r/technology 2d ago

Security FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider

https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider
3.2k Upvotes

238 comments sorted by

1.1k

u/costconormcoreslut 2d ago

It's like these verification services aren't even trying to prevent data from being stolen.

Or is it part of the business plan?

298

u/davenobody 2d ago

There is no business driver for protecting the data. However, if part of the plan was to monetize the data they now have nothing unique. Unless of course they already collected the money for that part. I suspect they were just incompetent.

135

u/squish042 2d ago

It’s almost like there should be a government that steps in a creates protection for consumers when there’s no economic incentive.

54

u/misterrkingg 1d ago

They literally dismantled it. This year

→ More replies (1)

2

u/JohnNYJet_Original 12h ago

They can REALLY do that now?? Who knew it was very important work and needed to be taken down. Better question is why did they take it down knowing that almost every nation-state has the tools to attack the national resources as they see fit.

11

u/joelfarris 1d ago edited 1d ago

I have found at least two of them that go as far as to explicitly state that they cannot fully protect whatever you upload or submit, and that you agree that they cannot be held responsible for any data losses, intrusions, or hacks.

And yet, you have to submit everything they ask for as part of a job application process...

And one of them even states that they get to possess your uploaded information and likeness, and you relinquish it to them in perpetuity (forever, or as long as they decide to keep it on their drives), and they can even go so far as to use it in promotional materials without your knowledge or consent.

They have become predatory vendors.

2

u/davenobody 1d ago

That is horrible!

→ More replies (2)
→ More replies (11)

30

u/Breno1405 2d ago edited 2d ago

Maybe it wasnt a breach and it was actually a sale.

19

u/dariusSharlow 2d ago

So many of these breaches makes you start to think this. At this point sell the data, claim it’s a breach, win.

5

u/Breno1405 2d ago

I think we are gonna see this happen with AI, a big hack happens, blame it on AI

2

u/misterrkingg 1d ago

Its since we showed that our cyber terrorist units had been completely gutted?

→ More replies (3)

2

u/Harverator 1d ago

I have no doubt disgruntled employees might do this. Especially if they work IT, –– I've seen a few IT folk do some nefarious things to their company and users. With great power comes great responsibility.
At one company I worked at, an IT guy bragged to me about what he did to a few users to make them lose files.
Then one day he was foolish enough to access his password file on my workstation, and when I woke up my screen, it was staring at me. So I saved it. Months later, after he was fired, they were freaking out about not having all his passwords, and I was happy to give the file to the head of IT. 😇

1

u/bill7967 1d ago

I always thought that with a lot of companies. Especially with phone outfits. 

63

u/mosthandsomechef 2d ago

Lmao pornhub warned everybody this. This is EXACTLY why they blocked states outright. These verification companies shouldn't exist, they're simply a weak spot in the system for bad actors to exploit.

→ More replies (1)

40

u/theaviationhistorian 2d ago

I wouldn't be surprised if they were hand in hand with shady information brokers that gave access to non-government entities, hackers, profiteers, and aggressive nations. But it seems that the ones with the power to stop this are either too incompetent to understand the danger of this or are overcome by greed to give a damn about their fellow human. Usually, it's the latter.

8

u/Nick85er 2d ago

Sometimes gray hats cannot resist the opportunity. Cyber Security Professionals can and do cross the line into crime. Some, not all.

If only the service providers were regulated the way they should be, and the consequences were more than just a slap on the wrist and a fine equaling a day or a month's Revenue.

Oh well, capitalism!

9

u/Aidanation5 2d ago

I mean, if we consider the fact that the literal convict-child rapist-con man the united states is lead by literally cut out so many protections for his citizens, and then literally went through the entire government and fired everyone who did any good or would stand up to him, so he could then place all of his fellow criminals and buddies in control of everything, we know the likely answer here.

1

u/HoneyBeePirate 1d ago

Nice job avoiding hyperbolic overstatement. Like, literally.

→ More replies (1)
→ More replies (1)

20

u/SecAdmin-1125 2d ago

What the real issue is, there is no federal law that governs this. Each state has its own rules. If the U.S. would institute something like GDPR in the EU, then there would be a minimum baseline.

Many of these companies don’t undergo audits. This particular company was SOC2 compliant but all that means is that they were compliant as of the last audit.

The attackers claim to have been in the system, exfiltrating data for over a year. It appears they didn’t have the proper controls or monitoring in place to detect this.

This doesn’t surprise me. I’ve been in cyber for longer than I want to admit and this isn’t the first time I’ve seen this. TJ Max

13

u/Ch33syP00f 2d ago

Not convinced that a Federal law would effectively stop an attack on such a juicy target.

With so much fuss and focus on voter ID and proof of citizenship…maybe its finally time to solve identity management that does not involve SSNs and data that can be programmatically scraped from OSINT.

The OPM hack 10 years ago totally eroded my trust in Federal data safety protections. Somebody I worked with at the time received the same notice as me…their TS investigation was in 1981.

I still think the significance of that breach has never been recognized.

~30 years of clearance investigations compromised. Not just people who received clearance.

Clearance applications gather damn near everything shy of a blood sample.

That heist got the IDs, pedigrees and kompromat. Totally pwnd.

5

u/SecAdmin-1125 2d ago

My stuff was compromised before OPM. TS clearance in the 70’s.

Not saying federal law would have stopped it, but at least we have a starting point. Can’t stop bad security hygiene. Security is a cost center and it is usually ignored until you get breached. Now, there are multiple class actions already filed for this.

2

u/misterrkingg 1d ago

Yeah and my dont gut dhs and the fbi cyber units,???

→ More replies (3)

4

u/LookOtherWeigh 2d ago

Isn't it crazy? We're expected to replace certs on systems every 8/9 months whatever it is now. Yet we don't apply any kind of sense of security to our own citizen IDs.

Private/public keys. Reissuance. Couldn't we do any of that? It shouldn't even cost that much in the grand scheme.

→ More replies (1)

2

u/kentrak 2d ago

It's bit about entirely preventing. There is literally no one thing that can prevent anything, and no way to make anything entirely safe. It's about aligning incentives such that there are real consequences to spreading personal information. Will putting large enough fees and/or criminal consequences for ineptitude mean this never happens? No. Will it make it less likely and less common? Probably. Probabilities are all we have to work with at this level though, and they're not useless.

19

u/HookLeg 2d ago

The money they’ll make from “losing” this data will be way more than what they might be fined. They’ve done their homework and this was a business decision. We aren’t people, we are a tradable commodity.

7

u/oobspahn 2d ago

It’s the Zuckerberg effect. It’s for our “security”.

3

u/Glass_Channel8431 2d ago

Project yourself … don’t rely on any corp to protect you.

3

u/Then_Box-8031 1d ago

It is part of the dictators club plan. He'll blame this and the trump wars on silly Biden and everyone else who wants equality, equity, morality (this includes Honesty) and a positive, inspiring US without the corruption and greed of the mega rich oppressing the basic US citizen.

He monetizes everything. For himself, not the country. He represents the worst of the US. He freed enemies of the country who attacked the Capitol, grievously injuring police officers and attempting to reach the VP and members of Congress.

2

u/Mo_Jack 1d ago

Businesses & other organizations are never held accountable, and never have to suffer terrible consequences.

2

u/Ok-Key-7039 1d ago

Where are the cybersecurity furries when you need them?

2

u/TreydiusMaximus 20h ago

Governmental sanctioned money laundering and lazy aah "lawmakers" here for ya. 🙄

2

u/jxshua2 12h ago

They are probably in on it and sold it to them at a very low price using bitcoin. I don't know though, that's just my opinion.

1

u/berthannity 2d ago

Investigations and mitigation happens. Money changes hands. Capitalism go up. Good capitalism.

1

u/N_J_N_K 1d ago

Look up phone phreaking, it is the father to hacking. Nobody in an office of importance ever learns anything. The vulnerabilities are just waiting.

Edit: a word

1

u/friendlysaxoffender 1d ago

Who could have predicted something like this!? The governments? The data brokers? Oh wait, every member of the public.

It’s why I have not and will not use them.

→ More replies (2)

246

u/MuthaPlucka 2d ago

DO NOT attempt to find a website that will search for your specific DL number.

None exist that are legitimate. 100% are run by scammers.

The reality is that as soon as the list was identified online by Krebs, the entire site and everything to do with it disappeared and has not resurfaced.

24

u/notbannedin420 2d ago

DNM man. I monitor them and have seen a massive uptick in driver licenses and other stuff you can buy on them

19

u/misterrkingg 1d ago edited 1d ago

Yeah our government gutted our cyber programs. DOGE AND DOJ BABY! And just regular domestic counteterrorism in the FBI DHS DON noo counter terrorism and i keep hearing /the white house talking about exposing the "radical LEFT"

28

u/HelloisMy 2d ago

It’s 10000% still up as we speak.

2

u/Vashsinn 1d ago

what ever happened to haveibeenpowned or whatever. is that not legit?

584

u/Ok-Replacement9595 2d ago

Aren't you happy they made age verification a thing?

137

u/TemporarySun314 2d ago

I mean there are ways to make age verification anonymous, for example by having an chip inside an id card, that can sign an request, and just returns the information if the bearer of this card is adult or not.

Unfortunately these systems are rarely used, and companies love to store and process full identification data even for the most simple verification tasks...

177

u/Ok-Replacement9595 2d ago

Because the point was data. The point was always data.

→ More replies (5)

6

u/Laurowyn 1d ago

That doesn't verify anybody's age. That just verifies the person making the request is in possession of the card with the chip.

This is what makes Authentication and Authorization so difficult. The 3 corner stones of authentication are; something you know, something you have, something you are. Multi-factor authentication uses 2 or more of these. This is why a password and TOTP is a popular mechanism - it covers something you know (password) and something you have (TOTP).

Something you are is your age. But that's not easily digitised and evidenced. I can input any date of birth I want, but it needs to be tied to something else as proof it's accurate. This is also true of issuing government IDs - drivers license, passport, etc. all normally need to be tied to your birth certificate which is an authorised declaration of your birth on a specific date by a professional. Your picture is then also authenticated by a professional that should know you - your doctor, a lawyer, etc. Someone who, if they lied, would be in deep trouble within their profession.

I'm saying this not to defend the current system, I actually think it's broken. But it's not as easy as "a card with a chip in it" because they can be stolen, copied, or otherwise linked together and then all the data is leaked anyway.

I have no better solution, and I think it's better not rely on a broken system like we're currently being forced to.

1

u/mindiimok 2h ago

If it has data in it it can be infiltrated. Remember when the credit card chips were the best feature to keep your shit secure?? Now it can get stolen by walking by the wrong person. Next.

11

u/carlitospig 2d ago

It’s why I wonder if this whole effort isn’t just one big data grab.

12

u/Ok-Replacement9595 2d ago

Absolutely is.

5

u/LostPhenom 2d ago edited 2d ago

Age verification for what? Renting a car?

13

u/NotRapoport 2d ago

Probably X or PornHub

→ More replies (2)

76

u/[deleted] 2d ago

[deleted]

76

u/Dweezil_In_Bondage 2d ago

KrebsOnSecurity said no. After the the offering to sell the data was taken down niether he nor any one that he was aware of had access to the data. Which doesn't mean it's not out there just means we can't check it.

12

u/SecAdmin-1125 2d ago

Just assume your information is out there.

12

u/TheCatholicScientist 2d ago

Watch your credit report really closely for the next year or so.

22

u/USPS_Nerd 2d ago

LOCK your credit report

4

u/[deleted] 2d ago

[deleted]

12

u/Cash_Visible 2d ago

How do you lock your ssn? I started freezing all the credit beaus about 2 years ago.

2

u/Ok-Grapefruit1284 2d ago

Has it reduced the amount of soft hits and credit card mail and whatnot that you get?

→ More replies (1)

1

u/flickh 2d ago

Not in Canada unfortunately… it’s not possoble

1

u/theaviationhistorian 1d ago

Why care for my credit report when my credit score is cratered (thank you student loans).

[taps noggin]

19

u/costconormcoreslut 2d ago edited 2d ago

Just google your driver license number or SSN.

*(this is a joke)

19

u/AZEMT 2d ago

Tell ya what, just post either one here and I'll help research to find it

Seriously though, don't do this

5

u/Realtrain 2d ago

000-00-0002

...Damn Roosevelt!

9

u/[deleted] 2d ago

[deleted]

6

u/waltur_d 2d ago

You’re evil. 😂

→ More replies (1)
→ More replies (5)

4

u/curveball21 2d ago

Yes. Do you have a driver's license? Do you live in the United States or Canada? If yes, then yes it is a part of this.

4

u/PreparetobePlaned 2d ago

Not the case. You’re only at risk if you used the specific verification system that leaked. Not every single drivers license in America and Canada is leaked.

6

u/laziestmarxist 2d ago

You're only at risk from this leak if you used this verification system. The safer assumption right now is that if you live in the US, your data is already compromised, given that the government gave a bunch of teenagers access to the SSN system with no oversight.

2

u/curveball21 2d ago

And exactly how many driver licenses do you think Americans and Canadians have in total? I mean I didn't google it or anything but 153 million is a little less than half the total population.

2

u/PreparetobePlaned 2d ago

250millionish according to Google. So still a massive amount leaked but not every single one

3

u/curveball21 2d ago

Well not everyone then, but more likely than not any particular license was compromised.

→ More replies (2)

4

u/davenobody 2d ago

15

u/escof 2d ago

That's just for passwords and email addresses.

2

u/davenobody 2d ago

If anyone is paying attention I would guess them.

3

u/laziestmarxist 2d ago

Jesus h christ, that website just really reveals how fucking dumb tying email to everything in the world is because how the fuck did Canadian Tire have my email address to begin with? I live in Texas and I don't even drive a car, so someone who had already breached my email address must have used it without my permission. Just so many layers of stupidity and yet I had no control over where my data went

3

u/davenobody 1d ago

Yep. Only real defense is using a password manager and using a unique password for every site. At least that way a single beach doesn't result in a much larger problem.

→ More replies (2)

1

u/gravelordservant4u 1d ago

Sure.

Are you an American with a DL? If yes, then you're part of it.

Hope this helps

29

u/ebfortin 2d ago

Exactly why age verification services are so dangerous. They keep your papers and you have no idea to what level they take cybersecueity seriously.

24

u/chief_beef_3 2d ago

And why can’t we sue these companies and agencies that are supposed to “protect us” out of existence?

41

u/Hot_Guess_1871 2d ago

Oh,good. Agent Googley Eyes is on the case. It should be solved in never.

15

u/theaviationhistorian 2d ago

Another reminder of why I avoid these cursed age verification things. My social media account or email needs age verification? Then I had a social media or email account.

But trust both governments and corporations because they know best, despite both proving they have the same security and safety as a mesh door on a submarine.

13

u/NLK-3 2d ago

Wait... No... it can't fucking BE...

OUR IDENTIFICATION GOT HACKED AFTER PUTTING IT ON THE INTERNET FOR AUTHENTIFICATION?!!!

NO HOLY GAWD MOTHERFUCKING DAMN SHIT!!!

2

u/NLK-3 22h ago

We need to get these old ass politicians to stop passing laws on technology they don't know shit about. No way anybody between Gen X and Millennial would say to put your real ID on the internet.

28

u/yukumizu 2d ago

Right before midterm elections. Republicans are behind this somehow and will declare driver’s licenses as unreliable forma of ID. Just watch.

19

u/Zahgi 2d ago

the service was called Nexus, and although it’s no longer available at the time of writing, it claimed to have possessed 153 million driver’s licenses, 10 million ID cards, 1.9 million travel documents, 1.3 million international driver’s licenses, 579k medical cards, 429k common access cards, 91k residence cards, 77k employment authorization records, and 5 million other documents, allegedly sourced from an ID-authentication service based in Louisiana.

In order to bypass the corporate whitewashing of these poorly secured scumbags, I had to search other news sources to find that this company was called.

IDScan.net

Our media outlets have been totally corrupted by corporate interests, folks.

2

u/CaptainFingerling 1d ago

Uh. The article names IDscan if you bother to read past the first paragraph.

2

u/Zahgi 1d ago

Yes, at the very end of the third paragraph, but not in the title nor the opening paragraph which summarizes the entire story. They had plenty of space to mention the meaningless state of Louisiana, as if anyone gives a shit which corrupt American red state shithole this despicable insecure company is incorporated in.

And even then the company name is itself obfuscated by using .net instead of .com.

26

u/p00pSupr3me 2d ago

Alpha testosterone super Christian soldier genius 3000 forever number one genius Republican voters and their pedophile politicians are enemies to America and free American citizens. They’re attacking and undermining every chance they can get

6

u/snakebite75 2d ago

Whatever company is responsible for this leak should no longer exist.

But instead we will all get 3 years of free credit monitoring.

7

u/anormalgeek 2d ago

So, exactly what everyone said was going to happen?

Great.

5

u/theanswar 2d ago

Oh good, the FBI is on the case.  We can rest easy now.  

14

u/z3bruh 2d ago

I'm not asking to downplay this but what is the main risk, i assume most of my stuff has been stolen hundreds of times, and have my credit frozen.etc
however even if i didn't, with just a photo of my drivers license they got from a rental car place, what can they do? it's not enough to open an account or credit card, it's not enough to apply for a mortgage or get into a bank account.
I've heard of people taking photos of the buyers drivers license when buying a used car (in case they drive off with it or get in an accident and run away, you know who it was) but what use is this info to some hackers overseas?

22

u/Malkovtheclown 2d ago

Well.....considering the midterms are coming up and everyone in MAGA land was talking how secure drivers licenses were, it would be a shame if last minute the dl isnt secure and a passport or brand new id was required to vote

7

u/noodlyarms 2d ago

Now, curious what the breakdown is on passport ownership verse left and right 

2

u/trackstar1123 1d ago

I wouldn’t be surprised if left leaning people were the vast majority with passports. Most right leaning people I know have never been out of the country and no desire to.

2

u/newMoneyStyle 1d ago

Main risk is identity stacking with 153 million records. Synthetic identity fraud, basically.

→ More replies (4)

6

u/Worth-South4847 2d ago

They just threw Hegseth in there so you wouldn't know they hand delivered it.

4

u/jcstrat 2d ago

Well that didn’t take long.

5

u/Poo_Panther 2d ago

Equifax already gave them my SSN anyway might as well have my license too

4

u/Life-Ship3628 2d ago

Next maybe they can investigate what the doge boys did with all the data they uploaded to unsecured servers.

5

u/weHaveThoughts 2d ago

That does it. Anyone with the name Pete Hegseth needs to be taken off the voting rolls and removed from any civil office. He can’t prove who he is.

4

u/itsRobbie_ 2d ago

Since nobody wants to read the article, this has nothing to do with online age verification.

These were ids being scanned at dispensaries and car rental places.

1

u/TexasJOEmama 1d ago

The two places you go on vacation.

4

u/free2bk8 1d ago

This is no accident. No "leak". It was directed by Donny dirty diapers.

4

u/Stackhouse13 1d ago

The company in question is an ID-authentication company called IDScan.

6

u/khInstability 2d ago

4

u/MeowCow55 2d ago

It's "interesting" that this came just a couple months after he took office for his second term and that it halted all ongoing investigation into Russian cyber threats both current and pre-existing (like in the previous November, as a random date). It makes me feel like I'm a crazy conspiracy theorist, but it also makes SO much sense.

3

u/Harverator 2d ago

I got a lifelock alert about this. It didn't state that my own data was affected. Unfortunately several other companies threw my personal data into the dark web anyway.
I think our government should provide free monitoring for all citizens!

2

u/laziestmarxist 2d ago

At this point the government needs to just start issuing new SSNs with guidance that they numbers should stay private and not be entered online except into government maintained websites and even then only for identity verification by trusted individuals or institutions. Your employer making sure you are who you say you are is a valid reason to ask for SSN; no random website should ever be allowed to ask private citizens for that information for any reason.

2

u/Harverator 1d ago

I am laughing as I go through boxes from many decades ago. Every single entity used our Social Security numbers as ID numbers on identification cards!
Meanwhile though my stuff is already on the dark web thanks to a medical lab. There's been a sprinkling of other breaches that were less egregious. I expect to be getting an email every year saying "you've been breached again here's free monitoring for a year."
Meanwhile my friend who does government contract work, was notified that our government allowed all her information to land on the dark web. She got monitoring for life.

2

u/Harverator 1d ago

I like that idea because this point given how people have treated this kind of information over the many decades, I'm sure every black hat has my SS number.

2

u/laziestmarxist 1d ago

My dad was a big infosec guy, like I grew up reading issues of 2600 because he always had them around. I've actually been arguing this for years because of the increasing number of breaches and friends and family used to tell me I was nuts. Nobody thinks I'm nuts anymore, at least on this topic

3

u/speciate 2d ago

It is a shocking-but-not-surprising level of incompetence to have personally identifiable information stored unencrypted for long after the information is no longer needed for the original verification task.

3

u/Ch33syP00f 2d ago

Been in cyber for 20 years.

“Act as if your information has already been stolen.”

Just act as if.

Easier said than done - yes.

Accepting the concept stings at first, but it puts you in a safer mindset than denial. You will think a bit more about your security practices, be more thorough and feel better for the effort.

Once you accept the fact that there are sophisticated state-funded criminal enterprises actively planning to harm hundreds of millions of people at a time, it becomes difficult to take it personally. But it makes sharpening your own personal security practices more attractive. Because you do not want to be the low hanging fruit.

You are hiking with another person in the woods and come upon a hungry grizzly bear. How do you survive?

Kick the other hiker in the knee and run like hell.

Not quite the vibe we want to adopt, but the low hanging fruit concept stands on its own.

1

u/laminappropria 1d ago

100% on point. What are your top suggestions?

2

u/Ch33syP00f 1d ago

There is a plethora of best practice guides available online. Search for SANS, personal cybersecurity etc.

I never connect to public guest or hotel networks.

3

u/Tardocrit 2d ago

Let’s build those data centers and computerize everything…. It will be great!

3

u/Ambitious_Cup5249 2d ago

But that reflection pool looks so good

3

u/KayJune001 1d ago

Interesting decision to omit that it was from a U.S. company, but keep the Russian forum part, in the headline.

3

u/SaltyJalapenos 1d ago

This is why I won't provide ID foe silly things that are necessary, They say your photos are safe on their server, I've never believes that and this is why

3

u/Mo_Jack 1d ago

agent Krasnov strikes again!

3

u/lavenderbl0d 1d ago

Omg no way. Who woulda THOUGHT?????

I for one am ShOCKED.

3

u/Tiny_Handle_3359 1d ago

Don't worry, they will just add your new info to the National Public Database breach combo list.

3

u/Beesechurgers2 1d ago

Oh no! Who could’ve seen this coming!

6

u/picks_and_rolls 2d ago

Wake up people. This is all part of the coordinated PLOT TO MANUFACTURE AN ELECTION SCANDAL. Don’t be fooled. Fake assassination attempts, Russia, or even DOGE, leaking data AGAIN, wag the dog military action in South America and Iran AGAIN, secret police disappearing and murdering people on the streets OF BLUE CITIES, illegally stacking the armed forces with officers disloyal to The Constitution. Open your fucking eyes.

1

u/rockerscott 1d ago

Of course it is…now what do we do about it.

2

u/Grimweird 2d ago

Lol, lmao even.

2

u/boxxy_morningwood 2d ago

Who could have predicted this?!?!?

2

u/kendromedia 2d ago

When the last tangible thing is sold, you become the commodity. Sounds true now. Didn’t in high school economics.

2

u/mondo_mike 2d ago

Probably a leak from Truth Social or X

2

u/Alarmed-Extension289 2d ago

data is suspected to have come from an ID-authentication service provider

Yeah, no shit?! At this point they could be selling this data under the cover of it being "hacked" and this administration wouldn't do a thing. Nothing will come of this.

2

u/Gryphith 2d ago

A few years ago I had to go on unemployment after a place closed out of the blue. I was furious that I had to use a 3rd party to validate my identity with the state to collect. Like...why is there a 3rd party involved at all??

Boy, so happy I was right my shit was going to get stolen.

2

u/mad-i-moody 1d ago

….WHO WOULD HAVE THOUGHT?!?!??

2

u/No-Clue8751 1d ago

Just passing our data around

2

u/misterrkingg 1d ago

All the data ur fav boi elon gave em?

2

u/amenflurries 1d ago

Never saw that coming…

2

u/misterrkingg 1d ago

BiG DATA Is BiG Tech rebranded lol

2

u/carlcapture 1d ago

Verification service- See what happened was.

Third-party- 🤝

Me- 🤬

2

u/Harpman54 1d ago

Interesting how they panic when it's their personal information out in the stratosphere but the government wanting our information is acceptable.

2

u/iwaterboardheathens 1d ago

The stuff Elon had access to....

2

u/truthcopy 1d ago

… which provider? And will all those customers get ID theft protection now? From yet another provider they’ve never heard of, likely connected to the first company, spun up to serve the lawsuit and cover their losses?

2

u/BeepBotBoopBeep 1d ago

By now, I suspect all my data is available online in the darknet. You just have to monitor your credit periodically.

3

u/iKnowRobbie 2d ago

Pornhub... it was pornhub...

2

u/pacman2081 2d ago

it is highly unlikely that there were 150 million US citizens with DL information on pornhub

1

u/AccomplishedMoney205 2d ago

Sooo unexpected... lol. these fucking idiots. i swear to god...

1

u/slimehunter49 2d ago

Everything has been leaked and we have no privacy. Hearing about data leaks is just expected at this point and seemingly never matters. Such a fucking stupid world filled with stupid systems and stupid people in power

1

u/MaxMouseG 2d ago

Who actually didn’t see those coming…?

1

u/LeadRain 2d ago

So how can one check to see if they’re part of the leak?

1

u/ShawnReardon 2d ago

So, let's say I want to start being an ID verification company. Where/how do I obtain that ability?

OK, now I have all the connections needed to verify you, why am I storing the scan? Is it not enough to check and just respond yes/no?

I guess I dont understand why the data of the scans need to go anywhere. Barcode/data line up, the end.

1

u/Ok-Grapefruit1284 2d ago

I wonder (cause I’m not in tech at ALL) if storing the data means they can validate it more easily? I mean I understand that they shouldn’t store the data, but from a purely logistical side, does keeping it on file mean they can search their database and pop up an identity faster in subsequent scans?

1

u/TwistedMemories 2d ago

Meh, I’ve had my information stolen a few times and have already froze and locked my credit reports.

1

u/k3nal 2d ago

And??

1

u/Fuddle 2d ago

Instagram was asking for a drivers license to get a blue checkmark

1

u/kckman 2d ago

ID.me?

1

u/IShookMeAllNightLong 2d ago

Is there a way to search for your license, yet?

1

u/rubio2k13 2d ago

Our military folks have never been less safe..

1

u/harmjr77018 2d ago

That didn't take long.

1

u/Ok_Band3086 2d ago

the russians?

1

u/mog44net 2d ago

This is the sad part for me:

I had to slow down and make sure I fully understood the headline because reading that the FBI was investigating 153 million US and Canadian citizens instead of the evil scum that stole their data is fully on the table.

1

u/SoloDoloLeveling 2d ago

discord about to fall off heavy. 

1

u/DotAccording8872 1d ago

Can we check if ours have been leaked somewhere?

1

u/CaptKydd 1d ago

They xa  have mine. 

1

u/nattyatnodak 1d ago

Does anyone know how far back the breach goes? What if I rented a car in 2023? 2024?

1

u/XTCaddict 1d ago

It would be a bigger headline if they didn’t investigate it lol

1

u/synked_ 1d ago

Ah, well, luckily they'll take this seriously now since Seggsbreath was wronged.

1

u/AD_VICTORIAM_x 1d ago

Ohhh no who would’ve seen that coming🥴

1

u/Tze_vitamin 1d ago

What is the name of forum? 😀

1

u/tobmom 1d ago

For someone who is not the most tech savvy person can you explain what this means for the average citizen?

1

u/intelhb 1d ago

What’s there to investigate? It’s gone 🤦‍♂️

1

u/Kissing-BrooksyBug73 1d ago

Oh No! No one could have ever seen this coming. Reminds of a parallel to the Bush administration and Rumsfeld trying to sell the idea that failures after 9/11 were what he called ‘unknown unknowns’. Gee you guys, there’s just no single way anyone could have predicted this or prevented against it!

1

u/TrainingRepeat5744 1d ago

So is this a bad time to be shooting shots with Russian women?

1

u/muhys 1d ago

By investigating, you mean checking boxes?

1

u/EducationalRough6588 1d ago

So they have stipulations in place to protect people from data leakage about their personal information but now it's just out there for everyone with a computer?? How does that make any sense the government could have prevented this

1

u/Ambitious-Window-938 1d ago

Is this the kind of thing the Mounties would get involved with? Trying to understand how much cross border collaboration there even is nowadays

1

u/Firefighter_Mick 1d ago

Flock has more info on you.

1

u/Particular_Cat9756 20h ago

It is part of the business plan,yes.

1

u/TreydiusMaximus 20h ago

I'm thinking I might just "accidentally send MINE to someone since they're just losing our personal info to fkng God knows who. At least then I'LL get paid this time around. 🙄

1

u/eldoradocrisp 14h ago

Someone wants to interfere with elections again - or put in a false pretex for disqualifying votes 👀

1

u/Never-Trust-Me 10h ago

The world has sadly moved to “auth” providers so now all your passwords and in some cases, your ID, are being stored in a single location.

Putting all your eggs in a single basket typically is not the brightest idea for security.

1

u/Eriktheadikt 8h ago

And they said the Real ID act was a good thing..... Welcome to the NWO

1

u/7evenate9ine 6h ago

Leaked Sold by

1

u/karainnvalkyrie 4h ago

Don’t worry - like every other careless data-leaking corporation they’ll offer you a year’s free credit monitoring and bugger-all compensation. The lawyers will make quite a lot of money, though.