Digital ID/age verification puts us all at risk while our corrupt politicos, notably Mark Carney and Danielle Smith, refuse to regulate the vile tech billionaires and their sexually abusive AI shit because they and pedophile rapist Trump want mass surveillance. More than 153 million U.S. and Canadian driver’s license scans for sale on the dark web, “along with more than 10 million other identification cards, more than 3 million travel documents and international IDs, and hundreds of thousands of medical cards.” JFC!

@caineswritings.bsky.social:

Remember, META (aka Facebook) is the one that wants age verification.
It saves them from the lawsuit and removes the proof of burden from them to 3rd party companies. When they know VERY WELL how old you are.

@chilangolandia.bsky.social:

Exactly. They expect us to just trust them with our IDs. We all need to not do this. Get off the apps if necessary until they get their heads out of their asses and realize that demanding people’s passports/DLs does not make any of us safer.

@mickstec.bsky.social:

We do not actually need age verification. What we need is for Meta and X to be a paid subscription so people can be identified via their bank account. Any country not supporting subscriptions, or accounts without subscription gets ZERO access to Australia.

Trolls gone overnight, just like the kids

@aiagentcanada.bsky.social:

Anything asks me for age verification gets tossed into a void

@9b8ll.bsky.social:

The worst part is that the age assurance companies are not regulated and fined for data leaks. They need to be investigated like IDscan.net , K-id yoti
Persona and so on. Because breaches keep happening and security is nonexistent.

@goldenvanity.bsky.social:

I chose to decline activating a new credit card because they required a selfie photo together with a driving license image. I complained and was offered the opportunity to send an unredacted 1040 (not allowed to redact kids’ names and SSNs!) instead.

This was all after I had the card in hand.

@journodale.bsky.social:

The Carney government demands age verification as part of their digital safety bill.

And you can thank Senator Miville-Dechêne for pushing this for years, and every party (eventually) signed on.

Slow clap.

Age verification makes everyone less safe.Age verification makes everyone less safe.Age verification makes everyone less safe.Age verification makes everyone less safe.Age verification makes everyone less safe.Age verification makes everyone less safe.

Evan Greer (@evangreer.bsky.social) 2026-09-04T22:19:16.053Z

@rlynner.bsky.social:

disgusting. FBI probably gonna figure out how to deny voting with this little trick.

@evangreer.bsky.social:

Setting aside all the civil liberties, privacy, and free expression concerns, online ID checks / “age verification” laws are just a massive massive security risk.

Every time I read one of these bills I ask “did an identity thief write this?!”

@danofiniquity.bsky.social:

Half the US population, that an extraordinary amount of personal information lost. This is one of the problems with age verification schemes, it leaves so much data vulnerable to nefarious entities. Wish the UK government understood this.

@esqueer.net

This is an absolutely catastrophic data breach of an identity verification vendor 150+ million drivers license scans that includes photos, address, license numbers etc. It includes Pete Hegseth, security researchers, and even the deputy director of the FBI. krebsonsecurity.com/2026/09/fbi-…

This is exactly why privacy advocates have pushed back against age verification measures. These companies are reckless with their data and it can easily be compromised. It can leave people vulnerable to identity theft, doxing, and targeted harassment.

This data breach looks like it was an identity verification service idscan[.]net. They provided services to hertz car rental, various hotels, dispensaries, and retail stores.

@davidmack.pro:

We warned the American government and people that this would happen, that it was inevitable, and that they should reject age-verification laws for exactly this reason. Not enough people listened. Oh, how we warned them.

@darkglade.bsky.social:

AAAAAAAAND, this is precisely the sort of thing we’ve been warning people about for YEARS…

Identity Verification Is Broken. The 153 Million Driver’s Licenses Now for Sale Are Proof

A massive trove of driver’s license scans allegedly stolen from an identity verification company shows the danger of creating honey pots of our most sensitive documents for malicious actors to exploit.

By Kyle Torpey Published September 2, 2026, Gizmodo

Comments (16)

A dark web identity theft service is offering more than 153 million U.S. and Canadian driver’s license scans for sale, and the FBI is investigating where the data came from. The apparent breach is a particularly stark example of the problem with the modern identity verification economy where proving who you are means providing a third party with permanent copies of sensitive documents.

According to KrebsOnSecurity⁠, the service, called Nexus, launched on a Russian-language cybercrime forum and claims to have more than 153 million driver’s licenses, along with more than 10 million other identification cards, more than 3 million travel documents and international IDs, and hundreds of thousands of medical cards.

The number is difficult to independently verify, but Krebs found evidence suggesting the service is not simply bluffing. The database contained the licenses of Krebs himself and U.S. Defense Secretary Pete Hegseth, among other government officials. The licenses included multiple images of the documents, including front and back scans and, in some cases, infrared and ultraviolet versions.

The data also appeared to be fresh. Nexus’s advertised collection grew by nearly 400,000 driver’s license records in roughly 24 hours, while the operators claimed they had been continuously exfiltrating information for more than a year.

Krebs traced the apparent source to IDScan.net⁠, a New Orleans-based identity verification company. The company says its technology processes more than 21 million identity verifications every month at more than 20,000 locations around the world.

IDScan.net’s customer materials show just how deeply this type of infrastructure is embedded in everyday commerce. Its official site lists companies and brands including Holiday Inn, 7-Eleven, GameStop, DraftKings, Hertz, Target, FedEx, Shell, and Caesars Entertainment among its customers or integrations.

The connection is particularly striking because Krebs found that timestamps attached to several leaked licenses corresponded with trips, hotel stays, car rentals, and other real-world interactions where people handed over their IDs.

IDScan.net said it is investigating the incident but has not publicly confirmed that its systems were the source of the Nexus database. The company told Krebs that it was unable to provide additional information while its investigation continued. The FBI has also opened an investigation through its New Orleans field office into the apparent breach.

Shortly after Krebs published its report, the Nexus site itself disappeared from the dark web and was replaced with a message saying the service was no longer available.

Peter Van Valkenburgh, a longtime cryptocurrency policy advocate and Coin Center Executive Director, argued in an essay⁠ that the breach was not some bizarre one-off accident. He called the hack “inevitable” and said society is “long, long, long overdue to reduce the amount of KYC we do.”

Van Valkenburgh’s argument is fundamentally about data minimization.

Every time a company demands a scan of a government ID, it creates another repository containing information that can potentially be stolen, resold, or abused.

We deputize a sea of s*itty quasi-government contractors to perform data collection and monitoring,” Van Valkenburgh wrote, arguing that the resulting databases become attractive targets precisely because they contain so much valuable information in one place.

Security and privacy researcher Zach Edwards, whose own driver’s license was found in the Nexus database, told Krebs that the incident highlights the risks of outsourcing identity verification to an expanding network of third-party vendors. “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe,” Edwards said.

Indeed, the very systems that have been built are a contradiction in themselves. While there are increasingly sophisticated processes put in place to determine whether someone is really who they claim to be, those systems often require collecting enough information to create a devastating situation if the security surrounding the associated database fails.

And this is hardly the first time the scale of the problem has become absurd. In 2025, education software company PowerSchool was breached in an attack that exposed sensitive information belonging to tens of millions of students and teachers, including Social Security numbers, dates of birth, and medical information. In 2024, AT&T also disclosed that hackers had obtained the Social Security numbers, dates of birth, phone numbers, email addresses, and other information of 73 million current and former customers. A separate incident exposed phone records belonging to nearly all of the company’s customers.

Solutions are Available

Technical solutions to this underlying problem of creating honey pots of sensitive customer data are available. For example, zero-knowledge proofs can allow someone to prove that they satisfy a particular condition without revealing all of the information contained in the underlying credential. Instead of handing over a complete driver’s license to prove that you are over 21, a system could theoretically verify the relevant fact without receiving your name, address, license number, and other information printed on the card.

153M drivers licenses leaked!
Identity documents should only be authenticated using zero-knowledge proofs. Stop revealing all your personal details just to prove you have a valid drivers license.https://t.co/ebdV54Zk78

— Remco (@recmo) September 2, 2026

While these technologies do not magically make identity verification secure in all scenarios, they offer a way to redesign the system so that verifying someone’s identity does not create other, second-order issues.

Of course, there is also a less convenient reality behind all of this in that some of the data collection is not simply a matter of companies deciding they want more information. Laws and regulations can require businesses to collect, verify, or retain identifying information in certain circumstances. In other words, changes to the regulations around personal data collection are needed on top of the adoption of various technical innovations.

Whether these technical or regulatory changes will be implemented anytime soon remains to be seen. “Risk-averse compliance departments and set-in-their-ways regulators prefer old practices and the appearance of rigorous compliance—box checking—to actually protecting people through data minimization and auditable, verifiable alternatives,” wrote Van Valkenburgh.

@techpriest4.bsky.social:

It never was about age verification, it is so the platforms can guarantee real people are looking at ads and not bots. The sale and theft of our information is just a bonus revenue stream they get to enjoy with no repercussions.

@cianwood.exploration.team:

OpenAI is now facing more than 50 consumer harm and wrongful death lawsuits alleging that extensive use of ChatGPT resulted in psychological harm, physical injury, and even the deaths of users and/or those around them.futurism.com/artificial-i…

Maggie Harrison Dupré (@mharrisondupre.bsky.social) 2026-09-04T19:33:41.603Z

@aster-verite.bsky.social:

I hope everyone files in California court… or other jurisdiction that does not cap punitive damages…

It is going to take a lot to bankrupt these ghouls.

@aster-verite.bsky.social:

Make OpenAI pay in the billions of USD please.

@reyhusky.bsky.social:

Do not settle please there should be criminal charges not just civil.

This entry was posted in Global Frac News. Bookmark the permalink.