skip to content

🤦‍♂️ Driver’s License Dump Lays Bare Hazards of Data Hoarding

Regulation-1 Gray-1

This article originally appeared in Galaxy Research's weekly newsletter. Subscribe to get timely insights delivered to your inbox every Friday morning.

More than 153 million American and Canadian driver’s licenses were exposed in an apparent data breach of a widely used identity verification service, cybersecurity researcher Brian Krebs reported Tuesday.

Krebs learned about the incident because his license was compromised. A dark web vendor known as Nexus was offering it as a free sample of the 170 million stolen records it was selling on a Russian forum. Aside from scans of licenses (including U.S. Secretary of War Pete Hegseth’s), the trove included identification cards, medical cards, and travel documents.

The FBI (whose assistant director’s license was also exposed) has opened an investigation, Krebs and Reuters reported. Shortly after Krebs posted his article, Nexus' website disappeared.

Another victim was Krebs' mother. Both had shared their licenses with the Hertz car rental service, as did three other people whose data was compromised. Yet another scanned his license at a marijuana dispensary that had something in common with Hertz: IDScan.net, the verification service, listed both as clients.

IDScan told Krebs it was investigating the matter. As of writing, the company had not issued a detailed statement.

A third IDScan client, bank technology vendor Jack Henry & Associates, disclosed a cybersecurity incident Monday. “Based on our investigation to date, personally identifiable information (PII) data for fewer than 10 clients was impacted,” Jack Henry said. (Its clients are banks, not their customers.)

That incident, which involved voice phising and an extortion attempt, may be unrelated to the one Krebs reported. A Jack Henry spokesman told Galaxy Research: “While we use one IDScan.net product in our OpenAnywhere digital deposit account opening platform as an optional feature, we have been notified by IDScan.net that this specific product is not impacted. We are actively monitoring the situation and keeping our clients informed.”

Other IDScan clients include the U.S. Coast Guard, FedEx, Motorola Solutions, and Caesars Entertainment, according to a screengrab in Krebs' report.

The IDScan breach would rank among the top 20 in U.S. history by number of records leaked, according to data from cyber risk management firm UpGuard. It’s on par with the 2017 Equifax incident, which exposed sensitive data of 147 million U.S. and 15 million U.K. consumers.

Our take

This debacle underscores a message that cryptocurrency and cybersecurity community members have been shouting from the rooftops for years: data is a liability.

In a comment letter to the U.S. Treasury last year, we explained:

U.S. citizens are required to share copious amounts of personally identifiable information (PII) with strangers on a daily basis, simply to get by. Even to purchase cold medicine at the drugstore, Americans have to scan their driver’s licenses. Each time a consumer entrusts PII to a business, they widen the attack surface for would-be identity thieves. ... Promiscuous data collection turns businesses into “honeypots,” irresistible targets for hackers.

Many businesses need to learn something about their customers. A car rental service needs to know you are fit to drive. A dispensary or casino needs to know you’re of legal age. Financial institutions, famously, are required by law to “know your customer” (KYC).

Personally identifiable information should be handled with care, if at all.

PII should be handled with care, if at all. Businesses should collect only the data they absolutely need to operate and dispose of it as soon as they legally can. While that’s standard practice, many organizations cut corners.

Whenever data is retained, access should be locked down tight. Last year, Coinbase disclosed that nearly 70,000 of its customers’ sensitive details were leaked. Criminals obtained this information by bribing contractors and employees outside the U.S. with access to Coinbase’s systems, the company said.

Long term, we remain optimistic about zero-knowledge proofs’ potential to reduce data hoarding. “ZKP makes it possible for people to prove that something about them is true without exchanging any other data,” explained Alan Stapelberg, group product manager for Google Wallet, in a blog last year. “For example, a person visiting a website can verifiably prove he or she is over 18, without sharing anything else at all” – a feature Google added to its digital wallet.

Historically, ZKPs were slow and expensive to run, but they’re constantly improving. For example, the average cost of proving on the Ethereum blockchain steadily declined over the last 90 days, and latency generally held below a 10-second target:

ethproofs image
Source: Ethproofs.org

Still, adoption is slow. Several apps (Zkpassport, Zpass, Rarimo) can scan a passport and spit out a proof attesting to an attribute (“at least 21 years old”; “not a North Korean national”) without doxxing the user. They face a chicken-and-egg problem: consumers have little incentive to download apps few businesses accept, and businesses have little incentive to accept forms of identification few consumers carry.

The hacker asked only $100 for War Secretary Pete Hegseth’s drivers license.

It's easy to despair. The Nexus hacker asked only $100 for Hegseth’s ID, suggesting stolen PII is so abundant it sells dirt cheap. But the worst thing to do would be to downplay this breach because “it's already out there.” Attackers can cause orders of magnitude more damage than the data costs.

We agree with Peter van Valkenburgh, executive director of crypto advocacy group Coin Center, who wrote in response to the driver’s license breach: “You should be mad. We are long, long, long overdue to reduce the amount of KYC we do as a society.” Don’t be complacent; demand better alternatives and support the developers building them. – Marc Hochstein

You are leaving Galaxy.com

You are leaving the Galaxy website and being directed to an external third-party website that we think might be of interest to you. Third-party websites are not under the control of Galaxy, and Galaxy is not responsible for the accuracy or completeness of the contents or the proper operation of any linked site. Please note the security and privacy policies on third-party websites differ from Galaxy policies, please read third-party privacy and security policies closely. If you do not wish to continue to the third-party site, click “Cancel”. The inclusion of any linked website does not imply Galaxy’s endorsement or adoption of the statements therein and is only provided for your convenience.