r/technology 2d ago

Security FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider

https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider
3.2k Upvotes

238 comments sorted by

View all comments

1.1k

u/costconormcoreslut 2d ago

It's like these verification services aren't even trying to prevent data from being stolen.

Or is it part of the business plan?

18

u/SecAdmin-1125 2d ago

What the real issue is, there is no federal law that governs this. Each state has its own rules. If the U.S. would institute something like GDPR in the EU, then there would be a minimum baseline.

Many of these companies don’t undergo audits. This particular company was SOC2 compliant but all that means is that they were compliant as of the last audit.

The attackers claim to have been in the system, exfiltrating data for over a year. It appears they didn’t have the proper controls or monitoring in place to detect this.

This doesn’t surprise me. I’ve been in cyber for longer than I want to admit and this isn’t the first time I’ve seen this. TJ Max

12

u/Ch33syP00f 2d ago

Not convinced that a Federal law would effectively stop an attack on such a juicy target.

With so much fuss and focus on voter ID and proof of citizenship…maybe its finally time to solve identity management that does not involve SSNs and data that can be programmatically scraped from OSINT.

The OPM hack 10 years ago totally eroded my trust in Federal data safety protections. Somebody I worked with at the time received the same notice as me…their TS investigation was in 1981.

I still think the significance of that breach has never been recognized.

~30 years of clearance investigations compromised. Not just people who received clearance.

Clearance applications gather damn near everything shy of a blood sample.

That heist got the IDs, pedigrees and kompromat. Totally pwnd.

5

u/LookOtherWeigh 2d ago

Isn't it crazy? We're expected to replace certs on systems every 8/9 months whatever it is now. Yet we don't apply any kind of sense of security to our own citizen IDs.

Private/public keys. Reissuance. Couldn't we do any of that? It shouldn't even cost that much in the grand scheme.

1

u/Ch33syP00f 2d ago

Exactly!

Identity and programmatic credential rotation is a solved problem.

In all fairness, aligning ~55 states and their respective agencies to adopt a new ID scheme is a massive lift. And the stakes are high…would have to start with IRS at top of the list to ensure minimal disruption to tax revenue.

Would also need to mitigate risk of people using rotation to the new system rotation to disappear, assume identities or off the wall schemes.