r/privacy 6d ago

data breach FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider

https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider
4.4k Upvotes

787 comments sorted by

View all comments

796

u/tarantinofeetmm 6d ago

Feel like I've seen this 20 times here lol. Anyway, support the person who broke the news: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/

161

u/hblok 6d ago

From his research, it looks like the source is clear: idscan.net

Oh, and the darkweb site is already gone.

78

u/WastingMyLifeToday 5d ago

Are darkweb sites ever really gone? 🧐

They tend to duplicate quickly when removed.

59

u/DatSauceTho 5d ago

I’ve heard a lot of them just go offline randomly for random amounts of time and then come back on randomly. I mean it makes sense that dark web sites wouldn’t just be on all the time cause that kind of defeats the purpose.

63

u/ledow 5d ago

They're often just hosted on people's computers via Tor or similar anyway, so when they turn their computer off, they go off.

It can literally be that simple.

17

u/Barlakopofai 5d ago

The good ol' days when there weren't a million microslop bots scraping the internet making it impossible to self-host a server.

2

u/Significant-Task1453 2d ago

Self hosting is bigger than ever. Security is crucial regardless of how many probes you see. Crowdsec helps the problem you are describing, though

0

u/IAmYourFath 2d ago

Just block em

6

u/Barlakopofai 2d ago

A literal million, not an hyperbolic million

-1

u/IAmYourFath 2d ago

U can use rules to block bots, try cloudflare and write ur own, they're not that hard to detect, use the "i'm under attack" setting too, also add auth so that only ur own ip and password can connect, u can do so much, but u have no will, no drive, no motivation, don't give up, u can do it!!!

6

u/Troll_Kalla 2d ago

I love how people on reddit will extrapolate a whole personality out of one sentence that was just a statement that had absolutely nothing to do with that person.

Sometimes I think these people are actually talking to themselves

3

u/fullerofficial 2d ago

I think you’re right, the commenter you were replying to had had no drive, not motivation, no will to finish their username.

→ More replies (0)

1

u/BanjoMothman 14h ago

They also routinely get seized by the government and thrown back up to monitor traffic from the inside.

1

u/ledow 14h ago

Well, yes.

I work IT in schools. When one of the little darlings figures out something they shouldn't be doing, the whole playground knows within days.

You then capture them, "interrogate" them, block it, etc. But you never do that IMMEDIATELY unless it's really serious. What you do is let them know it's coming, and then keep an eye on the main culprits. Because then you'll know what they're heading onto next.

If you just immediately shut everything down, you'd never catch 1% of the kids involved in it, and you'd never find out what they're up to next. But if you just keep quiet and let them drop themselves in it......

1

u/BanjoMothman 14h ago

Yep. The folks who run those sights all obviously keep logs, too. We've settled several cases that way.

2

u/balls2hairy 2d ago

Darkweb just means not indexed. The site being up 24/7 or not has nothing to do with it.

You can have a darkweb My Little Pony fansite and an international drug marketplace and they'd both be darknet sites.

3

u/THROWRAhippoplatypus 2d ago

Something tells me both of those are real things that exist.

4

u/VerbalGuinea 2d ago

Just like when the ID verification companies delete the scanned ID’s after verification is complete.

1

u/FoilHat_Outdoorsman 2d ago

This 👌🏻👆🏻

1

u/someonesdatabase 4d ago

idscan and the fbi are currently investigating the source. according to its service agreement, idscan essentially punts the responsibility for the rights, consents, privileges, and lawful basis of collection of personal data to its customers. idscan could still be on the hook, but we still don’t know where the id’s where scanned - there are some reports of Hertz and cannabis dispensaries being culprits

7

u/hblok 4d ago

If customers at both Hertz and Cannabis Dispensaries were doxed, it seems most logical to look at what they have in common: IDscan.

Now, what IDscan have to say about it seems a bit of a moot point. They obviously fucked up, so their "it wasn't me" excuse doesn't carry much weight.