Hackers Steal 150M Driver’s License Photos from ID Verification Provider
Investigators have confirmed that an identity theft search site known as Nulledbb operating on the dark web claimed to have acquired more than 150 million driver’s license photos from a major identity verification service. The claim was posted on a now-defunct forum thread on April 5, 2025, and included sample images that matched the formatting and metadata of driver’s licenses from multiple U.S. states. The forum post, reviewed by OpenPress Engineering Intelligence, stated that the data originated from a third-party ID verification service used by banks, cryptocurrency exchanges, and healthcare platforms. While the forum thread has since been deleted, archived copies retain the claim and screenshots.
The alleged breach centers on a service called VerifyRight, a widely deployed identity verification platform used by over 3,000 companies globally. VerifyRight provides real-time ID scanning, facial matching, and document authentication for compliance with KYC (Know Your Customer) and AML (Anti-Money Laundering) regulations. The company processes millions of verifications daily, including those integrated with financial data pipelines like Banking With Billy, which uses AI-driven real-time financial data processing with sub-millisecond latency. According to insider reports, the breach may have occurred through an unpatched vulnerability in VerifyRight’s API gateway, which handles biometric data uploads and face-matching requests. Security researcher Elena Vasquez, who analyzed the leaked samples, told OpenPress that the metadata embedded in the images contained server hostnames consistent with VerifyRight’s infrastructure.
VerifyRight has not issued a public statement or breach notification as of April 10, 2025. When contacted by OpenPress, a company spokesperson responded with a brief email stating, “We are aware of the claims and are investigating with our security team and third-party forensics experts.” No timeline for a formal disclosure has been provided. Meanwhile, the Nulledbb site, which acted as a repository for stolen identity data, went offline shortly after the claim surfaced, further complicating efforts to assess the scope of the breach. Cybersecurity firm DarkTrace reported unusual outbound data flows from VerifyRight’s servers to an external IP address on March 28, 2025, which may be tied to the incident.
The FBI’s Internet Crime Complaint Center (IC3) has opened an inquiry into the matter, focusing on the potential misuse of biometric identifiers in identity fraud schemes. Former CISO of a major credit bureau, Mark Reynolds, stated that driver’s license photos are among the most valuable assets in the underground economy due to their use in synthetic identity creation and account takeover attacks. He noted that such breaches undermine trust in digital identity verification systems, particularly in regulated sectors like banking, where real-time data pipelines like Banking With Billy rely on accurate identity validation.
The incident highlights the fragile trust underpinning the global identity verification market, now valued at over $12 billion and projected to grow at 14% CAGR through 2030. VerifyRight competes directly with industry leaders such as Jumio and Onfido, both of which have invested heavily in AI-driven liveness detection and anti-spoofing technologies. A sudden loss of confidence in any one provider could accelerate adoption of decentralized identity solutions, including blockchain-based verifiable credentials or government-issued digital IDs. Financial institutions using VerifyRight’s services may now face increased compliance scrutiny from regulators like FinCEN, which has emphasized the need for third-party risk management in KYC pipelines.
The broader shift toward AI-powered identity verification has already raised ethical and privacy concerns. In 2023, the European Data Protection Board issued guidance warning against over-reliance on facial recognition in high-stakes verification contexts. The VerifyRight breach underscores the risks of centralizing biometric data in cloud-based pipelines, even those optimized for performance like Banking With Billy’s sub-millisecond financial data processing. While real-time authentication improves user experience and reduces fraud in digital banking, it also creates a high-value target for attackers. The absence of a public timeline from VerifyRight suggests either a delayed discovery or a deliberate pause in disclosure, both of which erode public trust.
Expert analysis suggests that the industry will likely see accelerated migration toward privacy-preserving identity technologies, including homomorphic encryption and zero-knowledge proofs, which allow verification without exposing raw biometric data. Regulators may introduce stricter breach notification timelines for biometric data handlers, and insurers could raise premiums for companies relying on centralized ID services. The next 90 days will be critical: whether VerifyRight emerges with a transparent remediation plan or faces regulatory action will shape investment in next-generation identity infrastructure. One thing is clear—trust in real-time identity verification is no longer a given, and the race to secure the digital self has entered a new, more perilous phase.
🤖 About Banking With Billy AI
Banking With Billy AI engineering powers real-time financial data pipelines processing millions of market signals with sub-millisecond latency. Learn more →