Why Your Driver’s License Keeps Ending Up In Data Breaches, And What Could Fix It
Key Takeaways
- A dark-web service is reportedly offering more than 153 million driver’s license records tied to an alleged IDScan.net breach now under FBI investigation.
- Coin Center’s Laz Pieper argues centralized identity databases function as “honeypots,” citing FTC data showing fraud complaints rose from about 860,000 in 2004 to 6.47 million in 2024.
- Pieper proposes privacy-preserving verification that proves specific facts, like age eligibility, without handing over full documents to centralized databases.
A dark-web service is reportedly offering more than 153 million American and Canadian driver’s license records for sale, and the FBI is investigating an apparent data breach tied to identity-verification provider IDScan.net.
The incident has renewed a long-running argument from privacy researchers: mandatory identity-collection rules meant to prevent fraud may be creating the very data troves criminals are stealing. Laz Pieper, research director at Coin Center, argues in a new column that the fix is not abolishing identity verification, but redesigning how it works.
A Breach That Fits A Pattern
IDScan.net provides hardware and software that scans, parses and authenticates identification documents for car-rental agencies, banks, hotels, casinos, cannabis dispensaries and other businesses.
Its systems can capture front-and-back images of an ID, extract personal information, compare a photo against a selfie, and store the resulting data in a cloud portal that businesses can access after authentication.
Pieper’s column places the reported breach in a longer history of large-scale identity-data compromises.
In 2017, credit reporting agency Equifax suffered a cyberattack that compromised sensitive personal information belonging to nearly 148 million Americans, close to 45% of the U.S. population at the time. The U.S. Department of Justice alleged in a 2020 indictment that members of China’s People’s Liberation Army were behind that attack.
IDScan is not itself a financial institution and is not legally required to retain personally identifiable information; it functions as a vendor that lets other businesses run identity checks. According to Pieper:
“Businesses using a shared vendor’s cloud infrastructure effectively concentrate their customers’ sensitive data into a single, more attractive target, regardless of what each individual business’s own security looks like.”
The Case That Verification Rules Aren’t Working As Intended
Financial institutions are required under the Bank Secrecy Act and its associated regulations to collect and retain personally identifiable information when onboarding new customers, a requirement meant to combat money laundering and fraud.
Pieper describes the resulting centralized databases as “honeypots,” pools of sensitive data valuable enough to draw sustained attacks from criminals and state-linked hackers alike.
To support his argument that these requirements have not delivered the intended protection, Pieper cites Federal Trade Commission data showing the agency’s consumer complaint database received 6.47 million reports of fraud, identity theft and related problems in 2024, up from approximately 860,000 in 2004.
He also cites an industry estimate putting global illicit financial activity at $4.4 trillion in the most recent year measured. Pieper argues:
“Verification methods added on top of ID collection, including one-time codes sent by text or email and biometric checks, have provided only limited additional protection, noting that codes remain vulnerable to phishing and that biometric systems face new pressure from advances in artificial intelligence.”
A Different Approach: Prove Only What’s Needed
Pieper’s central proposal is a shift toward privacy-preserving identity verification, technology that would let a person prove a specific fact, such as being above a minimum age or being eligible for a given service, without handing over a complete copy of underlying documents like a driver’s license or passport.
Under that model, the sensitive source data would stay under the individual’s control rather than sitting in a third party’s centralized database.
“Federal regulators should give institutions room to test these systems as they mature, and Congress should scale back information-collection and retention requirements as privacy-preserving alternatives become viable.”
Pieper’s position is that anti-fraud verification retains real value, but does not require creating a permanent, centralized dossier that becomes a target for theft.
Where Policy Could Go Next
Pieper takes a more pointed position on emerging policy trends, specifically age-verification mandates for online platforms and software, which he argues extend identity-collection requirements into new areas without a matching security benefit.
He contends these mandates expand the same honeypot dynamic to additional services while failing to reliably protect the children they are meant to shield. This is a position that reflects Coin Center’s broader advocacy stance on digital privacy rather than a settled empirical finding.
Pieper’s broader argument, that avoiding unnecessary data collection is itself a security strategy, is presented as his own policy recommendation rather than as an established regulatory direction.
Whether privacy-preserving verification technology matures quickly enough to influence upcoming rulemaking, and whether federal regulators and Congress act on his specific proposals, remains an open question rather than a settled outcome.