15 ms·
FBI Probes Service Selling 153M+ Drivers Licenses
- fishfasell 1mo agoSo an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.
- wahern 1mo agoYour ID and PII was likely already on the black market, the only question is accessibility and price. You can't exactly advertise on Reddit or sell to every two-bit identity thief and not expect heat.
- 3eb7988a1663 1mo ago153 million puts them at roughly 1/2 of all Americans. Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
- mulmen 1mo agoI had two active Clear subscriptions at the same time. How did an identity verification company not know both accounts were the same person? They were both using the same credit card! What does an "identity verification" company even do?
- toast0 1mo agoClear takes your money and zips you through the airport checkpoint line. Because terrorists wouldn't spend money or time to get through the lines faster?
- deleted 1mo ago[deleted]
- deleted 1mo ago[deleted]
- deleted 1mo ago[deleted]
- mejthemage 1mo agoYou cut the line but still go through security.
- megagpt5 1mo ago> What does an "identity verification" company even do? Handles the multitude of ID document standards around the world while providing a simple Boolean flag to websites that are required to check if you're an adult.
- deleted 1mo ago[deleted]
- mulmen 1mo agoThen inexplicably keeps the data and gets hacked in the most obvious way possible.
- ornornor 1mo agoI once tried to reach one of the two Canadian background check companies a prospective employer wanted to use to check me. I eventually found their privacy and security phone number. It had a poorly recorded voicemail to leave a message and they’d call back to answer questions. It’s been 12 years. They haven’t called me back yet but I’m assured they take privacy very seriously. I didn’t go through with that part of my application and didn’t keep the job.
- oogali 1mo agoTotal population (341M) is the wrong divisor. It’s so much worse. Count the number of Americans who would have an ID worth scanning (aka ages 18 or over): 269M [1]. Or the number of Americans with a driver’s license: 212M (2013) [2]. 1: https://www2.census.gov/programs-surveys/popest/tables/2020-2025/state/detail/SCPRC-EST2025-18+POP.xlsx https://www2.census.gov/programs-surveys/popest/tables/2020-... 2: https://www.bts.gov/content/licensed-drivers https://www.bts.gov/content/licensed-drivers
- 3eb7988a1663 1mo agoExcellent catch. Somehow even worse than I first thought.
- 3RTB297 1mo agoFrom the article, it's some national-chain hotels, car rentals, casinos, dispensaries, and a couple maybes like if you bought alcohol at Target and they scanned your ID or sent something via FedEx that required an ID scan. Your ID might be scanned and in there multiple times.
- Scaled 1mo ago[dead]
- jakevoytko 1mo agoAs always, friendly reminder to lock your credit and enable your mobile carrier's protections against SIM swapping
- fishfasell 1mo agoExcellent advice. A compromised phone number is an absolute nightmare, most MFAs default to SMS as a last resort. I lost my Okta verify login at work since I transferred phones, thought I'd need a ticket with our ID team but turns out my phone number is sufficient. Wasn't thrilled about that.
- cute_boi 1mo agoI don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.
- zdragnar 1mo agoYou've already answered your own question. They don't provide an API with zero trust. Many services are legally required to collect the information anyway. Telehealth billing through insurance, for example, require it for the old "red flag rule" intended to prevent insurance and Medicaid fraud. So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.
- stephbook 1mo agoIn Germany, everyone's national ID – which everyone has – has a NFC chip to securely identify you digitally. It was introduced 15 years ago and can be read by any smartphone. (It does use trusted third parties which only share the requested data though.) You'd think that 80 million people from a rich first world country would be enough of a market to use this. No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.
- lifestyleguru 1mo agoYou want to have it done cheaply on a dumb computer, so you have it.
- Tangurena2 1mo agoOur lobbyists have more money than your lobbyists.
- charcircuit 1mo agoBecause physical business are also allowed to collect this information.
- FpUser 1mo agoSo they want to see my driver's license "to make the world safer" when in reality all they do is facilitating mass fraud. When the fuck will those brainless infusoria will get punished 9fat chance).
- Nition 1mo agoThe thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.
- samlinnfer 1mo agoThe whole point is they keep it forever. You think any id verification services actually delete the data?
- Nition 1mo agoI mean, just because all your friends are jumping off a cliff...
- kevin_thibedeau 1mo agoIf you and your friends are all sociopaths, you're going to feel left out if you don't join in on the cliff jumping.
- mindslight 1mo agoIt feels like we need to tweak the analogy for the surveillance industry. Something more like if all of your friends are pushing people off a cliff...
- maccam912 1mo agoIt's not clear that this came from a point in time dump, but like it has been getting harvested by someone for awhile. They may be deleting it, but by then a copy is made? Speculation after reading the article but that's what it sounded like to me.
- Nition 1mo agoGood point, "we have been continuously exfiltrating new data for over a year into our private database". I missed that line on first read.
- tgrowazay 1mo ago> Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”
- deleted 1mo ago[deleted]
- ungreased0675 1mo agoBankrupt this company to serve as a warning to others that hang on to way too much data.
- walrus01 1mo agoIn addition, actual federal prison time for the C-levels would help as a deterrent to future fuckery.
- bilbo0s 1mo agoThis is the actual answer. Things like this need to be a criminal offense. Monetary fines have a tendency to simply be modeled in as a cost of doing business. Going to prison is far more effective when the goal is to concentrate minds.
- b3lvedere 1mo agoAt least reimburse everybody for all the costs involving getting the old drivers license invalidated and apply for a new one. Unfortunately that will not cause to magically dissapear the rest of your harvested profile.
- Tangurena2 1mo agoYou can change your credit card number. You cannot change your face. And because REAL ID requires mailing your DL/ID to you (in order to prove you live at that address), the address will not change (most states require you to get a new DL/ID within 30 days of moving - my state is 15 days). Replacing the driving license will not change any of the data. Only the DL/ID number. For other identity theft, the old data will not change.
- trollbridge 1mo agoOne of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera. They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
- latchkey 1mo agos/retained/leaked/
- trollbridge 1mo agoWell, yeah. Retention eventually means leaking. I deliberately throw away logs, customer data, etc once it ages last a certain amount simply so I can stop being responsible for it.
- Aurornis 1mo agoThe ID scans in the article weren't submitted by people from their phones. They include IR and UV scans, too. The database might contain multiple sources but at least the big one appears to have a lot of IDs from physical locations where you hand your ID over the counter to someone to scan.
- klausa 1mo agoI'm now very curious how does a UV/IR scan of an ID card looks like!
- kotaKat 1mo agohttps://www.microptik.eu/product/id-card-verification https://www.microptik.eu/product/id-card-verification Basically swaps the LED illum with an UV LED instead. Makes all the security features pop right out.
- 1mo ago
- htrp 1mo agoIt was probably Hertz that was the source of the breaches.
- tgsovlerkhgsel 1mo agoHertz or the company Hertz uses
- rio517 1mo agoI am so jaded, i cannot help jumping to the conlusion that to me they wanted to data to continue voter supression efforts.
- GolfPopper 1mo agoNah. It they want to make sure that Trump gets his cut from the sale.
- tgsovlerkhgsel 1mo agoIf there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold. Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.
- tencentshill 1mo agoMake Customer Data a Liability
- MaKey 1mo agoI'm in Europe and got ~$350 because of three data leaks. The amount per instance was vastly different though - $255, $80 and $15.
- consp 1mo agoI'd be very interested in which ones, since I've never received anything despite being in several big breaches (and have received the boatload of spam to prove it). I'm pretty sure this is very country specific.
- MaKey 1mo agoI can't say which ones as it is one condition of the settlement agreements not to talk about specifics and I gave numbers already. You don't get compensations automatically. I pursued them with the help of a specialized law firm that takes a cut of the settlements.
- cbolton 1mo agoWhat did you do to get the money?
- 1mo ago
- ChrisMarshallNY 1mo ago> vendors who collect this sensitive data need to be held to a higher standard. They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news). One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses. The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.
- thesmtsolver2 1mo agoAhem Some Interrail travellers told to cancel passports as hacked data posted online https://www.theguardian.com/technology/2026/apr/23/some-interrail-travellers-told-to-cancel-passports-as-hacked-data-posted-online https://www.theguardian.com/technology/2026/apr/23/some-inte...
- ChrisMarshallNY 1mo agoTrue, and there’s the notorious story of the Finnish psych data leak[0]. I just don’t hear about it anywhere near as much. [0] https://en.wikipedia.org/wiki/Vastaamo_data_breach https://en.wikipedia.org/wiki/Vastaamo_data_breach
- michaelt 1mo ago> They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there Often it's straight up the same companies - a Brit's PII is held by Experian, Equifax and Transunion just like an American's is. And while the rules are strict and complicated enough to be very inconvenient for anyone who tries to follow them to the letter, the fines for even the worst fuck-ups are trivial. We're talking a $5 billion company handing 15 million people's credit reports to hackers, and getting fined $15 million.
- Razengan 1mo agoHow about probing the laws (and politicians who pushed for them) about making IDs mandatory for using the internet?
- veunes 1mo ago[dead]
- guelo 1mo agoNow I feel justified that I started boycotting my neighborhood bar when they started scanning IDs at the door with some unknown app.
- megagpt5 1mo agoThose apps are internet ID checks brought to the real world. You're right to be suspicious. They do keep leaking data or getting found out to be storing everything forever or forming profiles of a person's movements.
- grommet_kit 1mo agoIt's always the driver's license data that seems to find its way out. Another reminder to freeze your credit.
- trivet 1mo agoWild how many states seem to have had their DMV systems compromised. Guess mine's in the mix by now too.
- rswail 1mo agoThe main question to government is: 1. You already know who everyone is. By definition identification as an individual is by government. 2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)? 3. Why is that evidence not provided directly, but as a confirmation from the government service ("Yes, this person is over 18", not "Yes, this person is 37")? Governments need to protect the public, not allow businesses open slather on collecting PII.
- Hobadee 1mo agoWe can't do any of that because it is forward-thinking and doesn't involve clear-cutting a rainforest to make the stacks of paperwork that are otherwise required to fill out forms in triplicate, run everything through 17 different departments, and ensure an army of bereaucrats have something to do with their day.
- vincnetas 1mo agoThis is exactly the way its being implemented in EU (Yes, this person is over 18"). European Digital Identity Wallet (EUDI Wallet) framework established under the eIDAS 2.0 regulation (Regulation (EU) 2024/1183)
- acchow 1mo agoThis is already present today in California Driver's licenses in your Apple Wallet (mDL). When you scan your driver's license at a compatible reader, you're given a notice of what information is being requested and the ability to share it (or not). It can also request some derived attribute (is this person above the age of 21?) instead of the actual data field itself. Most of this is from ISO/IEC 18013-5
- 2legit2quit 1mo ago> Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)? Generally speaking, it's the narrative of a pushback on a "national id". Many countries already have this place. Estonia has the Digital ID provided by government[0]. Nordic countries use BankID, which is a form of KYC that is backed by banks (you prove your identity to the bank, the bank issues a bank id - usually back by certificate[s], and you login with this to services[1][2]). Finland is the outlier, here, with their own service[3]. 0 - https://e-estonia.com/service/estonian-e-identity/id-card/ https://e-estonia.com/service/estonian-e-identity/id-card/ 1 - https://www.bankid.com/en/individuals/get-bankid https://www.bankid.com/en/individuals/get-bankid 2 - https://bankid.no/en/how-to-get-bankid https://bankid.no/en/how-to-get-bankid 3 - https://www.suomi.fi/instructions-and-support/identification/what-is-suomifi-e-identification https://www.suomi.fi/instructions-and-support/identification...
- wolvoleo 1mo agoOoh I thought they sold that many fake ones lol. I know fake IDs are a big thing in the US because of the really high drinking age (were I'm from it was 16). But even then it's a lot. But no it's about leaked data. That wasn't very clear from the title.
- VladVladikoff 1mo agoStartup idea for these darknet guys, use AI to select the best matching face in your collection of IDs to your customers face, so you can generate them a fairly realistic fake ID.
- ethagnawl 1mo agoI know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID. Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which gets cross-referenced by the legit provider against the id.gov database. Of course the devil is in the details and I wouldn't trust GrandePelotas and friends to vibe code such a system but it is absolutely possible and is something we should, at the very least, be thinking about.
- ericmay 1mo agoWhich “normal, modern countries” have done variations of this?
- ShowalkKama 1mo agoItaly doesn't have crypto keys (as the average person would just lose/leak them) but they offer SSO login with the ID card. Basically whenever you need to verify your identity you pick "sign in with CIEid", you get redirected to a goverment website where you can authenticate (typically by scanning a qr code + scanning your physical id card on your phone) and then you approve/deny the authentication request (you can also clearly see which data is shared (name, last name, dob, etc)). it's stupid easy to setup, the app is not overly bloated and it has different options to authenticate.
- Levitating 1mo agoEuropean passports are NFC tags and you can prove your identity using your phone.
- ericmay 1mo agoI think American passports have those as well because I remember all the hax0rs making videos showing where to smash the NFC chip with a hammer or to buy wallets with special NFC blocking properties to keep folks from “stealing their identity” from the NFC chip. Personally I never cared but your comment jogged a memory. Recently I added my passport to my Apple wallet but I’m not sure if that’s used anywhere.
- shireboy 1mo agoWhat even would be the fix for this? 153m people need new license asap and id verification systems need to block the stolen ones? Also what are some of the bad things this could cause: a risk malicious actors open verified accounts in their name, ability to vote and travel under stolen id, what else?
- SpaceL10n 1mo ago[dead]
- duxup 1mo agoI’ve had more than one client tell me they want to collect drivers license images for various reasons. Somewhere in the inane executive brain world there are some folks who seem to see some unspecified value in collecting driver’s license images. They never have given me a sensible justification. They seemed to think it provided some assurance that the providing it is in fact who they really are and they can validate…. something. I’ve managed to push back on that and told them I didn’t want the legal responsibility of managing such data and tracking all the legal responsibilities for any number of countries and ect. It doesn’t surprise me that there is a ready made service to bypass this kind of absurd requirement.
- morkalork 1mo agoStupid side comment but lmao the website looks like it was designed in 2002 rock on you crazy diamonds!
- ChrisMarshallNY 1mo agoIt’s interesting how quickly this story dropped in the rankings. It’s a highly relevant story, that is likely to spawn more notice. Ars already has a story about the same breach: https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/ https://arstechnica.com/security/2026/09/my-drivers-license-... Is this story being flagged? If so, why?