Hackers Had a Live Feed of Every ID Verification Company Scanned for over a Year
Points and comments are a snapshot, not live.
A breach leaked 153 million driver's license scans from ID verification firm IDScan.net over a year.
Hackers had a live feed of every ID scanned by IDScan.net, a major identity verification company used by Hertz, FedEx, Target, and dispensaries. Over 153 million driver's licenses from the US and Canada were sold on the dark web via a service called Nexus, which added 400,000 records in 24 hours. The breach included the Secretary of Defense's license. The author argues that this proves age verification systems are inherently unsafe, as any centralized data becomes a target despite security claims.
The article highlights that IDScan.net promoted its security certifications while leaking data in real-time for over a year without detection.
What commenters are saying
The thread's top comment recommends Brian Krebs' original article as a better read. Several commenters use sarcasm to mock age verification advocates, noting the breach exposes people to identity theft and dangers like stalking. A camp argues the government should handle verification via zero-knowledge proofs rather than third parties, citing the EU's approach. Others point out government systems also leak data, using examples like state DMVs selling driver data to third parties. One commenter notes that REAL ID requirements discriminate against the unhoused by requiring a physical address, while another criticizes the HN title as a garden-path sentence.