This Week on What the Hack: Data Breach Exposed 153 Million IDs
This Week on What the Hack: Data Breach Exposed 153 Million IDs
A driver’s license breach didn’t just leak data—threat actors now have access to a universal key to every identity verification system that relies on state-issued identification. DeleteMe’s Rob Shavell joins us to explain what happens when the document designed to prove you’re you can no longer be trusted.
Episode 270

Ep. 270: “Your Driver’s License Can’t Prove Who You Are Anymore”
“What the Hack?” is DeleteMe’s true cybercrime podcast hosted by Beau Friedlander.
Disclaimer: This transcript was auto-generated and may include minor errors.
Open
Beau: Somewhere right now a criminal has a tab open on a monitor. There’s a scan of the front and back of your driver’s license. There’s 10 more tabs open. You’re being targeted. Those other tabs have information about you. No social media? Cool. They have other ways of getting what they need. People search sites, minutes from some meeting you went to. You’d be surprised at how little a threat actor needs to figure out who you are, who you know, and what makes your world go round.
CBS Mornings: An FBI investigation into a potentially massive identity leak on the dark web. Independent journalist Brian Krebs says he discovered an online marketplace called Nexus. It offered to sell digital scans of more than 153 million driver’s licenses from the US and Canada, as well as travel documents and medical records.
Beau: It’s my job to determine how serious a risk this or that news about a compromise or a breach or a hack may or may not be, right? My friends text me links all the time with messages like, “Serious?” Or, “Do I need to worry?” The answer regarding this particular incident with ID scan is yes. It marks the end of cybersecurity as we know it, possibly. Now, you might be thinking, “I’ve never had my license scanned for anything.” I’m willing to bet you’re wrong about that. Maybe you’ve never been a passenger on a commercial airline. Fine. Have you ever bought ammunition for a gun or applied for a firearms permit? Ever been to a cannabis dispensary? How about a hospital? You ever been to an ER or urgent care? Visit a sick loved one? GameStop? You go to GameStop? Rent a car? Have you ever rented a car?
Rob: I don’t know how many more driver’s licenses there are that aren’t in the breach. So I wonder what those other 50 million people didn’t do. Maybe they didn’t go to their car rental agency. They never gave their license out ’cause they just refused ’cause they’re great privacy people. I don’t know.
Beau: So what now?
Rob: There’s a universal key that anyone can use to potentially get in and that’s a problem.
Beau: I’m Beau Friedlander, and this is What The Hack?, the podcast that asks, in a world where your data is everywhere, how do you stay safe online?
Start
Beau: Whenever something big happens in the land of data compromise or breach, there’s a few usual suspects I like to talk to. One is Travis Taylor, my old buddy from the old version of “What The Hack.” I also love talking to Adam Levin because he does a ridiculously good Chicken Little routine. But another person I absolutely love talking to when the sky is falling is our very own Sarah H. Sarah, welcome back to “What The Hack.”
Sarah: Thank you very much for having me on again.
The National Desk: And new this morning, your driver’s license could be for sale on the dark web, and you have no idea. The FBI now investigating a massive data breach after a dark web operation claimed to have more than 150 million driver’s license records from folks across the US and Canada. And these aren’t just names and numbers.
Beau: Now, the ID scan to me is not the sky falling. That is the Hadron Collider having just disintegrated the whole universe of data. Am I exaggerating or am I kind of spot on?
Sarah: In one sense you would be exaggerating if it was an isolated incident. I think with the current ID verification systems in place, it’s not an isolated incident. We’re gonna see more and more of this happen. There was another major breach to happen this month at a Florida DMV where another two hundred and twenty thousand licenses were exposed. This is going to be an ongoing issue, and it’s going to affect a lot more than the initial a hundred and fifty-three million people whose IDs got compromised in that breach.
Beau: Okay, but Sarah, 200,000 or so driver’s licenses is a rounding error when you consider the ID scan breach, which was just ginormous. My theory is that this actually changes the landscape of cybersecurity and threatscape forever.
Sarah: I think that’s very possible. I think there are a lot of systems that are built specifically based on identity verification through scanning your ID or a photo of your ID. So this breach was particularly unique because it didn’t just include driver’s license numbers, it actually included front and back images of most of the driver’s licenses. So now those can be used to verify identity to get into medical systems, also unfreeze credit, different things like that, where you would expect a photo of your ID to be the wall that keeps attackers out. Now they have that information to break those systems.
Beau: Now, I know what I think is the most notable person who was breached. I mean we can take turns, but I bet you have the same person in mind. What do you think was the most notable victim of this so far?
Sarah: There were two that come to mind. There was Pete Hegseth, and there was also the assistant director of the FBI.
CBS News: Hackers have allegedly stolen 170 million US and Canadian IDs, including Pete Hegseth’s. These IDs were put up for sale for $100 a piece on a Russian cybercrime forum called Exploit. There’s about a 50% chance that your ID is up there.
Beau: This is a problem of epic proportions for me because if Pete Hegseth’s information was compromised, how does he verify himself going forward? Like, what does that look like?
Sarah: I think they’ll have to make the switch to biometric systems until all of those get compromised, and I don’t know what the next step is after that. It’s probably going to be physical pass keys.
Beau: Yeah. I think I’m on the same page. And we’re about to talk to Rob Shavell, fearless leader of DeleteMe, about all of this stuff, and I suspect he’s gonna say the same thing.
Rob
Beau: Rob Shavell, CEO of DeleteMe, maybe the most private person I know on Earth. Welcome to the show.
Rob: Thanks for having me, Beau. I highly doubt I am even close to the most private person on Earth or the most private person you know. But I do think and act a lot in the privacy realm.
Beau: I’m glad to have you here because I’m freaked out about something that I feel like you’re gonna have a lot of insight about and you wrote about it in a blog post on the DeleteMe site. I’m talking about the IDscan breach. How would you say it’s different from other breaches we’ve seen?
Rob: Well, it’s a lot of driver’s licenses.
Beau: That’s a lot. 153 million, as a matter of fact.
Rob: Yeah. I don’t know how many more driver’s licenses there are that aren’t in the breach, but it’s sort of an interesting question. There’s what? 300 million of us here in the US. Maybe my guess is that 200 million max have driver’s licenses. I’m just guesstimating. I don’t know if I’ve told you this before, Beau, I tend to be a good guesser of things. It’s just one of my qualities. Like, if somebody says, “How many marbles are in that jar?” I usually kind of get it right. So I’m guessing it’s around 200 million. So I wonder what those other 50 million people didn’t do. Maybe they didn’t go to their car rental agency. They never gave their license out ’cause they just refused ’cause they’re great privacy people. I don’t know, but it’s interesting. At any rate, how is this breach different? Well when Equifax loses our data, it’s momentous because the scale of it is so big, it covers everybody. You know, even more than 150 million. I’m just thinking back to comparing it to other huge breaches that we’ve had.
Beau: Like Social Security numbers. I mean, that was kind of all of them at one point.
Rob: Your credit score linked to your social, linked to all this stuff, right? And just all of the PII that got out there systematically with that breach was alarming, to say the least. What’s different here is that we rely on driver’s license as a proof of ID that can’t be as easily spoofed as just the numbers, just the data. And so you’re combining image, like proof that you have this government-issued thing that most of us never lose, never let go. So it becomes this more solid proof of your identity. And as we start to store, scan and store that in different ways and outside of just what the government absolutely needs, like you’re coming through immigration from a trip or something like that, we start to increase the risks of this happening. And sure enough, it finally did, and now it’s out in the wild.
Beau: What do you think the worst thing… I mean, there’s so many worst things, but what are some of the things that can happen now that these driver’s licenses are out in the wild for anyone to grab who has a working knowledge of the dark web?
Rob: Well, I think, and privacy advocates argue with identity and security advocates about this possibility, what’s happened in this breach all the time. And one of the arguments is, well, hey, as soon as we create this system that stores identity as image and everything, and verifies it with infrared and all whatever else, then if that information is breached, it enables bad actors to take fraud to the next level where they couldn’t if this information wasn’t available and wasn’t stored in the first place. So really, the worst part of this is that all of our other—and there are a lot of them—KYC and identity verification systems that sort of relied on this as the proof of license, proof of physical ownership, now they’re all able to be penetrated and breached by hackers or by anyone that wants access to fake your identity for any reason. Doesn’t have to be a cyber hacker. So I think the real problem is a lot of the more serious verification gates and sort of toll booths or doors, locks, fences, restrictions, those are all now potentially… there’s a universal key that anyone can use to potentially get in and that’s a problem.
Beau: For a second, for our listeners, I think it’s important to differentiate between verification and authentication, right? So verification is to prove who you are, and authentication is to say that person who I already proved was me is me again. I’m coming back. This driver’s license problem, it really sticks in my craw because I’m wondering, like, why are these driver’s license images being retained? After the primary usage, the need is met, why aren’t they just tossed?
Rob: It’s a great question. And in this instance, I don’t know what the use case was. A lot of times companies consider any data—and we know this at DeleteMe very well—a lot of times companies consider any data that they collect, if you look at the terms of service their lawyers wrote and everything, a copy of it is theirs, and it becomes their IP. Even if they don’t know what they want to use it for, they consider it valuable. And this is the thing that really has to change. From the lawyers to the business CEOs, to the boards of directors that run these companies, there has to be a 180-degree shift from, “Hey, this data could be valuable someday, even though once we verified the customer, we don’t really need it anymore,” to, “That data, that particular identity information is a freaking liability and could cost us a lot, could bring down the business if we lose it.”
Beau: Last year according to IBM Cost of Breach, the global average was actually down. It was down 9% to 4.4 something million dollars. That’s what it would cost if a company had a breach. Now, what I heard you just say, in not so many words, is there are a lot of companies out there who think the $4 million is worth it. It’s a tax almost on what they can make processing the entire buffalo of our identity, using every little bit for some different thing. You know, they can sell the eyeballs for this, the hair for this, it’s just… You know, there is a mentality right now with any data among companies that it has value and therefore we’re keeping it. Is that right?
Rob: That’s exactly right.
Beau: Traditional security has been something you have, something you are, and something you know. Now, deepfakes are real, so where do we stand? I know it’s not an issue for a lot of places, but where it is an issue, where there’s a high-stakes target, what do we do with that? Because I am pretty sure there’s AI capabilities now where it says, “Now pick up your phone and show it to me.”
Rob: Sure, there are. And it’s gonna make a simple act that we consider a version of reality, “Hey, find your license, show it to me on camera, wave it around,” it’s gonna make that simple act not enough. The bar is gonna continue to have to rise beyond those things. Today, it’s hard to get a deep fake to be able to do true liveliness on a real-time video call.
Beau: 100%. I think from—I haven’t seen it yet. Have you?
Rob: I have not. And there’s lag time. There’s the ability to kind of do a real-time video response. But I’m sure we’re never that far away. And so that brings me to the other way to solve this problem, which is even in some ways worse, which is, we go back to the pre-internet days where we have to be IRL in order to do a bunch of things. Now, I happen to be a customer of a bank that is, I would say, a little old school, and they happen to require a lot of transactions to be done at a branch with the people in that branch for different types of transactions, which seems crazy.
Beau: It does not if the ante’s high enough. Come on.
Rob: But I’m always saying, “Hey, this bank is crazy. I can’t do a wire transfer without coming in. I have to drive all the way to the branch. There’s none right around where I live.” But it got me thinking as I’m complaining about it, and as we think about this breach, hey, maybe they’re ahead of the game and that’s the future. We’re all gonna have to be in person more, which probably from a social perspective isn’t the worst idea, but it’s certainly gonna add a lot of friction to things.
The Incredibles/In Person Scan
Beau: Did you ever see “The Incredibles,” the animated movie, “The Incredibles”? Here’s Sarah H again. Do you remember the amount of verification he had to do to get into the lab?
Sarah: Yes, I do.
[The Incredibles Clip]
The Incredibles: Edna mode. And guest.
Beau: I’m wondering if we’ve entered the land of habeas corpus when it comes to identity verification. In other words, the only way to really do it is to show up in person.
Sarah: I think that’s a very real possibility. I was considering that this past week because of a medical thing. I had to send in a picture of my ID, and like I said, this breach specifically exposed those. So at that point, it would be safer for my information probably, but also a lot more secure to just say, “You have to come in in person and verify your identity before we can let you see all these medical records and all these other things.”
Beau: You know, back in the day when I was young, which was 18 million years ago, cameras used film, and you would drop that film off at a place, an actual physical place, and they would develop that film for you. And there were one-hour photos, famously a movie starring Robin Williams, where he becomes a stalker using the information he gets from people’s photographs. It was analog information, it was pictures. The basic idea is this, like every town had a place where you could go develop your film. The point I’m getting at is there’s probably a business model in here where inside your local pharmacy or Walmart or wherever, there’s actually a person at an actual desk and you actually have to show up and actually verify yourself in person in order to get XYZ. And they have contracts with the Social Security Administration, with TSA, with big banks, and that is gonna be how we verify. And people are gonna just get used to it. Like, just like you have to get a notary to stamp something. Like, “Ah, I gotta go to the pharmacy.” What do you think?
Sarah: It’s kind of wild when you think that we’re even talking about this, because these systems aren’t that old, and they’re already broken, and we’re already looking at a time where we’ll have to move back to in-person verification in order to stem the tide of insane data breaches.
Beau: 100%. Like, get in shape ’cause you might also have to dig a well in front of your house and get the water out yourself. I mean, it’s funny that technology has expanded at such a rapid pace that we might be looking at this kind of catastrophic implosion.
Sarah: If you can imagine it in science fiction, it probably has already come true or is going to, and that is absolutely the fact with identity verification.
C Break
Beau: Here’s the thing about the whole system of proving you’re you. It was built on the assumption that some things are just too hard to steal. I can tell you anecdotally, I was in an airport not too too long ago heading to the West Coast, and I’d forgotten my driver’s license at home. I took it out for something at home. It was laying on my desk. I was at the airport with no ID. Needed to get on that plane.
Rob: They let you on, right?
Beau: They did, with a… I just sat with TSA and they verified and authenticated me right there on the spot. Now, the reason they were able to do that is because the TSA has access to databases with other information about me, and they can see that I am who I say I am from photographs and all the rest. Now, that’s cool. I’m not a particularly sensitive person. Yeah, I am sensitive emotionally, but like, hacking me is not gonna create any great national security problem. But Pete Hegseth’s ID was in this tranche of information that was breached, and that is a national security problem. So Rob, is the cat out of the bag? I mean, is there any way of mitigating or lessening the threat that we’re all facing right now?
Rob: The cat’s never gonna be completely out of the bag. I mean, security has always been a cat and mouse game, and there’s two sides, and they’re always trying to one-up each other with respect to what they can do and how confidently they can do it, and that game will continue. It’s conceivable that AI changes it in unexpected ways, but I still believe that that game is always gonna be played. The breach happens like this. We find other tools to work around that information being out there, or we change the system in such a way that we use new technologies like ZK proofs and assertions and can get around some of these frictions in using newer technology. So no, I don’t think the cat’s completely out of the bag. I think that it’s cat and mouse. But it’s certainly changing fast and this breach is one hallmark, one big milestone in how fast it has to change.
Help Desk
Beau: The need for change is now. You can see it in this next problem set very clearly, and that’s keeping corporate help desks safe from threat actors wielding a valid ID. You know, I’m logged out, I can’t get in, I need to talk to someone about a database that I don’t have access to. Authentication systems have built this side door, standing side door called account recovery, and oftentimes ID is used to authenticate it and to verify. It seems like the lock in the side door that account recovery thing, it just became meaningfully less secure with this last breach.
Rob: Yeah, it’s one concrete example of many. Our existing systems that we’ve built around accepting driver’s licenses and other physical government-issued documents, when those get breached, those systems are now vulnerable.
Beau: What should help desks start to think about? I mean, like, you can’t just get a third-party vendor to teach better security practices. These are real world problems.
Rob: One methodology that people can fall back on is, “Hey, let’s get on a call. Prove to me you have the license. Show it to me, talk to me, let me record this.” And of course, to recover an account that’s a lot of work. It costs the company, the help desk, and the customer a lot of time and money that we didn’t have to spend before. The cost from this breach, forget about the cost the company’s gonna have to pay, forget about anything else, just the cost to the existing infrastructure could be in the many billions of dollars.
Music/Beat
Rob: I think two things are gonna come from this breach and other similar breaches that we’re bound to have because things are not changing fast enough. One is that the bar will continue to have to be raised for remote proof of identity. There’s just no other alternative that companies have, and that bar will largely mean real-time proof. So in the crypto world, for example, they’ve been doing this for a while because there’s so much fraud all over the globe with regards to Bitcoin and crypto. They often, to create an account or to verify some significant transaction with a third party, if you’re not moving money directly between wallets of your own volition, companies will require you to get on do a voice authentication, do a video authentication, and show your ID physically and all this other stuff. And it’s a big pain. They have to have a call center. You have to get online. It’s like you have to have a Zoom call just to make a transaction. But that’s the way it’s gonna have to go because with all this information floating out there that can be made fraudulent, and what—and I know deepfakes you can create, so you can kinda spoof even that stuff. What I’m saying is it’s the combination of, in biometrics they call it liveliness, I believe. You have to be able to prove that you own stuff, prove that you have stuff, prove that you’re live, prove that your fingerprints of your voice and your video match yourself. Do all these things to try to stay one step beyond what the hackers can do these days. And with AI, that’s becoming increasingly tough. So what are the implications of that first thing? It’s that it’s more of a pain in the butt to do everything, and everybody has more friction in their lives when they’re trying to accomplish things that need authentication and verification.
Transition
Beau: There’s the invisible part of the data economy, and there’s the visible parts of it. The invisible part, I’ll give you an example. I recently got a letter from a health insurer of mine, asking me to give them money from a third-party claim that I had in a very small thing that happened years ago. And it was before they were my insurer. And so I called them up and I said, “Well, you weren’t my insurer when this happened.” And they said, “Oh, okay. Our bad. Then never mind.” And I said, “No, no, not never mind. I’d like to know what program this is that your company’s actively buying data of settlements for settlements and then trying to match them to customers.” How important is it to companies’ economy, their bottom line right now to use data in that way? And how common is it that companies are actually very quietly purchasing data that helps them find money in the couch?
Rob: It’d be great if somebody researched this more, an economist or investigative journalist or a team of those people. But my answer would be these practices are super prevalent. Everybody’s buying data and trying to mine it in ways they really shouldn’t be, and consumers definitely would not be okay with. Now, that said, I think the good news is I don’t think the companies are making that much money from it. I could be wrong, but since it’s not core to their business, it’s really about trying to eke out, squeeze more juice from the fruit that they already have, their core business. And if you take away their ability to squeeze that juice, do you take away their business and kill it? No. Now, industry likes to argue that removing any freedoms around data use, data selling, data buying, will kill all these small business owners and everything. I think it’s a crock.
Beau: I mean, what you just said has just blew my mind for one reason, which is, it made me think of Waze actually, Rob. Have you ever been in a somewhat populous area where Waze will give you directions and you know they’re absolutely wrong, and if you look to see what the time difference is, it’s a minute or it’s two minutes, but it’s not much. And if you know the area well, you’ll know that if the lights are going not for you that day, Waze is wrong. Now, I suspect that some of this data selling and this ancillary business that’s happening, not core, maybe not that valuable, isn’t worth much more than the cost of breach to a big company, actually. Let’s say the cost of breach is $4 million, maybe they’re making 10. And at the end of the day, if it’s not their core business because they have $500 million in sales, is that just gonna… Eventually they will just see that it’s not worth chasing or what do you think? Or is that a bad way of looking at it?
Rob: I mean, economists would argue markets are rational, right? I don’t think that’s true. I think there’s all kinds of calculations that people make that are effectively mistakes if you looked at it really objectively. It’s tough to say. It’s really tough to say what we should do, or what any country should implement to try to create the right incentives for companies to act more responsibly when it comes to the data they hold, the data they buy, the data they share. It’s very difficult. I suspect 20 years from now, much more evolved and intelligent human beings will look back at us and go, “You guys had no clue what in the hell you were doing in the 2020s.”
C Break
Beau: How does DeleteMe fit into that part of this? Like the fact that consumers find themselves in this world where not only is their driver’s license being leaked, but that’s just a really visible version of all of their data that’s being leaked all the time and resold and resold and used, and criminals can use that stuff.
Rob: Consumers are really at the mercy of the politics and the wins in their government, frankly. Because alone, consumers don’t have any power to affect change, especially in this day and age when data holders and big data companies and big tech wields more and more power and has infiltrated government. And so the consumer’s voice and clout has been weakened steadily over the last three, four, five decades. I mean, all the way going back to when Ralph Nader and so on was fading out of the social milieu and the gestalt. So I think, should consumers bear the cost of all this stuff? No. Will they organize and vote to stop it? In some cases, we see evidence of that. Eighty-eight percent of people voted for the California Consumer Privacy Act, the first one, ten years ago. And since then more than a dozen privacy laws have been passed, and we continue to pass more of them, that have different kinds of ways of enforcing penalties and holding companies accountable. And is it a series of small steps in a much bigger sea of data and data privacy concerns? Possibly. But it is indicative that governments can step in and give consumers power that they didn’t have before. And I think that’s an important thing to remember, as we get swept into this post-AI data processing and data breach era. Nobody really knows what things are gonna look like, and it’s important to make sure that consumers have rights. We are not very evolved in the way that we think about this, the way that we act, the way that we handle it, even the solutions we’re considering. It’s not evolved, it’s not mature, it’s not well thought out. There’s way more problems than there are solutions.
Beau: You’ve probably heard this, it’s an old example of how to figure out a mission statement for a company. There’s an example of a company that made bullwhips in the 19th century, and as the car took over from beasts of burden for transport, that company faced extinction. They changed their mission statement. They adopted one, and it was, “We get you where you’re going.” Now, they stopped making bullwhips and started making transmissions for cars. Same company, same mission: “We get you where you’re going.” DeleteMe’s focus is privacy, giving people agency over their private lives and their data. What does privacy look like going forward? Because the more that we talk about this, the more I feel like you’re right. We’re kind of in the sticks and stones part of the war on privacy. What’s the future look like? Are there gonna be kiosks in everyone’s hometown of the company where you just go and in person and authenticate yourself?
Rob: The easy answer is nobody knows. If we knew, then by definition we’d be more evolved and more mature than we’re claiming we are. And I do agree with you. We’re in the stick and stone age here. What is the future of agency with regards to your data and privacy look like? We’re trying to figure that out every day. I mean, every year at DeleteMe, we meet, we collaborate, we work with researchers, we work with our customers, we work with companies, and we try to figure out, hey, what’s around that next corner? What can we get ahead of, and what can we help our customers with? And not just directly, but also through law. I’m headed to DC tomorrow to participate in a law and privacy conference where these topics come up regularly. And the people leading different agencies in the government and people in industry responsible for privacy are all talking. They’re talking, comparing the US and Europe and other things, and they’re all talking about these issues, trying to figure out, hey, what’s next? And obviously, AI is a big, and has been an increasing part of that conversation. But like I said, even though there’s lots of smart people around these tables much smarter than me, there’s a lack of maturity in the solutions, and the ways that people are thinking about it. Beyond the nice clothing and the dress shirts in DC, there’s still a lot of immaturity. So I don’t know what it looks like, but I can tell you that at DeleteMe we have certain mission and vision beliefs, core beliefs that we think cut pretty close to what living in a democracy and a free society should incorporate. And you should, as a person, own your identity, and that should mean certain things. And you should have the right to be treated for that identity and yourself to be free, to make choices, to be treated fairly. Those definitions are important and they’re evolving. And so it’s a bigger topic than we have time for, but I think a very interesting one and hopefully one that more people become interested enough in to participate and have a voice in because I think it’s important, not just from a price discrimination standpoint, “Hey, I paid more than the next guy. I’m upset,” but for much bigger issues that are gonna affect all of us in our near-term lives.
Beau: I don’t think that if you go down to DC and you persuade all of Congress to clamp down on data, that DeleteMe stops being a company, because DeleteMe is fundamentally a privacy company. And so I am kind of curious to know, like, privacy isn’t gonna go away when, for instance, People Search maybe is stopped, is it?
Rob: No, not at all. And we think that a much bigger issue than people search and data brokers is how are companies you do business with selling your data out the back door? How are they aggregating data they buy with your data, and are they treating your data fairly? And that’s a… they talk about the tip of the iceberg. Those issues are the iceberg under the waterline.
Beau: They’re the iceberg under the… I mean, and that gets to the question of like to me, there are a lot of companies out there, and we’ve talked about some of them, or I have, that engage in what I would call shadow data brokering. And is that kind of where we’re pointed at? I know that now we can focus on companies that are selling our data and stop that. What does it look like to you?
Rob: Yeah. I mean, it’s a good term for it. I think that’s obvious. I mean, companies are doing it all over the place, and I think they’re abusing all kinds of trust they have with their customers. I think what’s non-obvious is how is AI going to change and accelerate both the rewards and the risks for companies doing that?
Beau: Oh, I guarantee you that letter I got from the insurance company about this settlement from years ago was found by an AI agent. An agent that was said, “Find money in the couch. Where is it? What could we do?” Well, your privacy policy says that if you have a third-party settlement, we get to recoup anything that you didn’t pay. So, you got a million dollars for that thing, and oh my gosh, your treatment cost a million bucks? Give us the million dollars that you already spent on a boat. So…
Music/Beat/Back to Sarah
Beau: All of that, the laws, the rights, the fight over who gets to hold this stuff, it’s the long game. But right now, today, what matters is what’s actually sitting in this specific breach, possibly in front of a specific threat actor.
Sarah: Not all of the records exposed addresses.
Beau: Here’s Sarah again.
Sarah: So some of the records exposed address and everything else. Some of them had certain things redacted. Some of them had addresses unavailable. Pete Hegseth was one that had addresses unavailable.
Beau: Was that, like, on the ID itself?
Sarah: They have like a record that shares the information that they found on the IDs and elsewhere. So it was not just IDs. It’s called the ID scan breach, but there was also medical records and other information that was exposed. So it was much fuller than just front and back picture of an ID. And among the IDs, not all of them had front and back pictures, not all of them had home addresses. So that’s where the idea of cross-referencing comes in. Cross-referencing with previous breaches, cross-referencing with data brokers, that’s where that becomes dangerous. One of the main things that the data economy does and the data brokers do is collect information that otherwise would be difficult to find and package it in a way that is very easy to find. So anybody can take that and cross-reference it with information exposed in a breach like ID scan and fill in anything that’s missing. So your home address, your age, your date of birth, anything that’s missing or redacted in a breach or anonymized, they can then cross-reference that, de-anonymize anything, add addresses, and fit those with the names and the photographs. There’s really no limit to how easy it is to fill in the rest of the information and then have a fuller package and a fuller picture of all these profiles to use for scams, identity theft, and any other cybercrime you can imagine online.
Beau: Yeah, and in the verification and authentication process, those people search sites are going to give you the answers to a lot of the security questions, including addresses that are associated with a person, family members, and past jobs. So there’s really no shortage of information when it comes to putting together an attack plan. And the attack plan is this: call up the help desk or call up whoever’s in charge of verification and authentication, say that you can’t get into your account, and have all that information in front of you. It’s as simple as that.
Sarah: Absolutely.
Beau: There’s no locks on the doors anymore. I believe that the ID scan breach and the other breaches that we’re starting to hear about, what they mean, if a breach can mean something, if it could cause something to happen on a manifestation of a thing—all the locks on all the doors just melted. They just disappeared.
TFS
Beau: Okay, it’s time for the tinfoil swan, our paranoid takeaway to keep you safe on and offline. This week it’s pretty simple. Well, there’s two things you can do. So personally, next time someone asks to take a scan of your ID, ask them if they really need to. If it’s not enough to just show them, “Here’s my ID. See? See?” And leave it at that. Some places will let you do it. Some places will not let you do it. If they don’t let you do it, ask them how long that image is going to be retained and who’s retaining it. And if they don’t know, say, “Well, I’d prefer not to do this then, and I would like you to just visually inspect my ID,” and see if you can get around it. Some places will relent once they understand that you have a legitimate reason for saying no. Now, the next thing that you can do is at work. You can actually be a leader, if your workplace is not paying attention to this. So I want you to talk to IT, and I want you, if you have a CISO at your company, I want you to send them, and they’re nice, I want you to send them a note and just say, “The ID scan breach has me concerned about the way that we verify. You know, I know that sometimes people can hold up an ID in front of a webcam, and that will be enough. I would like to suggest either you do it in person or it’s accompanied by video,” which can also be faked, but it’s much harder. It would be a lot of work to do it with your actual ID. So yeah, I want you to go to your IT or CISO and say, “The ID scan thing really concerns me. Does it create vulnerability here at work?” Just ask the question. That’s all you need to do. And if you’re interested, there is actually a lot of “is this a scam” content on the DeleteMe site, which you can check out. It really is a rabbit hole worth going down. Because there are certain things that aren’t scams that still kinda suck. They’re not great, but they’re perfectly legal. But there’s a lot of things that are perfectly legal in this great land of ours that maybe we would be better off if they weren’t? Okay, that’s it for this week. See you next week. Stay safe.
Learn More:
- Read our article that covers the IDScan.net breach investigation and its implications.
- Listen to more from What the Hack.
- Find out how to remove your personal information from the internet with DeleteMe.
Our privacy advisors:
- Continuously find and remove your sensitive data online
- Stop companies from selling your data – all year long
- Have removed 35M+ records
of personal data from the web
news?
Exclusive Listener Offer
What The Hack brings you the stories and insights about digital privacy. DeleteMe is our premium privacy service that removes you from more than 750 data brokers like Whitepages, Spokeo, BeenVerified, plus many more.
As a WTH listener, get an exclusive 20% off any plan with code: WTH.



