Live data from Hacker News

FBI Probes Service Selling 153M+ Drivers Licenses

krebsonsecurity.com

41–50 of 307 posts

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#41

If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold. Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in…

Make Customer Data a Liability

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#43

Bankrupt this company to serve as a warning to others that hang on to way too much data.

At least reimburse everybody for all the costs involving getting the old drivers license invalidated and apply for a new one. Unfortunately that will not cause to magically dissapear the rest of your harvested profile.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#44
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

I believe we need to criminalize possession of the data, with statutory damages per violation.

Not quite the same, but the GDPR gives you a right to erasure.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#45

So an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.

153 million puts them at roughly 1/2 of all Americans. Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.

I once tried to reach one of the two Canadian background check companies a prospective employer wanted to use to check me. I eventually found their privacy and security phone number. It had a poorly recorded voicemail to leave a message and they’d call back to answer questions. It’s been 12 years. They haven’t called me back yet but I’m assured they take privacy very seriously.

I didn’t go through with that part of my application and didn’t keep the job.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#46
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

I believe we need to criminalize possession of the data, with statutory damages per violation.

Exactly. Personal data should be treated like radioactive material. Strictly regulated to such an extent that no one wants anything to do with it unless they absolutely have to use it in the course of their business. After that, their primary concern should be how to dispose of it quickly and safely.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#47
> vendors who collect this sensitive data need to be held to a higher standard.

They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).

One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses.

The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#48

> vendors who collect this sensitive data need to be held to a higher standard. They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news). One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local leve…

Ahem

Some Interrail travellers told to cancel passports as hacked data posted online

https://www.theguardian.com/technology/2026/apr/23/some-inte...

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#49
post #12

The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

Any kind of lending facility, for example, is required, by law, to retain identity documents for an extended period of time - we're talking around five years _post_ account closure.

So most businesses are not permitted to just delete the data.

Re: FBI Probes Service Selling 153M+ Drivers Licenses

#50

> vendors who collect this sensitive data need to be held to a higher standard. They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news). One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local leve…

Ahem Some Interrail travellers told to cancel passports as hacked data posted online https://www.theguardian.com/technology/2026/apr/23/some-inte...

True, and there’s the notorious story of the Finnish psych data leak[0].

I just don’t hear about it anywhere near as much.

[0] https://en.wikipedia.org/wiki/Vastaamo_data_breach

Post reply on HN