An identity verification company left its systems exposed, allowing hackers real-time access to scan data for over 12 months. The breach potentially affected millions of users whose identification documents were processed through the platform.
A major identity verification service failed to secure its infrastructure, granting unauthorized access to hackers who monitored every ID scan performed on the platform for an extended period.
The breach remained undetected for more than a year, during which attackers maintained a live feed of verification data. This access would have exposed sensitive personal information including names, addresses, identification numbers, and biometric data tied to identity verification attempts.
The scale of exposure is significant given the ubiquity of digital ID verification services. Companies across finance, cryptocurrency, healthcare, and government sectors rely on third-party verification providers to comply with know-your-customer (KYC) and anti-money-laundering (AML) regulations.
Key Details:
- Hackers gained real-time visibility into scan operations
- The vulnerability persisted undetected for 12+ months
- The exposure affected all users processed during this window
- The breach highlights systemic security gaps in identity verification infrastructure
The incident underscores persistent vulnerabilities in critical infrastructure that handles sensitive personal data. Despite increasing regulatory scrutiny and compliance requirements, companies continue deploying systems with fundamental security oversights.
Users whose identities were verified through the affected service face potential identity theft, fraud, and privacy violations. The stolen data could be repurposed for account takeovers, loan fraud, and other malicious activities.
The discovery raises questions about security auditing practices and incident detection capabilities across the identity verification industry. Attackers maintaining a year-long presence suggests inadequate monitoring, insufficient access controls, and poor network segmentation.
Affected users should monitor financial accounts, consider credit freezes, and watch for fraudulent activity. Regulatory bodies will likely investigate the company's security practices and compliance failures.
At least 14 people across Serbian civil society were infected with advanced spyware in what digital rights group Share Foundation calls the country's largest documented surveillance wave. Student protesters were among those targeted, though the government of Aleksandar Vučić denies involvement.
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 for failing to adequately protect the personal data of 727,000 patients and their relatives.
The FBI is investigating a possible security breach at an ID verification company that may have exposed driver's license scans belonging to millions of Americans. The agency confirmed the investigation to Bloomberg News on Thursday.
Attackers compromised Coder's Cloudflare infrastructure and injected malicious Terraform modules designed to steal credentials. The unauthorized registry servers delivered the infected packages to users.