Security/ identity-verification · data-breach · security · privacy

ID Verification Firm Left a Live ID Scan Feed Exposed for a Year

An ID verification company exposed a live feed of every scanned document to attackers for over a year, proof that identity checks are honeypots too.

An identity verification company spent more than a year unknowingly streaming every ID it scanned straight to hackers.

The company runs the kind of service other businesses lean on to confirm a user is who they say they are, checking uploaded passports, driver's licenses, and other government-issued documents. A security flaw gave outside attackers a live feed of that verification process, letting them watch documents pass through as people uploaded them. The exposure went unnoticed for more than a year, meaning the leak kept running the entire time. It's not clear how the flaw was discovered or how many documents were exposed before it was closed.

This is the core problem with identity verification as an industry: the tool built to stop fraud becomes a single, concentrated target for it. A breach like this doesn't hand attackers a password to reset, it hands them the physical documents underpinning someone's entire identity, the kind of material that fuels loan fraud, account takeovers, and worse.

Companies keep asking users to upload scans of their most sensitive documents to prove they're trustworthy, while offering little proof they can be trusted with what they collect.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →