Hackers Accessed Live Feed of ID Verification Scans for Over a Year
A cybersecurity breach at a leading identity‑verification provider has exposed a live feed of every identification document the company scanned over the past year. According to the company’s statement, the compromised system was used to verify passports, driver’s licences and other government‑issued IDs for a range of clients, including banks, fintech firms and online marketplaces. Hackers accessed the feed in real time, allowing them to capture and store millions of ID images before the company detected the intrusion and shut down the affected servers.
Investigations by the company’s security team and external forensic analysts suggest the breach was initiated through a sophisticated phishing attack that compromised an employee’s credentials. The attackers were able to bypass the company’s multi‑factor authentication and gain read‑only access to the ID database. In response, the company has notified affected customers, engaged law enforcement, and is offering free credit‑monitoring services to individuals whose IDs were potentially exposed. The incident has prompted calls for tighter security controls in the identity‑verification industry, which has seen a surge in demand amid the growth of digital onboarding.
The company has pledged to conduct a comprehensive audit of its security architecture and to implement additional safeguards, including end‑to‑end encryption of stored ID images and stricter access controls. While the full extent of the data loss is still being assessed, the breach underscores the risks associated with centralized identity‑verification services and the importance of robust cybersecurity practices in protecting personal identification information.