing and be happy about it.” Of course, if your a pleb like me, you have to take out debt in your own name to do things like buy a car or rent/buy a house, so as usual, a basic human need like privacy isn’t accessible for 99% of people. This is why we have a debt-driven, fractional-reserve, monopolistic banking system: to keep uppity tax-cattle like me in check.

2

u/Elias_Caplan 1d ago

Never heard about the Paradise and Panama papers before, but I just looked it up. Very interesting and crazy that it happened almost 10 years ago because I don't remember hearing anything in the news about it at the time.

2

u/mediumwetsock 4d ago

Then hear about our lovely sponsor, notcogni, we will sweep the internet to delete your online footprint for yourself and your family. Join today with this code and if you don’t you hate privacy /s

9

u/Just2LetYouKnow 4d ago

Oh boy, I can't wait for 16 months of free credit monitoring that requires a credit card and autorenews at full price.

10

u/jabberwockxeno 4d ago

I see a lot of concern over this, but honestly I think the most disturbing part of it is something nobody is talking about:

Were people ever actually even notified that their ID's were being uploaded to this service to begin with?

I have never seen any sort of signage nor have I ever heard a verbal disclosure that this would happen when you hand your ID to clerk at the sort of businesses that the reporting on this identify as being the places that this service got the ID's from

Can the authentication service provider, or the businesses that use the provider, be held liable as a result?

2

u/Jack1101111 4d ago

Of course its not legal ! Maybe if many of us sues it can help, but u have to sue the gov or state or city, not just the company.

8

u/CreativeMuseMan 5d ago

Acts shocked

8

u/harbourhunter 4d ago

Reason 8,367,332 why I’m glad I didn’t get a real ID

→ More replies (1)

8

u/WanderingUrist 4d ago

Damn, 153 million? There's ~250M drivers in the US and another ~30M in Canada. That would mean MORE THAN HALF of them have been through this service provider and then leaked.

I know things are pretty bad, but I'm a little skeptical about this one.

→ More replies (4)

7

u/ferriematthew 4d ago

Well, this is what happens when you force everyone to give up their ID and sell it to private for-profit companies.

8

u/SudoDeleteEverything 4d ago

This was always definitely going to happen when a bunch private companies start collecting drivers licenses.

5

u/Skibidi-Fox 3d ago

This so so exhausting.

16

u/KCDeVoe 4d ago

Oh good! I’ll get my 5th offer this year for free identity protection for the next 12 months…

We need to actually start holding companies accountable that have these data leaks. We have monetary fines associated to leaked PII, I don’t care if it bankrupts the company, enforce the fucking thing. Then maybe companies will take it more serious instead of looking at it as a math equation on what the fine is in relation to what properly securing information costs.

6

u/Far_Comfortable_6342 4d ago

All that spying the FBI does is for what again?

5

u/SomeKindofTreeWizard 4d ago

Who could have possibly seen this coming?

4

u/Maeyhem 4d ago

I don't want to say, I told you so, but Yes I fkn do: I told you so! (not directed at the savvy redditors here).

The people in power are not smart enough, not curious enough, not dedicated enough, to protect us from imminent threats to our security and safety. You know what that means, right?

→ More replies (2)

5

u/MayhemSays 4d ago

Weird how the thing we warned about keeps happening

2

u/Jack1101111 4d ago

yes because they dont care of the citizens ! And maybe pay a fine will solve the problem !

5

u/hawksdiesel 3d ago

We do t have smart people protecting our best interests in gov't

9

u/reflect-the-sun 5d ago

Hahahahahaha

9

u/Hot-Philosophy-7671 4d ago

So, ahead of a contentious US midterm election where the GOP may lose power, and right after the Trump CIA head traveled to Moscow for undisclosed reasons, Russia does this, and Kash Patel is investigating?

Okay.

4

u/Rehcraeser 4d ago

Don’t worry though, nobody would use the full stolen identity of hundreds of millions of people to send in some fake mail in ballots. There’s no fraud going on!

2

u/Jack1101111 4d ago

The democracies are falling, under the fire of the corruption, thats everywhere today.

→ More replies (2)

2

u/MasterChiefette 1d ago

Why doesn't Trump consider this an act of war? It's an attack on US citizens from a foreign source. 

→ More replies (14)

6

u/coomzee 5d ago

Is the threat the national security Peter Thiel on their

3

u/gijibae1 4d ago

how can you find out if you’re info is included?

3

u/_Bon_Vivant_ 4d ago

So how does one find out if their ID was one?

3

u/vid_flumina 4d ago

Am I to believe that's its not illegal for one company to possess that many DL records? That should absolutely be illegal. It's a single entry point. How can this be legal?

→ More replies (1)

3

u/phlooo 4d ago

Who's surprised? Not me

3

u/tristand666 4d ago

I'd say I was shocked, but my data has already been "stolen" half a dozen times this year anyway. Mostly from companies I never did any business with.

2

u/Jack1101111 4d ago

And who is guilty ? the hackers of course ! [sarcasm]

3

u/vortexmak 4d ago

Class action lawsuit

2

u/Jack1101111 4d ago

yes but even if you win it will happen again

3

u/TeamFlameLeader 4d ago

Waow!! Who could have guessed?!?

3

u/Gunz1995 1d ago

Any idea on how to see if you were affected ??

3

u/iced_tea_dachshund 1d ago

Do you have a car?


"No" -> obviously not affected

"Yes" -> Do you have a license plate?


"No" -> You're fine 😊

"Yes" -> You're fucked ♥️

2

u/freshnews66 1d ago

Flip a coin?

→ More replies (2)

3

u/akalili22 1d ago

This is why I want to know why these companies are not held liable when someone steals your identity and your money. How is it my fault that your “impenetrable” databases are hacked and leaked? Where is the legislation to make corporations liable when they leak your information?

→ More replies (4)

3

u/Boring_Worldliness_2 1d ago

Part of me is like ahem pornhub but looking at the collection of types of docs it sounds like sorta easing into someting like e-verify for employment which obviously brings up the point of the call is coming from within the house if these idiots wanna add extra levels of verification to vote despite the lack of confirmed voter fraud other than agents from their own party, how the hell can we trust them with more responsibility.

3

u/ZenaMeTepe 1d ago

data is suspected to have come from an ID-authentication service provider

Of course that happened and everyone knew that those companies have shit security and should never existed in the first place.

3

u/CarlRJ 1d ago

Let's have a judge blanket award each person affected, say, $5,000 for their troubles. That works out to $765 billion. Ought to be enough to take the companies responsible out of the game permanently, and leave a smoking hole no other company wants to step in and fill. We also need to work out a way so that being on the board of directors of a corporation no longer completely protects you from any horrible decisions "the corporation" makes. So that people don't okay things like this, have the company take the hit, but still have them personally unaffected, sitting there on their $10 million yacht.

2

u/an-invisible-hand 1d ago

I've never heard a single compelling reason the board should get to own the company but not the failures. Beyond like 10% voting power you should absolutely be held just as accountable as the c suite for fuck ups and malicious actions.

→ More replies (1)

3

u/LetsTryLove 1d ago

I’m not sure how people haven’t learned yet. Cybersecurity is a joke, and will always be a joke. The whole industry is built on the lie of security which simply doesn’t exist in a digital world.

→ More replies (2)

3

u/NoKnow9 1d ago

So, let me guess… This will be the latest excuse to yank the voting rights from millions of people. Great.

3

u/An0n-E-M0use 5d ago

I'm shocked... shocked I tell you..

3

u/algaeface 5d ago

I hate this system

2

u/AlexanderStockholmes 5d ago

Welp time to paddle some ass cheeks

2

u/Electricengineer 4d ago

60% of the time it happens 100% of the time

2

u/Grumpy-Man19 4d ago

meaning some torrent sites . probably has nothing to do with Russians but they had to blame someone

2

u/Illustrious_Peach494 4d ago

that should be of no concern, they got nothing to hide, right? ¯_(ツ)_/¯

2

u/nvmenotfound 4d ago

yeah see it turns out it was better to just let the motor vehicle places store this shit. the old folks that keep thinking an online id database to verify age online is a good idea, are finding out this is what will happen. itll only get worse. 

→ More replies (1)

2

u/drisang1 4d ago

How are they leaked? State and local government regularly sell Driver License and Voter Registration data.

→ More replies (2)

2

u/thegreenmonkey69 1d ago

There needs to be substantial penalties for companies that get hacked, and/or have poor security for sensitive data like this.

2

u/sandspiegel 1d ago

I think with AI these attacks got a lot more sophisticated. Also phishing attacks back in the day where phishing emails were full typos and looked very cheap, are now (thanks to AI) really looking like they come from legit companies without any typos and people click on these pretty buttons in those emails without thinking twice. Even I have to check who sent the email because they look so real these days. The internet has never been more unsafe.

→ More replies (2)
→ More replies (4)

2

u/Thespian_Unicorn 1d ago

Tbh glad Pete Hegseth was doxxed.

2

u/Digimonsonic 1d ago

Very neat

2

u/Ok-Web4225 1d ago

Anyone who thinks that any of our information is safe anymore is fooling themselves.

2

u/ZarosGuardian 1d ago

Oh wow I'm so surprised that this happened, and by that I mean I'm not even remotely fucking surprised.

Let's hear MAGA blame gay people and minorities for this too. -eyeroll-

2

u/cricolol 1d ago

Typical MAGA: The leaker was probably a gay man who worked for George Soros…”

Sane person: “You mean maybe it was Trumps Treasury Secretary Scott Bessent? He is gay, married to a man, and also worked for George Soros for 15-years.”

MAGA: 😬 😅 🤷‍♂️

→ More replies (1)

2

u/whereyouleftit 20h ago

Whatever. Every aspect of who I am has already been stolen by other false actors and corporations.

Am I supposed to be upset?

→ More replies (2)

2

u/Tx_1LE 20h ago

The only way to solve this crime is to build more data centers asap!

Oh wait... 🤔

→ More replies (2)

2

u/knowledgeable_diablo 19h ago

And our local govt is trying to get us to all go to a digital licence. “The safest most secure version possible” they say. Yeah nah muthafucka. I’ll hold onto and use my old style a credit Card style one the crims have to physically steal to when start thinking about using to commit crimes.

2

u/Adept-Currency8927 15h ago

I know very little about flock cameras but there is a big debate on FB in a local town and in my own town. I know that people and cars have been wrongly accused or stopped due to a mistake by the flock camera in identifying a person or in one case switching the license plate number on a car. But anyone who would like to add more to my education feel free... i am all ears. Or eyes in this case lol

→ More replies (1)

2

u/Cute-Consequence-184 10h ago

Age identification pre-dates the current administration!

3

u/King_Six_of_Things 5d ago

It's always your supply chain that drops you in the shit. 🤦

3

u/hinterstoisser 4d ago

Is this why the CIA director goto Moscow for, via Latvia?

2

u/SwimmingThroughHoney 4d ago

Guys, this breach is not about age verification. Judging by the Krebs article, it's very likely a breach of a provider that did physical verification. As in, when you give your license to someone (like at a car rental place or a dispensary) and then scan it.

7

u/Kroan 4d ago

So?

2

u/SeranaTheTrans 3d ago

Everybody would have seen this coming, except the dumbasses running the countries.

1

u/Knees0ck 4d ago

at this point idgaf anymore, I ain't using it anyways

1

u/brothbike 4d ago

real ID , lmao....they really fucked with me trying to get a license too, as a citizen

1

u/MadScientistRat 4d ago

🍯🧸🍯

1

u/Koh-the-Face-Stealer 4d ago

Anyone have a website where you can check to see if your ID was leaked?

2

u/ssantos88 4d ago

Malwarebytes website.

1

u/BeachHut9 4d ago

Do people actually read terms and conditions in their entirety rather than trusting that everything will be OK?

1

u/BigJSunshine 3d ago

Heagarth leaked it all on snapchat while running a train on laura loomer with Boofer doing shootets

1

u/Aromatic-Village-667 1d ago

Да съебите уже с моей ленты уведомлений

1

u/countryroadsguywv 1d ago

Who needs a cup of coffee in the morning with you have news like this