FBI Probes Service Selling 153M+ Drivers Licenses

tatersolid 123 points 41 comments September 01, 2026
krebsonsecurity.com · View on Hacker News

Discussion Highlights (11 comments)

fishfasell

So an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.

jakevoytko

As always, friendly reminder to lock your credit and enable your mobile carrier's protections against SIM swapping

cute_boi

I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.

FpUser

So they want to see my driver's license "to make the world safer" when in reality all they do is facilitating mass fraud. When the fuck will those brainless infusoria will get punished 9fat chance).

Nition

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

tgrowazay

> Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”

ungreased0675

Bankrupt this company to serve as a warning to others that hang on to way too much data.

trollbridge

One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera. They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.

htrp

It was probably Hertz that was the source of the breaches.

rio517

I am so jaded, i cannot help jumping to the conlusion that to me they wanted to data to continue voter supression efforts.

tgsovlerkhgsel

If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold. Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.

Semantic search powered by Rivestack pgvector
5,215 stories · 47,053 chunks indexed