Hackers Had a Live Feed of Every ID This Verification Company Scanned for Over a Year

Hackers Had a Live Feed of Every ID Verification Company Scanned for over a Year

Hackers Had a Live Feed of Every ID This Verification Company Scanned for Over a Year

A dark web service is selling scans of over 153 million driver's licenses from the US and Canada, sourced from a breach at IDScan.net, a Louisiana-based identity verification company used by Hertz, FedEx, Target, and thousands of dispensaries. The breach went undetected for over a year, with hackers continuously exfiltrating new data in real time, even adding 400,000 records in 24 hours. The exposed data includes the driver's license of the Secretary of Defense, highlighting the severe privacy risks of mandatory age and identity verification.

We have been continuously exfiltrating new data for over a year into our private database.
  1. xvilka

    The original idea for the ID verification was broken by design anyway. The only safe and secure way is a chain/tree of trust, e.g. with PKI, where you could generate some certificate just for that particular service, while keeping your root key safe. Then, in the case of leak, the most you lose, is one particular key for one particular service that could be immediately revoked. You could even slap zero-knowledge proofs for particular properties (e.g. if the person has a driver license or not) without de-anonymizing the account. In the rare even of root key leak you should be able to physically go to the authority and make a new one, while revoking the old key. I don't see any other better alternatives than this.

  2. piva00

    Brian Krebs' article is, in my opinion, a much better read for this story[0].

    [0] https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...

  3. jonplackett

    We have too many non-technical people in charge of things who just make decisions based on politics and magical thinking about what is possible.

    ‘Just make the encryption secure and so we can read it’

    ‘Just check everyone’s id but make it totally secure’

  4. padjo

    Funny was just testing the pilot of the Irish Government Digital Wallet. Definitely seems like the way forward if we're intent on doing identity verification. I'd rather the government mediate this than a bunch of random 3rd parties.

  5. pelagicAustral

    I wonder if I can buy my own driver license since I lost it and now I need a copy to get some paperwork done! Hackers please!

  6. lrvick

    If you are in California the DMV makes tens of millions of dollars a year selling all the data you give to the DMV, which is why I give them a P.O. Box.

  7. kleiba2

    And again, there will be no monetary consequences for the companies that failed to secure our private data.

  8. mawadev

    How exactly does that work? How can you sneak a live feed past detection systems? It is incomprehensible to me, considering this is highly regulated and sensitive data. It is just open ports sending what they shouldn't be sending all the way out or what?

More from this day

2026-09-04