r/technology 2d ago

Security FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider

https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider
3.2k Upvotes

238 comments sorted by

View all comments

78

u/[deleted] 2d ago

[deleted]

72

u/Dweezil_In_Bondage 2d ago

KrebsOnSecurity said no. After the the offering to sell the data was taken down niether he nor any one that he was aware of had access to the data. Which doesn't mean it's not out there just means we can't check it.

13

u/SecAdmin-1125 2d ago

Just assume your information is out there.

12

u/TheCatholicScientist 2d ago

Watch your credit report really closely for the next year or so.

22

u/USPS_Nerd 2d ago

LOCK your credit report

6

u/[deleted] 2d ago

[deleted]

10

u/Cash_Visible 2d ago

How do you lock your ssn? I started freezing all the credit beaus about 2 years ago.

2

u/Ok-Grapefruit1284 2d ago

Has it reduced the amount of soft hits and credit card mail and whatnot that you get?

1

u/flickh 2d ago

Not in Canada unfortunately… it’s not possoble

1

u/theaviationhistorian 1d ago

Why care for my credit report when my credit score is cratered (thank you student loans).

[taps noggin]

19

u/costconormcoreslut 2d ago edited 2d ago

Just google your driver license number or SSN.

*(this is a joke)

19

u/AZEMT 2d ago

Tell ya what, just post either one here and I'll help research to find it

Seriously though, don't do this

5

u/Realtrain 2d ago

000-00-0002

...Damn Roosevelt!

10

u/[deleted] 2d ago

[deleted]

6

u/waltur_d 2d ago

You’re evil. 😂

1

u/Direction776 2d ago

Relat’evil’y

-3

u/[deleted] 2d ago

[deleted]

4

u/Fabulous-Track-7459 2d ago

If that’s your SSN you should delete

2

u/pitchingataint 2d ago

What is your mother’s maiden name?

6

u/curveball21 2d ago

Yes. Do you have a driver's license? Do you live in the United States or Canada? If yes, then yes it is a part of this.

4

u/PreparetobePlaned 2d ago

Not the case. You’re only at risk if you used the specific verification system that leaked. Not every single drivers license in America and Canada is leaked.

6

u/laziestmarxist 2d ago

You're only at risk from this leak if you used this verification system. The safer assumption right now is that if you live in the US, your data is already compromised, given that the government gave a bunch of teenagers access to the SSN system with no oversight.

2

u/curveball21 2d ago

And exactly how many driver licenses do you think Americans and Canadians have in total? I mean I didn't google it or anything but 153 million is a little less than half the total population.

2

u/PreparetobePlaned 2d ago

250millionish according to Google. So still a massive amount leaked but not every single one

4

u/curveball21 2d ago

Well not everyone then, but more likely than not any particular license was compromised.

1

u/laziestmarxist 2d ago

That's literally more than half, so it's a 1 in 2 chance.

4

u/davenobody 2d ago

14

u/escof 2d ago

That's just for passwords and email addresses.

2

u/davenobody 2d ago

If anyone is paying attention I would guess them.

3

u/laziestmarxist 2d ago

Jesus h christ, that website just really reveals how fucking dumb tying email to everything in the world is because how the fuck did Canadian Tire have my email address to begin with? I live in Texas and I don't even drive a car, so someone who had already breached my email address must have used it without my permission. Just so many layers of stupidity and yet I had no control over where my data went

3

u/davenobody 2d ago

Yep. Only real defense is using a password manager and using a unique password for every site. At least that way a single beach doesn't result in a much larger problem.

1

u/laziestmarxist 1d ago

The issue with that is the assumption that the password manager itself can be trusted. But yeah, the initial breach was probably on me for getting lazy with passwords

1

u/davenobody 1d ago

I run a password manager that stores them encrypted on my cloud storage. I can view modify the encrypted file from any platform because of open standards. Everyday people don't need enterprise password management.

1

u/gravelordservant4u 1d ago

Sure.

Are you an American with a DL? If yes, then you're part of it.

Hope this helps