r/news • u/polymute • 3h ago
Questionable Source [ Removed by moderator ]
https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider[removed] — view removed post
3.0k
u/BloodFartz69 3h ago
Too bad we have a googly eyed coked out podcaster running the FBI.
698
u/Wyden_long 3h ago
An insult to googly eyed coked out podcasters everywhere.
100
u/TheModWhoShaggedMe 2h ago
The guys from We Might Be Drunk are offended! ;-)
→ More replies (3)49
u/Professional_Echo907 2h ago
This comment was brought to you by Hello Diarrhea meal service. Too lazy to cook something that will make you spew poop like a firehose? Hello Diarrhea. And also Amazon Pharmacy.
28
u/TheModWhoShaggedMe 2h ago
Couldn't have done it without the Cyclospora and all-conservative government! RFK Jr. is the best. I gift my award to U.S. conservatives -- may the diarrhea spew forever in your favor!
→ More replies (4)8
u/Maxfunky 2h ago edited 2h ago
Start thinking of as many Googly-eyed, coked-out podcasters as you can, and I think you'll see it's actually a pretty fair comparison. I mean, start with the original Googly-eyed, coked-out podcaster archetype, Alex Jones. They're all pretty much cut from that cloth.
→ More replies (1)39
u/smellmyfingerplz 3h ago
It’s ok they’re only allowing the best and brightest animal lovers and prostitution hobbyists after they got rid of competent agents who did what they were told and investigated Trump
→ More replies (3)39
u/kneel23 3h ago
its fine they're going after fraud - nevermind the fact President Trump ripped off $2b from maga taxpayers through a rugpull memecoin scam but hey, they're going after any non-whites that committed fraud at least
19
u/The_Lapsed_Pacifist 1h ago
Hey, I won’t stand for this slander, a good chunk of that memecoin was foreign bribes.
→ More replies (1)20
→ More replies (28)8
774
u/jabberwockxeno 3h ago edited 3h ago
Something really important about this I haven't really seen people talk about and I'd like some investigation on...
...When did people even give permission for their ID to be shared to this service and retained by them to begin with?
For Hertz and the hotels that use the service, sure, maybe it's buried in the rental and stay/room contract somewhere.
But the IDScan website also says they serve Target, Gamestop, and a bunch of other businesses where you don't sign any contracts, and last time I checked, there's not a big sign at Target or Gamestop notifying you that your ID is being uploaded to some other service.
I have not seen a single person able to explain this and I seriously wonder if IDScan and the companies that used it without notifying people acted illegally here.
504
u/Illcmys3lf0ut 2h ago
Won't matter. If they get sued, they'll pay lawyers millions. A government millions. Consumers? 25 bucks, MAYBE, and free credit monitoring for a year.
The system is rigged. Period.
→ More replies (10)148
u/tectonic_break 1h ago
Last class action lawsuit I got it basically said something like “the funds are too small to be distributed to everyone so you’re not getting any” 🫠
→ More replies (5)58
u/EllemNovelli 1h ago
I got $5 from the Facebook class action, while the lawyers got tens of millions.
→ More replies (6)7
u/EnzoVulkoor 1h ago
I got 28. I should probably be more concerned with why my data was worth more.
→ More replies (1)46
u/GrandTheftBae 1h ago
GameStop saves ID info when you trade in games. When I worked at one in California many years ago we had to let anyone trading games in that it's under pawn shop laws in CA.
→ More replies (1)13
u/DefiThrowaway 1h ago
My state still has a weird porn law that you need id to scan
→ More replies (4)→ More replies (40)8
u/Gulmar 1h ago edited 1h ago
Because in general people are either trusting, naive or disinformed about the risks of these things. And companies want to do asich as they can get away with.
Which is why there needs to be legislation for things like this. Any app, website or whatever that uses a government ID needs to be controlled by either that government itself, or checked by it that it complies with privacy and cybersecurity concerns.
→ More replies (3)
1.3k
u/Lumpymaximus 3h ago
The breach was at idscan.net, a popular software/hardware company that lots of american cannabis dispensaries use to verify IDs
754
u/dubious455H013 3h ago
You can add fedex and target to that list as well
533
u/hotdamnhotwater 3h ago
And Hertz, FedEx, Motorola, many casinos, online adult sites, many dispensaries, the US Coast Guard, and many many more.
570
u/ProjectHarraseeket 3h ago
I’ll love the $2 from the settlement I’ll get in 7 years.
165
u/hotdamnhotwater 3h ago
Best we can do is have your identity stolen and massive debt accumulated to your name. /s
98
u/smallwonder25 3h ago
If they want to steal my identity I wish them luck! It sure hasn’t helped me 😂
32
→ More replies (4)14
u/NRMusicProject 1h ago
I remember how hard I laughed getting rejection letters for jewelry I didn't apply to buy. It was a surprisingly easy call to have it stricken from my record, and having had no credit at the time was my protection.
Though, that was at least 10 years ago. I bet credit companies have made it more difficult to clear your name because it doesn't help them to clear you.
→ More replies (1)→ More replies (5)30
39
u/Meihem76 3h ago
You can also have a 1 month free sample subscription to our identity securing service tm
With automatic subscription for the full $49.99 per month if you forget to unsubscribe.
19
u/ArrowheadDZ 3h ago
Yep, I already spent my cut of the action this morning. That’s how optimistic I am!
18
u/Buck_Thorn 2h ago
You will probably have to have your ID verified before you can claim it.
→ More replies (2)11
→ More replies (13)7
u/No_Tangerine2720 3h ago
No no no! They will say they owe you 2$ but they only pay out 5$ or more so you will get nothing! Yeah capitalism!
→ More replies (6)48
u/jabberwockxeno 3h ago
For you, /u/dubious455H013 and /u/Lumpymaximus :
Something really important about this I haven't really seen people talk about and I'd like some investigation on...
...When did people even give permission for their ID to be shared to this service and retained by them to begin with?
For Hertz and the hotels that use the service, Motorola, websites, etc sure, maybe it's buried in the rental, phone and stay/room contract and the website's Terms & Conditions page somewhere.
But Target? Gamestop (which was also on their site) and a bunch of other businesses? Last time I checked, you don't sign a contract when you walk into retail stores like those, nor is there a big sign notifying you of how your data is being used.
I have not seen a single person able to explain this and I seriously wonder if IDScan and the companies that used it without notifying people acted illegally here.
→ More replies (5)20
u/hotdamnhotwater 3h ago
If you've used an app associated with the company then you've given consent. Just like all the social media sites. When downloaded and used, you've agreed that anything you add is basically game.
13
u/satansmight 2h ago
And then they can change the terms of service anytime.
I stopped adding any new apps to my phone or computer as a way to try and limit my information moving around.
→ More replies (4)6
u/jabberwockxeno 2h ago
If you've used an app associated with the company
I'm talking about retail stores, not apps.
→ More replies (3)→ More replies (7)29
u/WoolooOfWallStreet 3h ago
I wonder if somewhere down the line, some AI hiring program will automatically associate someone’s ID with “drug use” despite never entering a dispensary thanks to this?
→ More replies (3)25
u/j0mbie 2h ago edited 2h ago
Also used by many different rental car companies, banks, various parts of different local and state governments, and the coast guard.
The word "suspected" in the headline is probably just there so they don't risk getting sued or something. They are "suspected" in the same way that if your car were to be stolen, and then you see the same model car parked in your neighbor's driveway. With the same license plate. And if you hit the lock button on your keys, the car horn beeps.
Kerbs On Security broke this news on Sept. 1st, but IDScan has yet to release any information while they are "investigating".
→ More replies (1)155
u/rory_breakers_ganja 3h ago
Also the original story only broke because the Ruzzian hackers picked an ID at random to show as proof of their database. It was a noted cybersecurity analyst who recognized it as his.
112
u/HigherandHigherDown 3h ago
Krebs was definitely not picked randomly, and this incident was publicized on his blog krebsonsecurity.com after another researcher saw his ID and alerted him.
→ More replies (3)54
56
29
→ More replies (18)13
u/Zombatico 1h ago
Are we sure it's that, and not when DOGE installed backdoors to our government servers and then literal minutes later Russia tried logging in with the correct credentials?
Hm, alright.
472
u/SunflaresAteMyLunch 3h ago
Meanwhile: "there's no risk involved with online age verification"
→ More replies (13)
823
u/Rexur0s 3h ago
if we stopped using private contractors as middle men for sensitive government data and software, maybe this wouldnt happen?
475
u/tackleboxjohnson 3h ago
Whoa whoa whoa, you wanna cut out the middle men? What are you, a communist?
30
→ More replies (2)69
u/Nazamroth 3h ago
No, of course not. We are an anarcho-syndicalist commune here.
20
u/Maybe_Black_Mesa 2h ago
Do you take it in turns to act as a sort of executive officer of the week?
→ More replies (5)13
96
u/rabblerabble2000 3h ago
To be fair the government isn’t any better. Remember when OPM was hacked and everybody’s clearance paperwork was stolen? They hammered over and over how PII had to be encrypted, then the organization charged with safekeeping some of the most sensitive PII had it all sitting in plain text.
19
u/exitnirvana 3h ago
Pepperidge Farm remembers.
Got that free credit monitoring tho 😂 😒 😐
→ More replies (4)18
u/laptopAccount2 3h ago
Man I wish I could get a bajillion dollar contract to store shit in plain text. It would last a couple years at least and whatever consequences there are for getting hacked would only be a fraction of the money I raked in.
→ More replies (2)39
u/Rexur0s 3h ago
very valid. but atleast if these things are built in house they can be audited and fixed properly.
→ More replies (1)14
u/Slickaxer 2h ago
I'm down with this, but you'll have to pay gov workers a lot more to pry talent away from tech companies
→ More replies (2)13
28
u/WasteBinStuff 3h ago
Jesus Christ, are you seriously suggesting the government should take responsibility for protecting its citizens? Just how the fuck do you expect the corrupt insatiable billionaire douchebags to keep raping us for everything we own?
→ More replies (19)42
u/HotBrownFun 3h ago
to be fair, DOGE stole your government data, possibly installed backdoors for the FSB already
22
u/cptjpk 2h ago
There were stories coming out that within minutes of his team arriving at buildings foreign IP addresses (mostly Russian) were noted to be making succesful network connections.
Our data is in the hands of foreign governments and was / is being used for training Grok already.
16
u/HotBrownFun 2h ago
It's so weird the federal government didn't investigate this leak and major security risk.
84
u/mperezstoney 3h ago
This was the call out for id verification in many states when it came to watching porn. In Missouri it was one of the main things against it. Yet, republicans in the state said it was far fetched. Welp, there ya go.
→ More replies (1)
74
u/Modern_Bear 2h ago
Because not many people will actually read the article here is the pertinent part.
The service was advertised on the Russian cybercrime forum Exploit, where whoever was promoting it posted the driver’s license of Krebs as a free sample, which caught the journalist’s attention. He was also able to see a preview of U.S. Secretary of Defense Pete Hegseth’s information on the database — a concerning breach of security for someone with such a sensitive position in the government. After further investigation, they concluded that the service seemed to have possessed legitimate data, especially after searching for the data of several of his friends and family members with their consent. One thing that all the people he found in the database had in common was that they all used Hertz to rent a vehicle.
Krebs also talked with security and privacy researcher Zach Edwards, who said that their information was also found on Nexus. Edwards said that they did not rent a car recently but used their ID at a Planet13 marijuana dispensary. The time stamps found on the scanned images of the driver’s licenses and other identity documents coincide with the time that the victims used their IDs at the said companies, confirming that they were the sources of the leaks. However, Planet13 and Hertz do not do their own authentication; instead, they contract a service provider for the service. Now, it turns out that both Planet13 and Hertz used the company for identity verification and ID-authentication — IDScan.
Based on the evidence gathered by Krebs, it seems that the leak is centered around the company. He has already contacted the company about the issue, and they said they were investigating the matter. “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” Jillian Kossman, a marketing and operations leader at idscan.net, told the journalist. The FBI has also started looking into the leak, with its New Orleans field office opening an official investigation into the breach.
→ More replies (2)30
u/Mountsorrel 1h ago
“I’m not able to share any additional information…” is a statement dripping in irony
6
75
u/PuzzleheadedGroup624 3h ago
In before this is used for justification to challenge votes from these ID holders.
→ More replies (4)17
u/zx109 2h ago
No no, you see, because it's Russia, they're the good guys now apparently
→ More replies (1)
104
u/MaximumAd9779 3h ago
Naive question but what do people do with a stolen drivers license?
194
u/yzeerf1313 3h ago
Identity theft
68
u/Talentagentfriend 3h ago
Also use your identity to commit crimes and pin it on you
55
u/HCJohnson 2h ago
But with the Flock camera network they will be able to easily verify that it wasn't really you committing said crimes, right? ....right?
/s
→ More replies (2)14
17
u/dwide_k_shrude 1h ago
Identity theft is not a joke. Millions of families suffer every year.
→ More replies (2)70
u/RasputinsAssassins 3h ago
It can be used with data from other breaches or sources to impersonate someone else when applying online for things like loans, bank accounts, credit, or anything else that requires ID verification.
→ More replies (1)73
u/hitbythebus 3h ago
If I had a copy of Hegseth’s and lived in a state that required ID to watch porn, I would one hundred percent use his.
→ More replies (2)55
u/ArrowheadDZ 3h ago
And it ain’t going to be “garden variety” porn either, I’m wading into the “content reviewer will need counseling” deep end of the pool.
→ More replies (2)59
25
u/ArrowheadDZ 3h ago
Vote your vote. If we’re going to make voter ID mandatory, then the government protecting the sanctity of our identities at all costs will also have to be mandatory.
In fact, it will have to be constitutionally protected.
→ More replies (1)→ More replies (10)16
u/UnknownPh0enix 3h ago
Identity theft, fraud, etc. here’s an episode of Darknet Diaries (177) to listen to.
513
u/CroleyforCongress 3h ago
Maybe letting Elon Musk and a bunch of tech bros access all of our personal data was a bad idea?
→ More replies (1)117
u/Synectics 3h ago
While yes, this has nothing to do with this specific story. Turns out, multiple places are fucking all of us over.
31
68
u/neutrino4 3h ago
Starting in October you will need to have an ID.me account to log into your federal accounts. What could possibly go wrong with your SS#, photo ID, and your biometrics all gathered up in one place.
36
80
u/donac 3h ago
Shocking that our defenses are unraveling, what with all the competent leaders we've got these days.
→ More replies (2)41
u/MoneyTalks45 3h ago
It’s on purpose. These people aren’t this stupid. This is all on purpose. We were bought and sold a long time ago, this groups of clowns just isn’t trying to hide it because of their hubris.
→ More replies (2)7
21
25
u/K0SSICK 3h ago
Using this thread to remind everyone to go on to all 3 credit sites and create accounts and freeze your credit. If you ever need to open a cc or take out a loan, to can easily login and unfreeze for a short period.
→ More replies (4)10
u/Modern_Bear 2h ago
Good post and hopefully a lot of people read this. I did this years ago after the Equifax breach. Everyone should just keep all credit reports frozen permanently at this point, only unfreezing for as long as necessary to apply for credit. It's safe to bet that most people have had their information leaked online at some point in the last 10 years, probably multiple times.
36
u/terabit3 3h ago
Wait I thought these companies didn't keep the data once they do confirmed your age. Oh they lied again I'm shocked
→ More replies (1)
15
15
u/StaticSystemShock 2h ago
Every time they tell us to verify/authenticate online with some 3rd party authentication services by providing personal ID or personal photo I'm annoyed at how monumentally incompetent these companies are.
And soon, we'll be forced to not be able to do anything online or give our data to these incompetent idiots. So wonderful. If only there were other ways to ensure kids don't do dumb shit online, like better and more user friendly parental control tools and devices that during first setup ask if it's going to be used by adult or by teenager. Then parents set the limits accordingly. Instead we're dealing with this nanny state bullshit across the world.
247
u/wolfonweed 3h ago
duh. if your submitting your ID through any age verification bullshit, it is obviously going to be leaked anywhere and everywhere.
Everyone who thinks private organizations will be able to keep that information safe against state adversaries deserves to have their identity stolen. its just too fuckin stupid.
74
u/kc_cyclone 3h ago
Oracle is forcing us employees to do it by the end of the month. I'm holding off til last minute in case I get hit by the impending layoffs.
59
u/MrMichaelJames 3h ago
Why is oracle forcing employees to verify themselves? That is what the i9 is for.
34
u/kc_cyclone 3h ago
Auth for internal stuff. They already have my face for SSO logins but are adding more to it.
The true "why" is because Larry and Clay are fuckwit tech bros.
69
u/Shopworn_Soul 3h ago
It is important to remember that Oracle is a fuckass company run by fuckass people who choose to do fuckass shit whenever possible.
The person you're replying to is just stuck in the middle of some fuckassery.
→ More replies (2)→ More replies (4)10
u/MomsAreola 3h ago
Oracle quietly taking over all us government infrastructure while we look over at "trumps" war.
→ More replies (3)24
u/jabberwockxeno 3h ago
if your submitting your ID through any age verification bullshit
But were people even notified this was happening?
For Hertz and the hotels that use the service, Motorola, websites, etc sure, maybe it's buried in the rental, phone and stay/room contract and the website's Terms & Conditions page somewhere.
But Target, Gamestop and a bunch of other businesses that are just in person retail stores also used the service, and last time I checked, you don't sign a contract when you walk into stores like those, nor is there a big sign notifying you of how your data is being used.
I seriously wonder if IDScan and the companies that used it without notifying people acted illegally here as a result
15
36
u/italicised 3h ago
One of the biggest leaks here is from Hertz. A little brutal to say anyone using hertz deserves that
→ More replies (2)→ More replies (7)5
9
u/eugene20 2h ago
But sure lets make the world send Discord and others their id to age verify, what could possibly go wrong. Oh wait THIS, always, every time.
10
u/Majestic_Analyst_177 1h ago
I love the bullshit security measures these companies take and then they send a silly letter about a “cyber incident” and all is well. They offer a year of credit monitoring and expect us to be happy.
17
u/BigIreland 3h ago
So, basically everyone in the U.S. with a driver’s license. Jeeezus…
→ More replies (3)
8
u/RsnCondition 2h ago edited 2h ago
Oh no cyber security experts say keeping hundreds of thousands of people's information on a data base is a bad idea security, and privacy wise is a recipe for disaster from every sector of employment e.g: Public, Private Corporate, Government, Law Enforcement, and Military.
8
u/Alive_Employer5620 1h ago
Hmm it’s almost as if there was consequences to this administration gutting our FBI cybercrimes division 🤔
→ More replies (4)
8
8
u/CommunicationRare775 1h ago
Whiskey Pete Hegseth has a valid driver’s license?! That’s the real surprise here.
→ More replies (1)
•
6
6
u/Nazamroth 3h ago edited 2h ago
To be fair, there was no way anyone could possibly have predicted this. Well, with the minor exception of everyone who predicted this.
8
u/everythingbeeps 2h ago
Oh you mean the thing we all knew was going to happen as a result of their big anti-privacy age verification push?
7
u/60threepio 1h ago
I do not give Russia permission to use my personal information.
There, that fixes it.
→ More replies (1)
7
•
u/Gilles_of_Augustine 54m ago
My gods. Who could have foreseen this. How could there possibly be any downsides to gating access to media behind moralistically-inspired authoritarian identification checks managed by third-party for-profit companies over the internet. It's unthinkable.
13
u/jharrisimages 1h ago
I’m gonna go out on a limb here and say that, somehow, they’ll blame the democrats and Biden for this.
→ More replies (2)
6
u/McG713 1h ago
Sweet…I can’t wait to get my 6month free plan from the worst identity protection company and the $21.50 in the class action lawsuit/forced payout from leaked info. This timeline truly sucks.
→ More replies (1)
6
u/Ok_Caramel_3923 1h ago
Meanwhile they send over lutnick and kushner to lick pootins boots. Most incompetent administration in U. S. History.
6
u/xChoke1x 1h ago
I’m sure the secretary of defense having his information compromised is totally normal. Nothing to see here. It’s fine.
I wonder how bad this shit can really get. lol
•
8.5k
u/organik_productions 3h ago
Oh no, it's the exact thing everyone said would happen