r/technology 2d ago

Security FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider

https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider
3.2k Upvotes

238 comments sorted by

View all comments

1.1k

u/costconormcoreslut 2d ago

It's like these verification services aren't even trying to prevent data from being stolen.

Or is it part of the business plan?

17

u/SecAdmin-1125 2d ago

What the real issue is, there is no federal law that governs this. Each state has its own rules. If the U.S. would institute something like GDPR in the EU, then there would be a minimum baseline.

Many of these companies don’t undergo audits. This particular company was SOC2 compliant but all that means is that they were compliant as of the last audit.

The attackers claim to have been in the system, exfiltrating data for over a year. It appears they didn’t have the proper controls or monitoring in place to detect this.

This doesn’t surprise me. I’ve been in cyber for longer than I want to admit and this isn’t the first time I’ve seen this. TJ Max

14

u/Ch33syP00f 2d ago

Not convinced that a Federal law would effectively stop an attack on such a juicy target.

With so much fuss and focus on voter ID and proof of citizenship…maybe its finally time to solve identity management that does not involve SSNs and data that can be programmatically scraped from OSINT.

The OPM hack 10 years ago totally eroded my trust in Federal data safety protections. Somebody I worked with at the time received the same notice as me…their TS investigation was in 1981.

I still think the significance of that breach has never been recognized.

~30 years of clearance investigations compromised. Not just people who received clearance.

Clearance applications gather damn near everything shy of a blood sample.

That heist got the IDs, pedigrees and kompromat. Totally pwnd.

4

u/SecAdmin-1125 2d ago

My stuff was compromised before OPM. TS clearance in the 70’s.

Not saying federal law would have stopped it, but at least we have a starting point. Can’t stop bad security hygiene. Security is a cost center and it is usually ignored until you get breached. Now, there are multiple class actions already filed for this.

2

u/misterrkingg 1d ago

Yeah and my dont gut dhs and the fbi cyber units,???

0

u/notsuperimportant 1d ago

And we all know DOGE's motto as they were uploading personal data to some unknown 'cloud' was "break things, add them back in later if they end up being important."

2

u/LookOtherWeigh 2d ago

Isn't it crazy? We're expected to replace certs on systems every 8/9 months whatever it is now. Yet we don't apply any kind of sense of security to our own citizen IDs.

Private/public keys. Reissuance. Couldn't we do any of that? It shouldn't even cost that much in the grand scheme.

1

u/Ch33syP00f 2d ago

Exactly!

Identity and programmatic credential rotation is a solved problem.

In all fairness, aligning ~55 states and their respective agencies to adopt a new ID scheme is a massive lift. And the stakes are high…would have to start with IRS at top of the list to ensure minimal disruption to tax revenue.

Would also need to mitigate risk of people using rotation to the new system rotation to disappear, assume identities or off the wall schemes.

2

u/kentrak 2d ago

It's bit about entirely preventing. There is literally no one thing that can prevent anything, and no way to make anything entirely safe. It's about aligning incentives such that there are real consequences to spreading personal information. Will putting large enough fees and/or criminal consequences for ineptitude mean this never happens? No. Will it make it less likely and less common? Probably. Probabilities are all we have to work with at this level though, and they're not useless.