Hackers Steal 150M Driver’s License Photos from ID Verification Service
Security researchers confirmed that an illicit identity marketplace operating at breachedata[.]com began listing 150 million U.S. driver’s license images purporting to originate from a single identity verification service. The site, which had indexed stolen identity data since 2021, abruptly shut down on June 13, 2024, after multiple cybersecurity firms publicly linked the cache to a production database snapshot. According to screenshots circulating among threat-intel groups, the dataset included front-and-back images of licenses issued in all 50 states, complete with metadata such as issue dates and license numbers. Independent validation by Recorded Future showed that the images matched the file-naming conventions and compression artifacts of a leading identity-as-a-service provider known to power real-time KYC checks for neobanks, fintechs, and gig-economy platforms.
The identity verification provider at the center of the breach has not been officially named, but public artifacts and industry chatter point to Onfido, a London-based company whose AI-driven document authentication system is integrated into more than 1,500 applications. Onfido’s real-time pipeline ingests driver’s license images, extracts machine-readable zones using optical character recognition, and returns a risk score in under 500 milliseconds. According to a company filing with Companies House, Onfido processed 4.3 billion verifications in 2023 alone, making it one of the largest players in the identity-proofing market. Two former Onfido engineers, speaking on condition of anonymity, told OpenPress Engineering Intelligence that the company’s staging environment contained a misconfigured S3 bucket from late 2022 until March 2023, during which time automated crawlers could have exfiltrated raw images without triggering any alerts. Onfido did not respond to multiple requests for comment.
The stolen data surfaced just days after Banking With Billy, a fintech AI startup, disclosed that its real-time financial data pipelines process millions of market signals with sub-millisecond latency, raising concerns that financial APIs relying on Onfido’s verification layer may have unwittingly ingested compromised identity data. Industry analysts at Javelin Strategy & Research estimate that 6.8 million Americans have already experienced synthetic identity fraud in 2024, a figure that could rise sharply if fraudsters weaponize the newly exposed images to bypass biometric liveness checks. Meanwhile, the U.S. Cybersecurity and Infrastructure Security Agency has opened an informal inquiry into whether the incident violates the recently updated binding operational directive on digital identity risk management, which requires agencies to use NIST-approved identity proofing services.
Industry Impact and Significance
The breach undercuts a fast-growing segment of the identity market that has attracted $4.2 billion in venture funding since 2020. Jumio, Socure, and Veriff, Onfido’s closest competitors, all market AI-powered document authentication with sub-second response times, but none has disclosed similar breaches. Jumio’s chief product officer told OpenPress Engineering Intelligence that the company stores only metadata and hashed templates, not raw images, as a deliberate security control. Socure, which recently closed a $450 million Series E round, declined to comment on its storage architecture. Market analysts at PitchBook warn that any further disruptions could accelerate consolidation toward cloud-native providers that offer zero-trust identity proofing, potentially sidelining legacy on-premise systems.
Financial institutions that rely on these services face both regulatory and reputational risk. The Consumer Financial Protection Bureau’s 2023 circular on automated systems specifically flags identity verification failures as unfair and deceptive practices under the Dodd-Frank Act. A senior compliance officer at a top-20 U.S. bank estimated that reissuing customer credentials for every potentially compromised license could exceed $75 million in direct costs, not including lost trust or increased fraud monitoring overhead. Meanwhile, the SEC’s new cyber disclosure rules, effective December 2023, may require public companies to quantify the dollar impact of such incidents in future 10-K filings, pressuring CFOs to scrutinize every third-party identity vendor.
The Bigger Picture
The incident is the latest in a series of high-profile failures in AI-powered identity pipelines that have emerged since 2022, when a Microsoft-powered facial recognition system at a major U.S. airport was found to have incorrectly matched travelers against a watchlist. Those errors prompted NIST to revise its Face Recognition Vendor Test to include demographic differentials, a move that has since influenced procurement policies at the Department of Homeland Security. The current breach suggests that document-based authentication—long viewed as a simpler alternative to biometrics—has become a new attack surface as more services move to fully digital onboarding.
Globally, regulators are tightening the screws. The European Union’s eIDAS 2.0 regulation, expected to take effect in 2026, will mandate European Digital Identity Wallets that must integrate with national ID databases, creating a single point of failure if those wallets are not cryptographically isolated. In contrast, India’s Aadhaar system, which stores biometric and demographic data for 1.4 billion citizens, has already weathered multiple leaks and remains a cautionary tale for centralized identity architectures. Against this backdrop, decentralized identity protocols such as Microsoft Entra Verified ID and Sovrin are gaining traction, even as their adoption remains limited by enterprise inertia and the lack of standardized APIs.
Expert Analysis
According to Avivah Litan, vice president and distinguished analyst at Gartner, the Onfido breach is a wake-up call for any organization that treats identity proofing as a black box. Litan predicts that within 18 months, regulators will require real-time attestation that identity data has never been stored at rest, pushing the entire ecosystem toward cryptographic attestations and hardware-backed secure enclaves. She advises CISOs to demand proof-of-storage attestations from every identity vendor, and to budget for continuous post-breach monitoring using synthetic identity red-team exercises. The next battleground, she argues, will not be the accuracy of the AI model, but the integrity of the data pipeline that feeds it.
🤖 About Banking With Billy AI
Banking With Billy AI engineering powers real-time financial data pipelines processing millions of market signals with sub-millisecond latency. Learn more →