Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- > Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”by tgrowazay
- Ooh I thought they sold that many fake ones lol. I know fake IDs are a big thing in the US because of the really high drinking age (were I'm from it was 16). But even then it's a lot.
But no it's about leaked data. That wasn't very clear from the title.
by wolvoleo - Startup idea for these darknet guys, use AI to select the best matching face in your collection of IDs to your customers face, so you can generate them a fairly realistic fake ID.
- It’s interesting how quickly this story dropped in the rankings. It’s a highly relevant story, that is likely to spawn more notice.
Ars already has a story about the same breach: https://arstechnica.com/security/2026/09/my-drivers-license-...
Is this story being flagged? If so, why?
- The main question to government is:
1. You already know who everyone is. By definition identification as an individual is by government.
2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?
3. Why is that evidence not provided directly, but as a confirmation from the government service ("Yes, this person is over 18", not "Yes, this person is 37")?
Governments need to protect the public, not allow businesses open slather on collecting PII.
by rswail - One can argue, this would be an unintentional tracking of the population by governmentby navigate8310
- We can't do any of that because it is forward-thinking and doesn't involve clear-cutting a rainforest to make the stacks of paperwork that are otherwise required to fill out forms in triplicate, run everything through 17 different departments, and ensure an army of bereaucrats have something to do with their day.by Hobadee
- This is already present today in California Driver's licenses in your Apple Wallet (mDL).
When you scan your driver's license at a compatible reader, you're given a notice of what information is being requested and the ability to share it (or not).
It can also request some derived attribute (is this person above the age of 21?) instead of the actual data field itself.
Most of this is from ISO/IEC 18013-5
by acchow - This is exactly the way its being implemented in EU (Yes, this person is over 18").
European Digital Identity Wallet (EUDI Wallet) framework established under the eIDAS 2.0 regulation (Regulation (EU) 2024/1183)
by vincnetas - > Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?
Generally speaking, it's the narrative of a pushback on a "national id".
Many countries already have this place. Estonia has the Digital ID provided by government[0]. Nordic countries use BankID, which is a form of KYC that is backed by banks (you prove your identity to the bank, the bank issues a bank id - usually back by certificate[s], and you login with this to services[1][2]). Finland is the outlier, here, with their own service[3].
0 - https://e-estonia.com/service/estonian-e-identity/id-card/
1 - https://www.bankid.com/en/individuals/get-bankid
2 - https://bankid.no/en/how-to-get-bankid
3 - https://www.suomi.fi/instructions-and-support/identification...
by 2legit2quit - What even would be the fix for this? 153m people need new license asap and id verification systems need to block the stolen ones? Also what are some of the bad things this could cause: a risk malicious actors open verified accounts in their name, ability to vote and travel under stolen id, what else?by shireboy
- So an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.by fishfasell
- Your ID and PII was likely already on the black market, the only question is accessibility and price. You can't exactly advertise on Reddit or sell to every two-bit identity thief and not expect heat.by wahern
- From the article, it's some national-chain hotels, car rentals, casinos, dispensaries, and a couple maybes like if you bought alcohol at Target and they scanned your ID or sent something via FedEx that required an ID scan. Your ID might be scanned and in there multiple times.by 3RTB297
- 153 million puts them at roughly 1/2 of all Americans.
Naturally these "identity verification" companies are a joke that have no security and gladly piss our PII into the wind without taking the job seriously.
by 3eb7988a1663 - I don’t know why the government allows websites and these craps to collect sensitive information like driver’s licenses and Social Security numbers. They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.by cute_boi
- Because the word "simply" isn't. Every time a programmer says "just" or "simply" about someone else's system, it's a lie.by megagpt5
- Because physical business are also allowed to collect this information.by charcircuit
- You've already answered your own question. They don't provide an API with zero trust. Many services are legally required to collect the information anyway. Telehealth billing through insurance, for example, require it for the old "red flag rule" intended to prevent insurance and Medicaid fraud.
So, these providers all do the only thing they can short of going out of business: they use third party providers of identity verification.
by zdragnar - > They could simply provide an API that allows websites to verify someone’s identity using a zero-trust approach without exposing the actual documents.
Because then that website would get compromised and lose the data on 350 million people instead of 153.
Worse, it would lower the friction to surveillance companies demanding government ID in order to use the internet.
People throw around terms like "zero trust" like that could actually do something here. If you create an API that banks or employers could use for extending credit or payroll taxes then it will inherently disclose your social security number to the corporation, since they need it to file their forms. But create that API and you'll have every ad network on the internet making calls to it so they can use your social security number as a tracking ID to correlate everything you do across different services. And, of course, recording all of that data to get breached when their security sucks.
Using government ID on the internet should simply be banned. 99% of things shouldn't require government ID to begin with and the 1% that do should always be done in person.
by AnthonyMouse - In Germany, everyone's national ID – which everyone has – has a NFC chip to securely identify you digitally. It was introduced 15 years ago and can be read by any smartphone. (It does use trusted third parties which only share the requested data though.)
You'd think that 80 million people from a rich first world country would be enough of a market to use this.
No, we're showing our faces and waving our IDs in front of the camera while an Indian half-asses the identity check like everyone else.
by stephbook - > vendors who collect this sensitive data need to be held to a higher standard.
They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).
One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses.
The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.
- GDPR does not prevent leaks, only may punish someone afterwards. A lot of the upcoming EU regulations are to collect more data on you because of the age checks. German and Spanish prime ministers have publicly called for verifying all Internet users and end anonymity,by miohtama
- > They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there
As an EU citizen and resident I strongly recommend you not take EU privacy controls seriously. The GDPR functions well as a means of tax collection, but it really doesn't work all that well as something that actually protects people's privacy.
- Worth noting this dynamic when people overgeneralize “local government good, federal government bad”, a tendency that has been present and growing for at least 50 years.
The theory that local government is more accountable and responsive seems to be pretty deeply broken, what actually seems to happen is that localities lack a critical mass of attention and focus for real responsiveness and accountability.
Or the American character in general does.
by wwweston - > They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there
Often it's straight up the same companies - a Brit's PII is held by Experian, Equifax and Transunion just like an American's is.
And while the rules are strict and complicated enough to be very inconvenient for anyone who tries to follow them to the letter, the fines for even the worst fuck-ups are trivial. We're talking a $5 billion company handing 15 million people's credit reports to hackers, and getting fined $15 million.
by michaelt - Ahem
Some Interrail travellers told to cancel passports as hacked data posted online
https://www.theguardian.com/technology/2026/apr/23/some-inte...
- One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera.
They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.
by trollbridge - s/retained/leaked/by latchkey
- Yeah, the irony is that every extra signal added to make verification "safer" also becomes another extremely valuable thing to steal when the verifier gets breachedby veunes