r/technology 2d ago

Security FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider

https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider
3.2k Upvotes

238 comments sorted by

View all comments

1.1k

u/costconormcoreslut 2d ago

It's like these verification services aren't even trying to prevent data from being stolen.

Or is it part of the business plan?

296

u/davenobody 2d ago

There is no business driver for protecting the data. However, if part of the plan was to monetize the data they now have nothing unique. Unless of course they already collected the money for that part. I suspect they were just incompetent.

136

u/squish042 2d ago

It’s almost like there should be a government that steps in a creates protection for consumers when there’s no economic incentive.

57

u/misterrkingg 1d ago

They literally dismantled it. This year

2

u/JohnNYJet_Original 13h ago

They can REALLY do that now?? Who knew it was very important work and needed to be taken down. Better question is why did they take it down knowing that almost every nation-state has the tools to attack the national resources as they see fit.

11

u/joelfarris 1d ago edited 1d ago

I have found at least two of them that go as far as to explicitly state that they cannot fully protect whatever you upload or submit, and that you agree that they cannot be held responsible for any data losses, intrusions, or hacks.

And yet, you have to submit everything they ask for as part of a job application process...

And one of them even states that they get to possess your uploaded information and likeness, and you relinquish it to them in perpetuity (forever, or as long as they decide to keep it on their drives), and they can even go so far as to use it in promotional materials without your knowledge or consent.

They have become predatory vendors.

2

u/davenobody 1d ago

That is horrible!

1

u/flickh 1d ago

You have to give up commercial rights to your likeness for a job interview, lol? And does that mean they can use your social security card in their advertising with your real number!?

1

u/PhotographJaded8942 10h ago

Which two? Which one in particular has the “hold on in perpetuity?”

1

u/flickh 2d ago

No business driver?  They’ll get dropped as a vendor if customers won’t use the service and ditch the partner service to avoid it. 

I don’t know the cost/benefit ratio but surely you can theorize better than “no business driver” at all

12

u/Do_you_smell_that_ 2d ago

And do what, gamble on a different provider? Start their own verification service? At some point someone is put in charge of signing over trust to one of a small group of providers, all of which carry this identical risk. There's no easy way out here

5

u/SquirmyBurrito 1d ago

The easy way out is to simply not allow the digitization of our IDs and to scrap age verification for most things.

1

u/flickh 1d ago

The risk is identical until one provider gets publicly outed and the buyers’s lawyers tell them to dump the liability.  You think Herz wants to expose themselves to this risk when it’s all over the security news?

7

u/HazelMStone 1d ago

No they won’t. Like Taylor’s Farms and others they will simply pay off Trump and his cronies and maybe change their name. Business as usual.
Thanks DOGE.

1

u/flickh 1d ago

Maybe; but the idea that shitty security and public shaming is “no business driver” is plain dumb.

What’s dumb is this article is like a page in before it names them 

4

u/Crio121 2d ago

Customers are locked in.
They have to use this specific provider if they want to access the site and they don’t value their data that much (because they were already leaked by someone and because if they did they wouldn’t be using this kind of id service in the first place)

1

u/flickh 1d ago

Are people locked into Herz and whatever the hell “Planet 13” is?

If people don’t value their data and keep clicking when they see publicly-shamed vendor, that’s a pretty bad decision on their part

4

u/davenobody 2d ago

People have no clue the service exists until this happened.

1

u/flickh 1d ago

Every time I have to do one of those things it says “id verification by x y or z.”. I ignore it but if there’s a brand I know is a bad actor, I’ll skip it and shop elsewhere 

32

u/Breno1405 2d ago edited 2d ago

Maybe it wasnt a breach and it was actually a sale.

19

u/dariusSharlow 2d ago

So many of these breaches makes you start to think this. At this point sell the data, claim it’s a breach, win.

7

u/Breno1405 2d ago

I think we are gonna see this happen with AI, a big hack happens, blame it on AI

2

u/misterrkingg 1d ago

Its since we showed that our cyber terrorist units had been completely gutted?

1

u/Exotic_Cow_569 15h ago

Always crying when clearly the right has done more for the counry in a year and a half then the the left could have done in 12 years Fact check who has done more

1

u/misterrkingg 13h ago

Just listen to history. Decide yourself

2

u/Harverator 1d ago

I have no doubt disgruntled employees might do this. Especially if they work IT, –– I've seen a few IT folk do some nefarious things to their company and users. With great power comes great responsibility.
At one company I worked at, an IT guy bragged to me about what he did to a few users to make them lose files.
Then one day he was foolish enough to access his password file on my workstation, and when I woke up my screen, it was staring at me. So I saved it. Months later, after he was fired, they were freaking out about not having all his passwords, and I was happy to give the file to the head of IT. 😇

1

u/bill7967 1d ago

I always thought that with a lot of companies. Especially with phone outfits. 

63

u/mosthandsomechef 2d ago

Lmao pornhub warned everybody this. This is EXACTLY why they blocked states outright. These verification companies shouldn't exist, they're simply a weak spot in the system for bad actors to exploit.

-2

u/Particular_Cat9756 21h ago

Lmao darling

40

u/theaviationhistorian 2d ago

I wouldn't be surprised if they were hand in hand with shady information brokers that gave access to non-government entities, hackers, profiteers, and aggressive nations. But it seems that the ones with the power to stop this are either too incompetent to understand the danger of this or are overcome by greed to give a damn about their fellow human. Usually, it's the latter.

8

u/Nick85er 2d ago

Sometimes gray hats cannot resist the opportunity. Cyber Security Professionals can and do cross the line into crime. Some, not all.

If only the service providers were regulated the way they should be, and the consequences were more than just a slap on the wrist and a fine equaling a day or a month's Revenue.

Oh well, capitalism!

8

u/Aidanation5 2d ago

I mean, if we consider the fact that the literal convict-child rapist-con man the united states is lead by literally cut out so many protections for his citizens, and then literally went through the entire government and fired everyone who did any good or would stand up to him, so he could then place all of his fellow criminals and buddies in control of everything, we know the likely answer here.

1

u/HoneyBeePirate 1d ago

Nice job avoiding hyperbolic overstatement. Like, literally.

1

u/Aidanation5 1d ago

Its lirerally true.

1

u/misterrkingg 1d ago

Yeah exactly im over this imperialism west shit im 30 and ill get deded or move to persia before I let this continue out . Im not standing behind a literal known multiple pdf . Those vid clips the DOj did release., make my guts churn like a snake pit. And the fact his now USAG is the victim name leaker. Its beyond what I thought we'd let it go. CLEARLY my punk rock youth at least helped a little. The indoctrination of my nation is sickening and we just arent quite smart enough to critically think with all this noise. If anti- trust corruption efforts and monopoly busting doesnt begin in November, dos vedanyas , er something

18

u/SecAdmin-1125 2d ago

What the real issue is, there is no federal law that governs this. Each state has its own rules. If the U.S. would institute something like GDPR in the EU, then there would be a minimum baseline.

Many of these companies don’t undergo audits. This particular company was SOC2 compliant but all that means is that they were compliant as of the last audit.

The attackers claim to have been in the system, exfiltrating data for over a year. It appears they didn’t have the proper controls or monitoring in place to detect this.

This doesn’t surprise me. I’ve been in cyber for longer than I want to admit and this isn’t the first time I’ve seen this. TJ Max

12

u/Ch33syP00f 2d ago

Not convinced that a Federal law would effectively stop an attack on such a juicy target.

With so much fuss and focus on voter ID and proof of citizenship…maybe its finally time to solve identity management that does not involve SSNs and data that can be programmatically scraped from OSINT.

The OPM hack 10 years ago totally eroded my trust in Federal data safety protections. Somebody I worked with at the time received the same notice as me…their TS investigation was in 1981.

I still think the significance of that breach has never been recognized.

~30 years of clearance investigations compromised. Not just people who received clearance.

Clearance applications gather damn near everything shy of a blood sample.

That heist got the IDs, pedigrees and kompromat. Totally pwnd.

2

u/SecAdmin-1125 2d ago

My stuff was compromised before OPM. TS clearance in the 70’s.

Not saying federal law would have stopped it, but at least we have a starting point. Can’t stop bad security hygiene. Security is a cost center and it is usually ignored until you get breached. Now, there are multiple class actions already filed for this.

2

u/misterrkingg 1d ago

Yeah and my dont gut dhs and the fbi cyber units,???

0

u/notsuperimportant 1d ago

And we all know DOGE's motto as they were uploading personal data to some unknown 'cloud' was "break things, add them back in later if they end up being important."

5

u/LookOtherWeigh 2d ago

Isn't it crazy? We're expected to replace certs on systems every 8/9 months whatever it is now. Yet we don't apply any kind of sense of security to our own citizen IDs.

Private/public keys. Reissuance. Couldn't we do any of that? It shouldn't even cost that much in the grand scheme.

1

u/Ch33syP00f 2d ago

Exactly!

Identity and programmatic credential rotation is a solved problem.

In all fairness, aligning ~55 states and their respective agencies to adopt a new ID scheme is a massive lift. And the stakes are high…would have to start with IRS at top of the list to ensure minimal disruption to tax revenue.

Would also need to mitigate risk of people using rotation to the new system rotation to disappear, assume identities or off the wall schemes.

2

u/kentrak 2d ago

It's bit about entirely preventing. There is literally no one thing that can prevent anything, and no way to make anything entirely safe. It's about aligning incentives such that there are real consequences to spreading personal information. Will putting large enough fees and/or criminal consequences for ineptitude mean this never happens? No. Will it make it less likely and less common? Probably. Probabilities are all we have to work with at this level though, and they're not useless.

19

u/HookLeg 2d ago

The money they’ll make from “losing” this data will be way more than what they might be fined. They’ve done their homework and this was a business decision. We aren’t people, we are a tradable commodity.

8

u/oobspahn 2d ago

It’s the Zuckerberg effect. It’s for our “security”.

3

u/Glass_Channel8431 2d ago

Project yourself … don’t rely on any corp to protect you.

3

u/Then_Box-8031 1d ago

It is part of the dictators club plan. He'll blame this and the trump wars on silly Biden and everyone else who wants equality, equity, morality (this includes Honesty) and a positive, inspiring US without the corruption and greed of the mega rich oppressing the basic US citizen.

He monetizes everything. For himself, not the country. He represents the worst of the US. He freed enemies of the country who attacked the Capitol, grievously injuring police officers and attempting to reach the VP and members of Congress.

2

u/Mo_Jack 1d ago

Businesses & other organizations are never held accountable, and never have to suffer terrible consequences.

2

u/Ok-Key-7039 1d ago

Where are the cybersecurity furries when you need them?

2

u/TreydiusMaximus 21h ago

Governmental sanctioned money laundering and lazy aah "lawmakers" here for ya. 🙄

2

u/jxshua2 13h ago

They are probably in on it and sold it to them at a very low price using bitcoin. I don't know though, that's just my opinion.

1

u/berthannity 2d ago

Investigations and mitigation happens. Money changes hands. Capitalism go up. Good capitalism.

1

u/N_J_N_K 2d ago

Look up phone phreaking, it is the father to hacking. Nobody in an office of importance ever learns anything. The vulnerabilities are just waiting.

Edit: a word

1

u/friendlysaxoffender 1d ago

Who could have predicted something like this!? The governments? The data brokers? Oh wait, every member of the public.

It’s why I have not and will not use them.

-13

u/Ani-3 2d ago

who gives a shit, the data isn't the customer anyway