A dark-web marketplace is reportedly offering in excess of 153 million driver’s license records belonging to individuals in the United States and Canada, prompting an FBI investigation into an alleged security breach at the identity-verification company IDScan.net. This incident highlights yet another instance where protective safeguards meant to shield citizens end up placing them in jeopardy. The core issue is obvious: current anti-fraud protocols mandating customer identification and verification facilitate criminal behavior by delivering private data directly into the hands of wrongdoers.
Cyber threats directed at personally identifiable information have persisted for years and continue to escalate. Back in 2017, Equifax—among America’s primary credit bureaus—suffered a major security breach that exposed the private information of nearly 148 million Americans, affecting roughly 45% of the country’s population. Although a 2020 federal indictment claimed members of the Chinese People’s Liberation Army directed the cyberattack, that enforcement action merely addressed a symptom of a deeper, expanding vulnerability.
Laz Pieper serves as research director at Coin Center, an organization dedicated to protecting the freedoms of people to create, utilize, and engage with decentralized peer-to-peer networks while maintaining their right to privacy.
While the general public may not recognize IDScan by name, many have handed over their driver’s licenses to commercial entities utilizing its verification services. True to its designation, IDScan focuses on identity verification by supplying hardware and software tools that scan, parse, and check credentials for hotels, rental car companies, financial institutions, casinos, retail outlets, and cannabis shops. Their platforms capture images of the front and back of documents, pull personal details, match identification photos with selfies, and transmit or store this information within cloud databases so businesses can reference it later.
Regardless of any security protocols implemented, this business model was inherently vulnerable to exploitation. Data ranks among the most valuable assets of the modern era, prompting governments and corporations to devise collection mechanisms to amass as much consumer and citizen information as possible, thereby inadvertently fueling a digital gold rush for cybercriminals and hostile foreign entities.
The most damaging category of data remains PII, encompassing sensitive attributes like names, home addresses, and government-issued credentials such as passports or driver’s licenses. To utilize numerous services throughout the United States, citizens are required to identify themselves while providers verify their identity. These mandates stem from both regulatory compliance and commercial self-interest, as authorities and corporations alike seek to curb illicit actions and fraud. Regrettably, the current methods employed have done little to stop fraudulent schemes while greatly assisting them.
Banks and other financial entities provide a prime illustration. Under the Bank Secrecy Act and associated rules, these institutions must gather and archive records containing customer PII during onboarding to counter financial crime and fraud. Such valuable and sensitive data typically resides in centralized repositories known as honeypots, rendering them prime targets for malicious actors. Once acquired, this stolen PII enables criminals to compromise existing profiles, open unauthorized lines of credit, execute fraudulent transfers, and launder funds using an innocent person’s identity.
How effective have these protective safeguards proven for the financial networks of America and the world? Data compiled by the Federal Trade Commission reveals that its consumer complaint system cataloged 6.47 million grievances regarding identity theft, fraud, and related consumer issues in 2024, a sharp rise from roughly 860,000 in 2004. Meanwhile, illicit finance remains widespread, with global financial crime estimated to have reached $4.4 trillion during the previous year alone.
Financial firms have continually introduced new customer verification mechanisms to block criminals from circumventing security barriers—despite holding consumer PII—yet these measures serve as minimal deterrents. One-time verification codes dispatched via email or SMS face constant compromise via phishing and alternative vectors, while biometric authentication standards are losing effectiveness due to rapid advancements in artificial intelligence.
Although IDScan is not a financial institution and faces no legal obligation to archive client PII, it operates as a vendor enabling third-party organizations to perform identity checks. Nonetheless, client businesses utilizing IDScan’s cloud infrastructure concentrated their data stores into centralized environments, simplifying potential security breaches.
Given these realities, citizens must question why they surrender vulnerable personal details when the sole return is an illusion of safety. Americans are not rendered safer simply by identifying themselves constantly to every commercial entity they encounter. On the contrary, the reality points elsewhere. Yet, domestic and international governments continue pushing to broaden mandatory identification frameworks through age-verification mandates under the rationale of child protection. Once more, these purported safeguards generate greater harm than benefit. Personal data now circulates among criminal networks simply because authorities and enterprises demanded to know our identities and activities, leaving the public to absorb the costs.
If there was ever an urgent period for enhanced data privacy, it is today. Still, one must maintain analytical balance. Proposals advocating for the complete elimination of identification and verification steps surface frequently. While appealing at first glance, anti-fraud frameworks exist to shield citizens and their assets alongside preserving corporate revenue and operational stability—the flaw lies purely in the execution of the current model. Genuine utility exists within verification, but maintaining the existing paradigm is unnecessary.
Emerging technologies present pathways toward superior methodologies. Rather than forcing citizens to continuously hand over complete duplications of identity documents, privacy-focused architectures could empower individuals to verify only the specific attributes required by a service—such as account authorization, eligibility, or age—while retaining full ownership of the underlying data.
While these innovations remain under development, regulatory bodies should grant institutions the flexibility to test them and refine legacy compliance frameworks as the tools mature. Furthermore, alongside the expansion of privacy-centric alternatives, legislative bodies should scale back extraneous data collection and retention mandates. Anti-fraud measures retain their importance, but they can function effectively without establishing permanent dossiers vulnerable to theft.
More urgently, federal and state lawmakers ought to halt any legislative efforts aimed at extending identity verification obligations into sectors where they currently do not exist and serve no purpose. The regulatory push toward mandatory age verification across the open internet and open-source software must cease; it places everyday citizens at risk, empowers malicious actors and hostile foreign governments, and ultimately fails to safeguard minors.
Security breaches of this nature remain entirely avoidable if society commits to preventing them. The requisite technological solutions are beginning to surface, and whenever verification proves unnecessary, it should be bypassed altogether. Ultimately, the most reliable method to safeguard sensitive personal information is to avoid collecting it in the first place.
Originally published at https://www.coindesk.com/opinion/2026/09/09/kyc-data-is-an-irresistible-honeypot-for-hackers-and-we-must-change-how-it-is-collected.