Massive Identity Data Breach Tied to Verification Services
The FBI is probing a service that sold 153 million-plus driver's licenses (49529621), many linked to marijuana dispensary identity verification. This is a direct consequence of an industry practice: collecting and storing sensitive government ID documents to comply with regulations, then failing to protect that data. Commenters immediately called for a government-provided API that would let websites verify identity without holding the actual documents.
The pattern is familiar. Companies collect sensitive data because regulation or business need requires it, store it insecurely or with third parties, and then that data gets exfiltrated and sold. The difference here is the scale and the sensitivity: driver's license numbers, tied to real names and addresses, are the foundation of most offline identity verification.
The concrete ask from the thread is smart: build an API that returns a boolean, 'yes this person is over 21,' without exposing the underlying document. Estonia has done something like this for years. The US hasn't. Until it does, every cannabis retailer and adult content platform is a breach waiting to happen.
So what?
If your product requires any form of identity verification, you need to audit what data you're actually holding and who you're sharing it with. Third-party KYC providers are a systemic risk, not a solution. The political and legal exposure from holding this data is growing faster than the convenience is worth.