You Never Chose the Company That Just Leaked Your Face
brian krebs just broke a story that should make a lot of people angry. more than 153 million driver's-license records are allegedly for sale on the dark web right now, and the price is a mere US$100. if you have handed your id to a business using one of these verification systems in the last few years, there is at least a chance your face and your license number are sitting in that database. and here is the part that should make you angry. you never chose the company that lost it. you probably do not even know its name.
let me lay out what happened, then why it matters more than a normal "run of the mill" breach.
a dark web service called nexus launched this week on a russian ecrime forum, claiming searchable access to more than 153 million us and canadian driver's-license records. it also claims over 10 million other id cards, more than 3 million passports and travel documents, and over 579,000 medical cards.
krebs traced the apparent source to idscan, a louisiana company that verifies identity documents. idscan has not confirmed a breach, and the fbi has opened an investigation. this is just speculation at this point. but the data is real. krebs found his own license in the leak. so did the researcher he worked with.
now the numbers that tell you the scale of this kind of vendor. idscan processes more than 21 million verifications every month. it operates across more than 20,000 locations. its clients include hertz, target, fedex, caesars, and motorola. this is not some fly-by-night operation. it is invisible plumbing sitting behind thousands of businesses you do interact with, quietly retaining a copy of the id you showed.
here is the detail that should chill you. the timestamps on the leaked licenses line up with real moments people handed over their id. a trip. a hotel check-in. a rental. nexus claimed the siphoning was ongoing, and the inventory appeared to be growing close to real time, with about 400,000 licenses added in a single day. among the exposed ids was defense secretary pete hegseth. if his got scraped, yours has no special protection.
other than the obvious breach of personally identifiable information, what is the actual problem at play here?
the modern identity economy runs on a broken premise. to prove who you are, you have to hand a permanent copy of your most sensitive document to a third party. not the bar. not the rental company. a vendor behind them you never picked, cannot audit, and likely cannot even name. you did not overtly agree to idscan. you showed your id to a cashier, and a company you never heard of kept it. you probably never considered this when handing over your id.
and that is the core lie in the phrase "secure identity provider." there is no permanently secure centralized identity repository. every centralized store of identity documents is a target, and the entire history of this industry says the same thing. it is not a matter of if they get breached. it is when. you are not trusting the business in front of you. you are trusting an invisible chain of vendors behind it, and that chain is only as strong as its weakest, least-audited link.
now here is why this specific leak matters far beyond the people in it. lawmakers are pushing hard to make exactly this model mandatory. age verification for the internet. prove you are over eighteen to see certain content, use certain apps, open certain accounts. in implementations relying on government-id verification, the mechanism they reach for is the same one that just failed. scan your government id, hand it to a third-party verifier, and trust the verifier to keep it safe. right.
think about what that means at scale. right now, id scanning happens at bars and rental counters. some of the proposals and systems now being pushed would extend this model toward the front door of the internet. more sites, more apps, more services, funneling government ids through verification vendors.
we just watched one of those vendors allegedly leak 153 million driver's-license records. now imagine that model as a legal requirement for basic online life. you would be multiplying the number of permanent identity honeypots by orders of magnitude, and handing each one the exact data that is currently for sale on nexus for a hundred bucks.
that is the slippery slope. this is not some hypothetical. the technology being sold as safety is a surveillance and breach machine waiting for its turn. the same architecture that lost these licenses is the architecture some want to require before you can go online.
here is what makes this worse than a credit card breach. you can cancel a card. you can change a password. you cannot meaningfully rotate your face or date of birth, and replacing a driver's-license number is nothing like cancelling a credit card. much of the data in the nexus database remains useful for years, and some attributes, like your face and date of birth, are effectively permanent. this is not a breach you recover from. it is a breach you carry forever.
so where does this land? the leak is bad. the model producing it is worse. and the plan to make that model mandatory is the most dangerous part of the whole story.
we keep being told that centralizing our identity is how we stay safe. wrong. it is the opposite.
every copy of our sensitive documents is a liability. every verifier is a target. every mandate to scan more ids is a bigger bounty sitting on a server, waiting for the day it inevitably spills. today happened to be one of those days.
the government and these vendors are not protecting your identity. they are accumulating it, and calling the hoard security.