
An ID verification company is suspected of being responsible for a data breach involving 153 million identity cards that were put up for sale to criminals! The cache includes drivers licenses, travel documents, medical cards, and other government issued IDs from North American victims.
This is another example of how companies are taking and storing personal and private identity documents which are eventually hacked and exposed for criminal activities.
We need better privacy rights.
How about we start with prohibiting the storage of personal Identity documents? There are legitimate needs to validate someone’s identity, but once it is complete, the documentation provided should be immediately purged. Let’s reduce the risks.
The exposure of such documents can cause significant financial and reputational harms. By actively deleting data that is no longer required, we greatly reduce the exposure risks from data breaches.
So why don’t we do it? Because deleting private and personal data goes against business culture. There is value there. Something to be used or sold later for an economic advantage. This is where public security and safety collide with corporate interests.
Regulations are the only fix when economic incentives are in conflict with consumer protection.
Great job by Brian Krebs in unmasking this data breach and zeroing in on the likely (but not confirmed) culprit, an Identity Verification company! IDScan.net is now under FBI investigation.
Attention US Congress, a few simple regulations could go a long way!