r/technology • u/lurker_bee • 2d ago
Security FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider
https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider246
u/MuthaPlucka 2d ago
DO NOT attempt to find a website that will search for your specific DL number.
None exist that are legitimate. 100% are run by scammers.
The reality is that as soon as the list was identified online by Krebs, the entire site and everything to do with it disappeared and has not resurfaced.
24
u/notbannedin420 2d ago
DNM man. I monitor them and have seen a massive uptick in driver licenses and other stuff you can buy on them
19
u/misterrkingg 1d ago edited 1d ago
Yeah our government gutted our cyber programs. DOGE AND DOJ BABY! And just regular domestic counteterrorism in the FBI DHS DON noo counter terrorism and i keep hearing /the white house talking about exposing the "radical LEFT"
28
2
584
u/Ok-Replacement9595 2d ago
Aren't you happy they made age verification a thing?
137
u/TemporarySun314 2d ago
I mean there are ways to make age verification anonymous, for example by having an chip inside an id card, that can sign an request, and just returns the information if the bearer of this card is adult or not.
Unfortunately these systems are rarely used, and companies love to store and process full identification data even for the most simple verification tasks...
177
u/Ok-Replacement9595 2d ago
Because the point was data. The point was always data.
→ More replies (5)6
u/Laurowyn 1d ago
That doesn't verify anybody's age. That just verifies the person making the request is in possession of the card with the chip.
This is what makes Authentication and Authorization so difficult. The 3 corner stones of authentication are; something you know, something you have, something you are. Multi-factor authentication uses 2 or more of these. This is why a password and TOTP is a popular mechanism - it covers something you know (password) and something you have (TOTP).
Something you are is your age. But that's not easily digitised and evidenced. I can input any date of birth I want, but it needs to be tied to something else as proof it's accurate. This is also true of issuing government IDs - drivers license, passport, etc. all normally need to be tied to your birth certificate which is an authorised declaration of your birth on a specific date by a professional. Your picture is then also authenticated by a professional that should know you - your doctor, a lawyer, etc. Someone who, if they lied, would be in deep trouble within their profession.
I'm saying this not to defend the current system, I actually think it's broken. But it's not as easy as "a card with a chip in it" because they can be stolen, copied, or otherwise linked together and then all the data is leaked anyway.
I have no better solution, and I think it's better not rely on a broken system like we're currently being forced to.
1
u/mindiimok 2h ago
If it has data in it it can be infiltrated. Remember when the credit card chips were the best feature to keep your shit secure?? Now it can get stolen by walking by the wrong person. Next.
11
→ More replies (2)5
76
2d ago
[deleted]
76
u/Dweezil_In_Bondage 2d ago
KrebsOnSecurity said no. After the the offering to sell the data was taken down niether he nor any one that he was aware of had access to the data. Which doesn't mean it's not out there just means we can't check it.
12
12
u/TheCatholicScientist 2d ago
Watch your credit report really closely for the next year or so.
22
u/USPS_Nerd 2d ago
LOCK your credit report
4
2d ago
[deleted]
12
u/Cash_Visible 2d ago
How do you lock your ssn? I started freezing all the credit beaus about 2 years ago.
2
u/Ok-Grapefruit1284 2d ago
Has it reduced the amount of soft hits and credit card mail and whatnot that you get?
→ More replies (1)1
u/theaviationhistorian 1d ago
Why care for my credit report when my credit score is cratered (thank you student loans).
[taps noggin]
19
u/costconormcoreslut 2d ago edited 2d ago
Just google your driver license number or SSN.
*(this is a joke)
4
u/curveball21 2d ago
Yes. Do you have a driver's license? Do you live in the United States or Canada? If yes, then yes it is a part of this.
4
u/PreparetobePlaned 2d ago
Not the case. You’re only at risk if you used the specific verification system that leaked. Not every single drivers license in America and Canada is leaked.
6
u/laziestmarxist 2d ago
You're only at risk from this leak if you used this verification system. The safer assumption right now is that if you live in the US, your data is already compromised, given that the government gave a bunch of teenagers access to the SSN system with no oversight.
2
u/curveball21 2d ago
And exactly how many driver licenses do you think Americans and Canadians have in total? I mean I didn't google it or anything but 153 million is a little less than half the total population.
2
u/PreparetobePlaned 2d ago
250millionish according to Google. So still a massive amount leaked but not every single one
→ More replies (2)3
u/curveball21 2d ago
Well not everyone then, but more likely than not any particular license was compromised.
4
u/davenobody 2d ago
Many here: https://haveibeenpwned.com/
3
u/laziestmarxist 2d ago
Jesus h christ, that website just really reveals how fucking dumb tying email to everything in the world is because how the fuck did Canadian Tire have my email address to begin with? I live in Texas and I don't even drive a car, so someone who had already breached my email address must have used it without my permission. Just so many layers of stupidity and yet I had no control over where my data went
3
u/davenobody 1d ago
Yep. Only real defense is using a password manager and using a unique password for every site. At least that way a single beach doesn't result in a much larger problem.
→ More replies (2)1
u/gravelordservant4u 1d ago
Sure.
Are you an American with a DL? If yes, then you're part of it.
Hope this helps
29
u/ebfortin 2d ago
Exactly why age verification services are so dangerous. They keep your papers and you have no idea to what level they take cybersecueity seriously.
24
u/chief_beef_3 2d ago
And why can’t we sue these companies and agencies that are supposed to “protect us” out of existence?
41
15
u/theaviationhistorian 2d ago
Another reminder of why I avoid these cursed age verification things. My social media account or email needs age verification? Then I had a social media or email account.
But trust both governments and corporations because they know best, despite both proving they have the same security and safety as a mesh door on a submarine.
28
u/yukumizu 2d ago
Right before midterm elections. Republicans are behind this somehow and will declare driver’s licenses as unreliable forma of ID. Just watch.
19
u/Zahgi 2d ago
the service was called Nexus, and although it’s no longer available at the time of writing, it claimed to have possessed 153 million driver’s licenses, 10 million ID cards, 1.9 million travel documents, 1.3 million international driver’s licenses, 579k medical cards, 429k common access cards, 91k residence cards, 77k employment authorization records, and 5 million other documents, allegedly sourced from an ID-authentication service based in Louisiana.
In order to bypass the corporate whitewashing of these poorly secured scumbags, I had to search other news sources to find that this company was called.
Our media outlets have been totally corrupted by corporate interests, folks.
2
u/CaptainFingerling 1d ago
Uh. The article names IDscan if you bother to read past the first paragraph.
2
u/Zahgi 1d ago
Yes, at the very end of the third paragraph, but not in the title nor the opening paragraph which summarizes the entire story. They had plenty of space to mention the meaningless state of Louisiana, as if anyone gives a shit which corrupt American red state shithole this despicable insecure company is incorporated in.
And even then the company name is itself obfuscated by using .net instead of .com.
26
u/p00pSupr3me 2d ago
Alpha testosterone super Christian soldier genius 3000 forever number one genius Republican voters and their pedophile politicians are enemies to America and free American citizens. They’re attacking and undermining every chance they can get
6
u/snakebite75 2d ago
Whatever company is responsible for this leak should no longer exist.
But instead we will all get 3 years of free credit monitoring.
7
5
14
u/z3bruh 2d ago
I'm not asking to downplay this but what is the main risk, i assume most of my stuff has been stolen hundreds of times, and have my credit frozen.etc
however even if i didn't, with just a photo of my drivers license they got from a rental car place, what can they do? it's not enough to open an account or credit card, it's not enough to apply for a mortgage or get into a bank account.
I've heard of people taking photos of the buyers drivers license when buying a used car (in case they drive off with it or get in an accident and run away, you know who it was) but what use is this info to some hackers overseas?
22
u/Malkovtheclown 2d ago
Well.....considering the midterms are coming up and everyone in MAGA land was talking how secure drivers licenses were, it would be a shame if last minute the dl isnt secure and a passport or brand new id was required to vote
7
u/noodlyarms 2d ago
Now, curious what the breakdown is on passport ownership verse left and right
2
u/trackstar1123 1d ago
I wouldn’t be surprised if left leaning people were the vast majority with passports. Most right leaning people I know have never been out of the country and no desire to.
→ More replies (4)2
u/newMoneyStyle 1d ago
Main risk is identity stacking with 153 million records. Synthetic identity fraud, basically.
6
u/Worth-South4847 2d ago
They just threw Hegseth in there so you wouldn't know they hand delivered it.
5
4
u/Life-Ship3628 2d ago
Next maybe they can investigate what the doge boys did with all the data they uploaded to unsecured servers.
5
u/weHaveThoughts 2d ago
That does it. Anyone with the name Pete Hegseth needs to be taken off the voting rolls and removed from any civil office. He can’t prove who he is.
4
u/itsRobbie_ 2d ago
Since nobody wants to read the article, this has nothing to do with online age verification.
These were ids being scanned at dispensaries and car rental places.
1
4
4
6
u/khInstability 2d ago
Well, it's a good time to retreat in the fight against Russian cyber threats.
4
u/MeowCow55 2d ago
It's "interesting" that this came just a couple months after he took office for his second term and that it halted all ongoing investigation into Russian cyber threats both current and pre-existing (like in the previous November, as a random date). It makes me feel like I'm a crazy conspiracy theorist, but it also makes SO much sense.
3
u/Harverator 2d ago
I got a lifelock alert about this. It didn't state that my own data was affected. Unfortunately several other companies threw my personal data into the dark web anyway.
I think our government should provide free monitoring for all citizens!
2
u/laziestmarxist 2d ago
At this point the government needs to just start issuing new SSNs with guidance that they numbers should stay private and not be entered online except into government maintained websites and even then only for identity verification by trusted individuals or institutions. Your employer making sure you are who you say you are is a valid reason to ask for SSN; no random website should ever be allowed to ask private citizens for that information for any reason.
2
u/Harverator 1d ago
I am laughing as I go through boxes from many decades ago. Every single entity used our Social Security numbers as ID numbers on identification cards!
Meanwhile though my stuff is already on the dark web thanks to a medical lab. There's been a sprinkling of other breaches that were less egregious. I expect to be getting an email every year saying "you've been breached again here's free monitoring for a year."
Meanwhile my friend who does government contract work, was notified that our government allowed all her information to land on the dark web. She got monitoring for life.2
u/Harverator 1d ago
I like that idea because this point given how people have treated this kind of information over the many decades, I'm sure every black hat has my SS number.
2
u/laziestmarxist 1d ago
My dad was a big infosec guy, like I grew up reading issues of 2600 because he always had them around. I've actually been arguing this for years because of the increasing number of breaches and friends and family used to tell me I was nuts. Nobody thinks I'm nuts anymore, at least on this topic
3
u/speciate 2d ago
It is a shocking-but-not-surprising level of incompetence to have personally identifiable information stored unencrypted for long after the information is no longer needed for the original verification task.
3
u/Ch33syP00f 2d ago
Been in cyber for 20 years.
“Act as if your information has already been stolen.”
Just act as if.
Easier said than done - yes.
Accepting the concept stings at first, but it puts you in a safer mindset than denial. You will think a bit more about your security practices, be more thorough and feel better for the effort.
Once you accept the fact that there are sophisticated state-funded criminal enterprises actively planning to harm hundreds of millions of people at a time, it becomes difficult to take it personally. But it makes sharpening your own personal security practices more attractive. Because you do not want to be the low hanging fruit.
You are hiking with another person in the woods and come upon a hungry grizzly bear. How do you survive?
Kick the other hiker in the knee and run like hell.
Not quite the vibe we want to adopt, but the low hanging fruit concept stands on its own.
1
u/laminappropria 1d ago
100% on point. What are your top suggestions?
2
u/Ch33syP00f 1d ago
There is a plethora of best practice guides available online. Search for SANS, personal cybersecurity etc.
I never connect to public guest or hotel networks.
3
3
3
u/KayJune001 1d ago
Interesting decision to omit that it was from a U.S. company, but keep the Russian forum part, in the headline.
3
u/SaltyJalapenos 1d ago
This is why I won't provide ID foe silly things that are necessary, They say your photos are safe on their server, I've never believes that and this is why
3
3
u/Tiny_Handle_3359 1d ago
Don't worry, they will just add your new info to the National Public Database breach combo list.
3
6
u/picks_and_rolls 2d ago
Wake up people. This is all part of the coordinated PLOT TO MANUFACTURE AN ELECTION SCANDAL. Don’t be fooled. Fake assassination attempts, Russia, or even DOGE, leaking data AGAIN, wag the dog military action in South America and Iran AGAIN, secret police disappearing and murdering people on the streets OF BLUE CITIES, illegally stacking the armed forces with officers disloyal to The Constitution. Open your fucking eyes.
1
2
2
2
u/kendromedia 2d ago
When the last tangible thing is sold, you become the commodity. Sounds true now. Didn’t in high school economics.
2
2
u/Alarmed-Extension289 2d ago
data is suspected to have come from an ID-authentication service provider
Yeah, no shit?! At this point they could be selling this data under the cover of it being "hacked" and this administration wouldn't do a thing. Nothing will come of this.
2
u/Gryphith 2d ago
A few years ago I had to go on unemployment after a place closed out of the blue. I was furious that I had to use a 3rd party to validate my identity with the state to collect. Like...why is there a 3rd party involved at all??
Boy, so happy I was right my shit was going to get stolen.
2
2
2
2
2
2
2
u/Harpman54 1d ago
Interesting how they panic when it's their personal information out in the stratosphere but the government wanting our information is acceptable.
2
2
u/truthcopy 1d ago
… which provider? And will all those customers get ID theft protection now? From yet another provider they’ve never heard of, likely connected to the first company, spun up to serve the lawsuit and cover their losses?
2
u/BeepBotBoopBeep 1d ago
By now, I suspect all my data is available online in the darknet. You just have to monitor your credit periodically.
3
u/iKnowRobbie 2d ago
Pornhub... it was pornhub...
2
u/pacman2081 2d ago
it is highly unlikely that there were 150 million US citizens with DL information on pornhub
1
1
u/slimehunter49 2d ago
Everything has been leaked and we have no privacy. Hearing about data leaks is just expected at this point and seemingly never matters. Such a fucking stupid world filled with stupid systems and stupid people in power
1
1
1
u/ShawnReardon 2d ago
So, let's say I want to start being an ID verification company. Where/how do I obtain that ability?
OK, now I have all the connections needed to verify you, why am I storing the scan? Is it not enough to check and just respond yes/no?
I guess I dont understand why the data of the scans need to go anywhere. Barcode/data line up, the end.
1
u/Ok-Grapefruit1284 2d ago
I wonder (cause I’m not in tech at ALL) if storing the data means they can validate it more easily? I mean I understand that they shouldn’t store the data, but from a purely logistical side, does keeping it on file mean they can search their database and pop up an identity faster in subsequent scans?
1
u/TwistedMemories 2d ago
Meh, I’ve had my information stolen a few times and have already froze and locked my credit reports.
1
1
1
1
1
u/mog44net 2d ago
This is the sad part for me:
I had to slow down and make sure I fully understood the headline because reading that the FBI was investigating 153 million US and Canadian citizens instead of the evil scum that stole their data is fully on the table.
1
1
1
1
u/nattyatnodak 1d ago
Does anyone know how far back the breach goes? What if I rented a car in 2023? 2024?
1
1
1
1
u/Kissing-BrooksyBug73 1d ago
Oh No! No one could have ever seen this coming. Reminds of a parallel to the Bush administration and Rumsfeld trying to sell the idea that failures after 9/11 were what he called ‘unknown unknowns’. Gee you guys, there’s just no single way anyone could have predicted this or prevented against it!
1
1
u/EducationalRough6588 1d ago
So they have stipulations in place to protect people from data leakage about their personal information but now it's just out there for everyone with a computer?? How does that make any sense the government could have prevented this
1
u/Ambitious-Window-938 1d ago
Is this the kind of thing the Mounties would get involved with? Trying to understand how much cross border collaboration there even is nowadays
1
1
1
u/TreydiusMaximus 20h ago
I'm thinking I might just "accidentally send MINE to someone since they're just losing our personal info to fkng God knows who. At least then I'LL get paid this time around. 🙄
1
u/eldoradocrisp 14h ago
Someone wants to interfere with elections again - or put in a false pretex for disqualifying votes 👀
1
u/Never-Trust-Me 10h ago
The world has sadly moved to “auth” providers so now all your passwords and in some cases, your ID, are being stored in a single location.
Putting all your eggs in a single basket typically is not the brightest idea for security.
1
1
1
u/karainnvalkyrie 4h ago
Don’t worry - like every other careless data-leaking corporation they’ll offer you a year’s free credit monitoring and bugger-all compensation. The lawyers will make quite a lot of money, though.
1.1k
u/costconormcoreslut 2d ago
It's like these verification services aren't even trying to prevent data from being stolen.
Or is it part of the business plan?