The enormous driver’s license hack reported by KrebsOnSecurity is outrageous. A dark-market database claims more than 153 million license scans—including Pete Hegseth’s and Brian Krebs’s—were apparently siphoned from identity-verification middleman IDScan.net. Read the story.
You should be mad.
We are long, long, long overdue to reduce the amount of KYC we do as a society. It doesn’t stop crime. It enables mass surveillance of the innocent by the tyrannical. And, perhaps most of all, it enriches hackers with troves of intimate personal data.
We deputize a sea of shitty quasi-government contractors to perform data collection and monitoring that would raise obvious constitutional alarms if the government did it directly. Then we act stunned when one is apparently run by negligent fools who fail to delete or secure the underlying driver’s-license photos they are verifying—photos belonging to people who aren’t even their customers, oh and it is literally HALF THE POPULATION OF AMERICA.
These types of hacks are only going to become more common as attackers weaponize AI to poke at honeypot verification systems. It’s even more absurd because we have the technology to do better: verifiable credentials and zero-knowledge proofs of limited identity data.
Risk-averse compliance departments and set-in-their-ways regulators prefer old practices and the appearance of rigorous compliance—box checking—to actually protecting people through data minimization and auditable, verifiable alternatives.
We explain the alternative in Tear Down This Walled Garden.
If you want this to change, get involved with our John Hancock Project and support Coin Center.
Image Source: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/




