A reported cache of more than 153 million U.S. and Canadian driver’s-license scans allegedly sold through a dark-web service exposes how routine identity verification turns durable government ID into a high-value, hard-to-remediate breach target.
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Welcome to the Shared Security Podcast, the longest running cybersecurity and privacy
show for actual humans.
No jargon, no hype, just honest analysis from industry veterans who've seen everything
and survived it.
Each week we break down the stories that matter, expose the nonsense that doesn't, and give
you the tools to stay safe in a world where everything is connected and nothing
is guaranteed.
This is Shared Security.
This week on Shared Security we're talking about a story that exposes a hard truth about
digital identity.
When a driver's license becomes the proof you need to get online, it can also become
a high value target.
So reporter Brian Krebs reports that a cache of purported driver's license data affecting
153 million people is being offered for sale.
Well we'll discuss what that says about identity verification, data brokers, and verification
vendors, breach responsibility, and why just upload your ID, what could possibly go wrong,
is never a simple security or privacy decision.
And joining me for this conversation is my co-host, Scott Wright and Kevin Tackett.
Welcome guys.
Yeah, I wanna.
Whatever, it's just another, what's 153 million people.
In North America by the way.
Includes it.
Would you be worried about it?
No.
Yes, there are Canadians affected in this, so it's not just the United States.
So there's been some updates to this story, so we'll link in the show notes that Brian
Krebs actually did a little more research in it.
Apparently this is attributed to a company called IDScan because there was some, I
guess speculation, right?
If this was like Department of Homeland Security or, you know, a government entity that
was breached, because as you know, when you go to the airport, you provide your ID or
your passports, but after further research, it seems to be this IDScan, which partners
with a lot of different companies.
I think this one in particular was like some marijuana dispensary in Las Vegas, apparently.
So like, this is a.
Not too shady.
No, I mean, if it's legal, right?
But you still have to present your ID and then that ID gets scanned and then
it goes somewhere.
So this is beyond, I think, what we've been talking about on this podcast about online
age verification and the problems with that.
But this now expands on to when you're physically handing your ID to somebody to,
I mean, it could be you could be going to a concert.
You could be going to, you know, a marijuana dispensary is one of many
things that ask you for your ID.
I think this is this is the transition from the bouncer at the club, making sure
you're 18 or 21 by looking at your ID and verifying it as a.
Yeah, this looks real, right?
Not that I've ever printed fake IDs, but, you know, back in the day, supposedly,
hypothetically, that that was something you could do that transitioned
to a technological solution.
And I think that what we're seeing is the same thing we've seen
with so many different, oh, we have to do some things, right?
We we roll out a solution, a company says, I can do that.
And they build very quickly.
And then nobody holds them to a standard that's reasonable, right?
I've talked to, you know, companies that do this type of ID verification.
We've worked with customers that are using them.
And we've said for years, this mechanism
doesn't appear to be secure and I want to be very clear.
I'm not I'm not claiming that somehow Evan was smarter than the average bear, right?
We've heard this from the industry as a whole, that they're running down this path.
The only thing holding them to a level of standard, typically,
is the contract they have with whoever they had it with that says
they should do good things, you know, be secure, whatever.
Right. I'm I'm laughing at it right now.
We're dealing with it security is with a customer
that is asking us why we don't have certain controls they think are reasonable
at the same time that there's a conversation about breaches they've been part of.
Right. That's what in my opinion, that's what happened here.
We had a company that stood up something to solve a problem
and they solved the problem and secure themselves well enough.
Yeah.
This will continue to happen for as long as we don't hold people accountable
for the loss.
And I mean, effectively accountable, not just, oh, man,
everybody got a year of free credit monitoring, because that's where it'll
come out of this. We'll all get another three year.
I think I'm currently a year four thousand that I've been right.
I've lost track. Right.
My my favorite is they don't stack.
Right. Like you don't.
OK, so I've got 2026 covered.
Do I get 2027? No, no, no, no, no.
You just get 2026 covered again.
Yeah, I know. Yeah.
I think it's really interesting and going back into the age verification
debate, there are so many of these companies out there now that are doing
ID verification, age verification, whatever flavor of verification
you want to call it.
And there is no regulation or, you know,
laws around how this this information is stored.
And so to your point, Kevin, about a breach, like this is going to
continue to happen.
And it's kind of scary to think about that any random company
can now just partner with these organizations and it's going to vary
by state and institution and business and all these things.
And this is just another way to expand out the attack
surface of very personal and, you know, these are driver's licenses.
And I it just blows my mind that here we are again talking about this
and it's only getting worse.
Well, like we've talked about in the past,
what was that dude that was running the business out of his apartment
that was just doing data collection and selling it to marketing?
Yep. Well, we've seen through lots of these companies
and I don't know about this one, but they are data brokers
in and of themselves, whether they're doing it for marketing
or whether they're doing it for verification, they are a data broker.
And as long as we allow anybody, private organization, individuals,
government agencies, what have you to collect data unfettered.
And then when there's a breach, we just go, oh, man, that sucks.
I go deal with that because I tell you right now,
I can't go to Florida and say my driver's license
has been compromised, give me a new number.
That is not an auction.
Nope. Right.
As far as I know, I don't know any state that allows you to say
my driver's license was compromised, give me a new number.
Unless you lost it.
But if you let it expire, you have the same driver's license.
You get the same number, though. Yeah, you're right.
Yes. So my address is the same.
My date of birth is the same.
The day it was issued is the same.
You know, originally issued.
Every piece of personal identifiable information on a driver's license
stays the same no matter what.
So there is no validation.
So at what point do we then say, OK,
driver's license are no longer good for ID
because they've been compromised so many times.
What's next?
Fingerprints. Well, digital ID,
which has already been rolling out.
Some states actually have this now
where you can have your digital ID on your phone
and you can go through security at the airport with it.
And I'm seeing this more now.
But then just like everything else,
what happens when you lose your phone,
which people lose their phones all the time.
So it's, you know, wallet or phone, physical piece of paper
or ID card versus a digital version.
I think to your point, Kevin, it's going to stay the same.
If I lose my phone, they're just going to issue
another digital ID with the same number.
Right. Well, what we need to do, in my opinion,
what we need to do is hold people accountable
for the damage they've done.
It's that simple.
Yeah, it really is.
The minute you start and I know
I willingly be called the hypocrite that I probably am here
because there is a level of victim blaming that I'm doing.
This organization is the victim,
is a victim because they were hacked.
And we don't know about this specific one,
but we, you know, as well as I do that in the past,
we have seen that they don't have even the basic security
controls that we would expect an organization to have.
I don't know about this one, right?
At what point do we say, OK, you're no longer the victim,
you're part of the problem.
Yeah. And I don't know where that line is,
but I think it needs to be figured out somewhat soon.
I think it's interesting to me when we talk about physical IDs,
like this used to be so simple, like literally,
like just like 10 years ago, maybe even further in 10 years.
But I'm just thinking like we didn't we were never recording
people's driver's license when you went to go rent a car
or when you went to show your ID at a restaurant
or, you know, purchasing alcohol, what like.
That's not true. No. Sorry.
We were recording driver's licenses when you rented a car
the 27 years ago.
And I only know that because I worked at Alamo 27 years ago.
OK, so their quick rent system.
We were storing credit card drivers license numbers then. OK.
But. But the rest of what you said is absolutely correct.
When you walked into a restaurant and showed ID to pick up your reservation,
which I've had to do not always, but there are times you have to do that.
They don't record it.
I just read an entire rent by somebody on Reddit.
I think it was where they went into.
I think they send Kroger's, but I don't know.
They went to buy something and it required ID,
whether it was alcohol, cigarettes, I don't know.
And they took the ID and they scanned it through the register.
And the person was complaining that that grocery store,
whichever one it was, yep, doesn't have a privacy policy about what they're doing.
What are you getting off of that?
Versions that you're scanning.
Where are you storing it?
Where are you putting that?
Are you, you know, every bit of that?
And those answers aren't available to us right now.
And we just keep running down the throwing out a tangent here, but related.
We going down the loyalty path, right?
Yeah, do you have a loyalty program with that grocery store?
Do you have a lawyer program with that marijuana dispensary?
Do you how did you verify that it was you?
How did you get right?
Yeah, it's just getting worse and worse.
And we're being told it's for our own safety.
And to protect the children, of course.
Well, absolutely. Yeah.
Yeah, so Scott, I think you had an interesting angle to this story, didn't you?
Yeah, I mean, first of all, you know, my background in risk management stuff
is interesting because what we're really talking about is transferring risk, right?
In this business model where you go into a rental car company,
they don't really want to have to go through all the process
of verifying exactly who you are.
They want to outsource that process of verifying your identity, right?
So that's the transfer of risk.
And what Kevin's talking about is really how do you minimize the data exposure, right?
And so if you can minimize the information that's being stored centrally,
especially, then that solves, you know, part of the problem.
The other part, of course, if you do it totally decentralized
is the problem of what happens if you lose your your device.
So it's still a risk management problem.
But the real issue is because, you know, when the stuff gets stolen,
you risk impersonation, right?
And that can have many other kinds of impacts on people,
not just that you can go and, you know, set up a loan account
or some other high value account in someone's name,
but you could impersonate people and do lots of damaging things.
And I think your comment about the digital ID is really important.
It's certainly an area we haven't really heard a lot about.
I know you guys know of many solutions out there.
I would like to mention there's one here in Ottawa in Canada called Blue Inc.
B-L-U-I-N-K.
So if you're looking for a Canadian solution that does digital IDs,
that's a it's a good place to go.
But the really nice thing from a risk management point of view
and data minimization is they're not storing data centrally, right?
They do some scanning of your things, capture some information
and then encrypt it and keep it locally.
So the service itself never has that information
and the customers of the service never have that information.
So I think it's an elegant solution, but yeah, you're right.
We've got to solve the issue of what happens if you lose your device.
There's got to be backup processes.
I don't have a whole lot of information about how the Blue Inc.
service works, but if I get any, I'll pass it on to Tom.
We can talk about that or provide some resources on it.
But I think the whole idea is that way, as Kevin says,
way too many people are storing data and not being held accountable for it.
And I think that I was trying to think of like, what would we tell
listeners of like, what to do about this, right?
Yeah. And there isn't anything you can really do
except for don't give your ID over, but then.
Yeah, I mean, actually, there's a use case I went through recently
where, you know, they didn't use Blue Inc.
or digital ID as far as I know, but I had to, you know,
to recover a Facebook account or something like that, right?
You've got to show your front and back of your driver's license, scan it.
It goes somewhere. I don't know where.
I don't know what, what, you know, did I read the terms of, you know,
privacy policies or anything like that?
So that kind of stuff is really common now.
And so I think you have to ask yourself, you know, where if you're
concerned about this stuff, where is the data being stored?
What data are they storing?
How is it being protected?
How is it being used or shared, right?
And what accountability or penalties are there on them for losing it?
Yeah, and that's just really hard to do when you're, you know,
trying to access a service and you just like, OK, I just want to get this thing done.
Well, I got five minutes, I'm not going to read it, 20 page privacy policy.
And so like, and I think it was interesting about this particular attack.
And if you read the article that was talking about how this was happening
in real time, so the attackers actually had access to this system
and new IDs were coming in like all the time.
And so they had a real time feed to this access.
So even if the company says, yeah, yeah, we delete your ID
after so many days or whatever, like this reminds me of mage card, Kevin,
like, you know, when you had a checkout system compromised
and attackers are getting credit cards as the transactions are happening.
Even if they do the right thing of like, hey, we're only capturing
certain information or encrypting it.
This is all happening before those processes actually start.
So this is like the worst case scenario, in my opinion, of of how this attack is happening.
This is the problem with application security that we have.
Totally. And three years, right?
The app at some point as the data, whatever we do, right?
And we've always we've always historically talked about Alice and Bob
and right, like transmission of data in somewhere
where I see a huge gap in understanding is that if one end is compromised,
what happens, you know, and yeah, this is a fun one.
Oh, yeah, really exciting.
Oh, well, we're going to get out of all the driver's license.
Well, I was not at a dispensary in Las Vegas.
I do know my driver's license has been scanned and pen into lots of systems.
Oh, everybody's. Yeah.
Well, mine has been more than average
because of the name chain, the number of systems.
Right. And I give you a good example.
I had to change my Hilton number, my name on my Hilton account.
I have never given Hilton my driver's license to change my name.
I had to send them a copy of my driver's license. Wow.
Right. And I understand why they asked for it.
Right. Like I get the reasoning and I'm not complaining about Hilton here.
But this is anybody who has had to go through that type of system recently.
Tag, you're in it.
Yeah, especially Hertz, Target, FedEx, Motorola.
Yeah. All the ones that Brian Krebs named, right?
Caesar's Entertainment. That's right. Yeah.
Yeah. It's a huge list.
And it's very hard as a consumer to, you know, unless you just literally say,
I'm not giving you my ID and then therefore you're just not going to use these services.
I mean, I even had my ID scanned for a reservation at a restaurant.
Like it's insane how much this is happening now.
So we just don't have great advice for everybody.
Sorry. The advice is how this sucks.
Yeah, it just sucks, right?
Until there is more legislation or, you know, something changes.
But I don't see this getting any better, unfortunately.
And you know my opinion of legislation.
Oh, I know. It's not going to help.
No. No matter what country it is, it's probably not going to help.
All right. Well, last thing really quick, again, we'll plug Scott's book.
So we'll have links in the show notes.
We love plugging the book because you're continuing to get feedback, which is good.
Yeah, absolutely.
Getting some great review comments from people who've been listeners to the show.
So thank you, everybody, for that.
I'll share just a little tidbit of wisdom for people.
You may have heard of the, you know, all the legacy contact solutions
that are out there for Google and Facebook and Apple and Microsoft, et cetera.
Right. So the Google solution is called the Google Inactive Account Manager.
And once it makes it so much easier if you can set up these things.
But just as an example, how they all work so differently.
It's great if you set this up with Google.
You can say, I want Tom to be my legacy contact.
And if I if he makes a request for my access
to my Google account information and I don't respond
within a period of time, then Tom gets granted access.
So that that makes sense.
But what I've learned and what might be interesting to people is the minimum
period that Google allows for that to happen is 30 days, which is a long time.
For my point of view, I mean, if I'm out of action
for five days, then somebody should be able to take over, right?
And so anyway, just thought I'd pass that on.
Yeah, that's good to know.
It means you've got to think more about, you know, what do you want to happen
in that period of time?
Yeah. And I'd encourage listeners, if you want to find out more about Scott's
book, definitely check out the link in the show notes.
And hopefully a pre-order coming out soon.
Yeah, we're going to be putting up a pre-order page soon.
Yep. Nice.
All right.
Discounted Kindle version for for shared security listeners.
Awesome. Awesome. All right.
Well, thank you all for listening as always and supporting the podcast.
We really appreciate it.
Until next time, stay safe, stay secure and stay privates.
Thank you for listening or watching.
If you like this episode, hit subscribe, share it with your friends and
colleagues or jump into our community at sharedsecurity.net
slash supporter to keep the conversation going.
Thanks again.
And we'll see you next week for another episode of shared security.