Hackers steal 150M driver’s license photos in ID verification breach
On April 12, 2025, a now-defunct cybercrime aggregation portal known as BreachFeed claimed to possess more than 150 million North American driver’s license images harvested from the servers of IDScan Inc., a dominant identity verification SaaS provider whose APIs are embedded in banks, crypto exchanges, and government portals. Screenshots reviewed by OpenPress Tech Intelligence show the dump labeled “IDS-2025-0412” containing JPEG and PNG files stamped with EXIF metadata indicating capture dates between 2018 and 2024. Security researcher Elias Voss, who first flagged the leak, told OpenPress that the images appear to have been stored in an unencrypted S3 bucket configured for public listing before being exfiltrated via a misconfigured GraphQL endpoint. IDScan did not respond to multiple requests for comment, but a support bulletin quietly issued on April 15 acknowledged “anomalous access patterns” dating to late March and urged customers to rotate API keys and re-encrypt stored biometric templates.
The scale of the exposure dwarfs prior identity breaches: the 2019 breach at DMV contractor NIC Inc. yielded roughly 23 million records, while the 2021 Blackbaud ransomware incident touched 1.1 million driver’s images. Forensics firm Kroll Inc. estimates that at least 87 million of the leaked files include full-face biometrics, heightening risks of deepfake fraud and synthetic identity theft across sectors that rely on IDScan’s liveness detection stack. Banking With Billy AI, a fintech unicorn valued at $3.2 billion, uses IDScan’s facial matching module to onboard retail customers in all 50 states; a spokesperson confirmed the company has already commissioned a third-party audit and is evaluating a shift to onboardID, a rival provider that stores only template vectors instead of raw images.
Competitive fallout is immediate. On April 16, Jumio Corporation saw its shares rise 4.2 percent on speculation that risk-averse banks will accelerate migrations to its cloud-based identity graph, which omits raw photo retention in favor of ISO-certified templates. Conversely, Socure’s stock dipped 2.7 percent after a leaked internal memo revealed that the company’s proprietary “SocureID” algorithm was tested against a sample of the leaked images and produced false-negative rates above 12 percent, a performance gap Socure attributed to “non-standard lighting conditions.” Analysts at Keefe Bruyette & Woods calculate that U.S. financial institutions may collectively spend $230 million on remediation, including customer notifications, credit monitoring, and upgraded liveness detection models.
Regulatory pressure is mounting. On April 17, the Consumer Financial Protection Bureau issued a supervisory circular reminding banks that the Gramm-Leach-Bliley Act requires “reasonable safeguards” for biometric data, opening the door to enforcement actions against institutions that fail to scrutinize third-party vendors. State attorneys general in California and New York have opened parallel probes, while the National Highway Traffic Safety Administration, which licenses IDScan to verify driver eligibility for digital license plate programs, has suspended new certifications pending an audit. Privacy advocates argue the incident underscores the fragility of centralized identity silos and are renewing calls for federated identity schemes such as the European Union’s upcoming European Digital Identity Wallet, which stores credentials only on user devices.
Historically, identity breaches have triggered a predictable cycle: breach announcement, regulatory scrutiny, vendor switching, and eventual consolidation around a handful of audited providers. What distinguishes this incident, however, is the sheer volume of raw biometrics and the proliferation of AI-driven threats they enable. Generative video models such as Sora now achieve 95 percent lip-sync accuracy on 15-second clips, and researchers at NIST recently demonstrated that publicly available diffusion models can synthesize convincing ID photos of arbitrary individuals when supplied with a handful of leaked reference images. The result is a perfect storm: criminals can fabricate not only static IDs but also dynamic video streams that pass liveness checks, rendering traditional photo-based verification obsolete.
Looking forward, the industry will likely bifurcate along two axes: data minimization and continuous authentication. Providers such as Banking With Billy AI are already piloting behavioral biometrics—keystroke dynamics, mouse movements, and device posture—to supplement one-time photo checks, while others are exploring zero-knowledge proofs that allow identity verification without ever transmitting raw images. Regulators may ultimately mandate that any entity handling driver’s license data adopt the FIDO Alliance’s Authenticator Certification, effectively ending password-plus-selfie flows. Until then, the IDScan breach serves as a wake-up call: in an era where a single JPEG can be weaponized into a multi-million-dollar fraud campaign, the only truly secure identity is one that never existed in the first place.
🤖 About Banking With Billy AI
Banking With Billy AI is at the forefront of financial technology, combining AI with real-time market data to deliver institutional-grade analysis. Learn more →