A dark-web service is reportedly offering more than 153 million American and Canadian driver’s license records for sale, and the FBI is investigating an apparent data breach involving the identity-verification provider IDScan.net. This is yet another case where some of the very mechanisms that are supposedly meant to protect the American public are being used to harm it. The problem is clear: current anti-fraud processes that require customer identification and verification empower fraudulent activity by handing criminals your sensitive information on a silver platter.
Cyberattacks targeting personally identifiable information (PII) have been prevalent for some time and are only getting worse. In 2017, Equifax — one of the largest credit reporting agencies in the U.S. — underwent a cyberattack that led to the compromise of nearly 148 million Americans’ sensitive personal information. Nearly 45% of Americans had their data stolen. The Department of Justice alleged that the Chinese People’s Liberation Army was behind the hack in a 2020 indictment, but this was merely a band-aid to the underlying and increasingly prevalent problem.
Laz Pieper is the research director at Coin Center, which defends the rights of individuals to build, use, and assemble free and open peer-to-peer networks, and the right to do so privately.
Most people have probably not heard of IDScan, but have handed a driver’s license to businesses that use its technology and services. As the name suggests, IDScan specializes in ID verification and provides hardware and software that scan, parse, and authenticate IDs for car-rental agencies, banks, hotels, casinos, cannabis dispensaries, retailers, and other businesses. Its systems can capture front-and-back images, extract personal information, compare an ID’s photograph with a selfie, and transmit or store the resulting data in a cloud portal for businesses to continue to access after authentication.
Despite any cybersecurity measures, its business model was always prone to attacks. Data is one of the 21st century’s most valuable commodities. Governments and corporations alike have designed schemes to acquire as much of it as they can from citizens and consumers, and in the process, have opened the door for cybercriminals and foreign adversaries to partake in the modern-day gold rush.
The most consequential data is, of course, PII, which is made up of highly sensitive details, including a person’s name and address, as well as their government-issued ID, such as a driver’s license or passport. To access a good amount of services in the U.S., Americans must identify themselves and the service providers must verify that they are who they say they are. This requirement can be both regulatory and commercial: the government wants to prevent fraud and illicit activity, but so do businesses. Unfortunately, the manner in which to do so has done little to prevent fraud and illicit activity, but plenty to empower them.
Financial institutions, such as banks, offer the best example. Financial institutions are required under the Bank Secrecy Act (BSA) and its regulations to collect and retain records of PII when onboarding new customers to combat illicit finance and fraud. This sensitive, valuable information is often stored in a central database, known as a “honeypot,” making it an attractive target for hackers. Once PII is stolen, it can be used to open or compromise accounts, conduct fraudulent transactions, and launder money in the name of an innocent person.
How have these “preventive” measures panned out for the U.S. and global financial system? The Federal Trade Commission’s database of consumer complaints and reports received 6.47 million reports concerning fraud, identity theft, and other consumer problems in 2024, up from approximately 860,000 in 2004. And illicit finance runs rampant: it has been estimated that global illicit financial activity reached $4.4 trillion just last year.
Financial institutions have increasingly adopted various methods for customer verification to prevent criminals from bypassing their anti-fraud checkpoints — despite acquiring a law-abiding citizen’s PII — but these methods have proven to be minor obstacles at best. Temporary codes sent via text or email are easily compromised through phishing attacks and various other methods, and biometric checks are weakening with rapid advances in artificial intelligence.
IDScan is not a financial institution, nor is it required by law to retain anyone’s PII — it is merely a vendor that allows other businesses to conduct identity checks. However, the businesses that used IDScan’s cloud services concentrated their honeypots into a more centralized location and made a data compromise that much easier.
Taking all this into account, why do we surrender our sensitive personal information if all we receive in return are false promises of security? Americans are not safer because they identify themselves in each waking moment to every service provider they come across. Far from it. And yet, governments at home and abroad wish to expand the identification regime even further with age verification under the guise of protecting children. But we are again witnessing that these “protections” cause more harm than good. Our information is out there, being traded amongst criminals because governments and corporations wanted to know who we were and what we were doing. And now we pay the price.
If there were ever a time for stronger privacy, it is right now. However, we cannot ignore nuance. There are calls for abolishing identification and verification processes entirely. This is an attractive alternative, but the reality is that the underlying purpose of anti-fraud processes is to protect Americans and their property, and they protect businesses’ revenue and operational integrity — the current approach is just unsuccessful. There is real utility here, but this does not mean that we need to remain with the status quo.
Developing technologies offer the possibility for a better approach. Instead of repeatedly requiring Americans to surrender complete copies of their ID, privacy-preserving systems could allow individuals to prove only what a service needs to know — such as their age, eligibility, or authority over an account — while keeping the underlying information under their control.
These technologies are still in the works, but federal regulators should give institutions room to test them and update existing requirements as they mature. Additionally, as more privacy-preserving approaches emerge, Congress should reduce unnecessary information collection and retention requirements. Anti-fraud processes are still valuable, but can exist without a permanent dossier for criminals to steal.
More urgently, Washington and various state governments should stop any legislation or regulation that extends identification and verification requirements to areas where they do not already exist and are not needed. The push towards age verification of open-source software and the internet must end; it endangers everyday Americans and empowers criminals and foreign adversaries, while failing to protect children.
Breaches like this one are preventable; we just have to want to prevent them. The tools to do so are beginning to emerge, and in cases where we do not need to verify someone, we should avoid doing so. Because the best way to protect sensitive personal information is to not collect it at all.
