From the very beginning of this recent obsession with identifying everyone online (yes, they like to call it “age” verification, but it always ends up as identity verification), we’ve been pointing out that it was a huge privacy nightmare waiting to happen. Or maybe it wasn’t waiting. Maybe it was already happening.
This week a massive new data breach has been revealed that should put the nail in the coffin for the idea that any sort of age or identity verification could be safe. 153 million scans of drivers licenses easily available based on this breach, with more being added all the time. Literally on the day it was revealed (and right before the site was taken down) it added another 400,000 records to its available database.
There is no safe age verification. There is no age verification that doesn’t put people at risk.
Last year, Eric Goldman wrote the definitive piece on how all of these technologies — no matter what they tell you — are huge privacy risks, but people are still living in denial. This is despite the numerous examples we’ve had in just the past few years of verification providers and their customers having massive data breaches.
The latest comes to us via Brian Krebs, who reports on a massive breach of scanned IDs — more than 153 million drivers licenses from people across the US and Canada, now for sale on the dark web:
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of theFederal Bureau of Investigation(FBI) today launched an official inquiry into the source of the images.
Krebs traces the breach back to an ID verifier that appears to be used by many companies, including Hertz, the rental car company. It appears to not be limited to them either, as he checked with a number of people who were in the database, and by looking at the date they were added alongside their calendars, found examples of other people who shared their ID at places like a pot dispensary.
That company turns out to be IDScan.net, based in Louisiana, which has contracts with thousands of dispensaries, not to mention Hertz, FedEx, and Target. And while Krebs is focused on how many of the leaked IDs are connected to real world businesses, it’s worth noting that IDScan.net is also doing age verification for a bunch of tech companies, has a page tracking state age verification laws and company implementations, and even has written positively about laws like KOSA, the Kids Online Safety Act, that would effectively require age verification.
So, yes, we have a company that is a big player in the age verification space, talking up age and identity verification laws, that appears to have had a long-standing ongoing leak of every ID it scanned.
Yiiiiiikes.
And, of course, like all age and identity verification providers, IDScan has spent years talking up how secure it keeps all this data, even as every single record appeared to be leaking in realtime. Here’s their “Trust Center” page which is still up days after the hack was revealed:
That’s the company that spent over a year leaking 150 million drivers licenses in real time, explaining “how we protect data, maintain system reliability, and earn the confidence of our customers and their users.” Might be time to update that page.
But also, this should be a massive warning to everyone pushing for age verification laws. You can have a “trusted” company in the space who brags about all the certifications it has. It’s in “compliance” with the GDPR, the CCPA, and every other law. It is “transparent” about its “privacy practices” and how its “sensitive identity data is handled responsibly” and…. for over a year it’s been leaking all of those sensitive records.
And it appears no one internally at the company noticed.
As Krebs makes clear, the breach included many, many millions of records and ID scans that were being swiped in real time by the hackers who breached the system:
The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.
The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.
“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”
Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this serviceon a semi-regular basis.
And the exposed records aren’t just random members of the public. Krebs found the driver’s license of the sitting Secretary of Defense sitting in there for sale:
A bargain! Only $100 to get a scan of the Secretary of Defense’s driver’s license.
Anyway, each time we highlight a breach people play it down and insist that mandating age verification is perfectly safe and nothing to worry about. Yet here’s one of the largest identity verification companies in the country, with a pipeline so wide open that hackers had a real-time feed of every government ID it scanned, for over a year, without anyone at the company noticing.
Krebs spoke to a security researcher at Cybera, named Larry Baldwin, who talks about how this kind of data can do real damage:
Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).
This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.
“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.
At this point, anyone still supporting age verification requirements, especially claiming it’s for “child safety,” should have to answer for all the millions of people put needlessly at risk due to data breaches like this.
You cannot do age or identity verification safely. It always creates some sort of record and that set of records will always become a target. That’s what happened here. And it’s what will happen with any such systems.
The US Court system’s electronic filing front-end has always been a mess. Not only is it prohibitively expensive for most casual users, it’s prohibitively dysfunctional even for power users. Whoever isn’t discouraged by the outdated front end will be just as unimpressed by its back end. PACER charges per page like it’s a librarian running paper copies on a mimeograph. It also charges per page of search results, even if the inadequate search system fails to turn up anything more than the notification that this failure has added another $0.10 to your PACER tab.
Perhaps the only way to make PACER useful is to bypass the front end and root around in the digital back room. That’s what appears to have happened here, as first reported by Politico:
The electronic case filing system used by the federal judiciary has been breached in a sweeping cyber intrusion that is believed to have exposed sensitive court data across multiple U.S. states, according to two people with knowledge of the incident.
The hack, which has not been previously reported, is feared to have compromised the identities of confidential informants involved in criminal cases at multiple federal district courts, said the two people, both of whom were granted anonymity because they were not authorized to speak publicly about the hack.
First, let’s discuss the “sensitive court data.” PACER records are de facto public documents. But not everything contained in the US Courts system is actually public or even meant to be public. In addition to the things Americans are still expected to pay $0.10/page to access, there’s plenty of stuff filed under seal or otherwise prevented from reaching publicly-accessible dockets. And those documents might include things the government would definitely prefer no Americans have access to, much less the presumably foreign hackers who managed to breach the system.
But Politico isn’t exactly correct that this hack “has not previously been reported.” The breach was apparently discovered by the government on July 4 (hmmm), but the attacks and the attack surface had previously been highlighted by the federal judge overseeing PACER modernization efforts. Two weeks before this hack was discovered, the judge had told Congress PACER was under constant attack by malicious hackers.
Michael Scudder, who chairs the Committee on Information Technology for the federal courts’ national policymaking body, told members of the House Judiciary Committee that about 200 million harmful cyber “events” were prevented from penetrating court local area networks in fiscal 2024.
“The Judiciary has had to respond to waves of highly sophisticated and persistent cyber threats,” Scudder said in written testimony. “Given the information in the Judiciary’s control, we continue to face unrelenting security threats of extraordinary gravity.”
This was apparently shrugged off as something a DOGE-subservient federal government wouldn’t be spending any money on. After all, very few people in power actually seem to care whether or not there’s easy and equitable access to court records citizens have a First Amendment right to access. And the US Court system itself is more concerned it won’t be able to buy new flatscreen TVs and office chairs if anyone allows everyone but (mainly corporate) power users to access documents for free.
And while this wasn’t confirmation of this particular hack, the government had been warned hackers were incessantly attacking PACER in hopes of accessing whatever wasn’t accessible via its counter-intuitive front end.
The modernization of PACER is relegated to the back burner in perpetuity, it seems, even though spending money to update the system might have made it a bit more resilient to persistent attacks. But the federal government rarely feels compelled to throw money at things that might make things better for the hundreds of millions of peons who have somehow failed to secure a seat in Congress.
Under Trump and DOGE, this breach may result in some hand-wringing about the potential exposure of confidential sources (or buried evidence of police misconduct) but it’s unlikely to result in funding for additional security efforts, much less any movement forward on the free access front.
I can only hope the hackers decide to dump these documents somewhere publicly-accessible, which will save citizens millions in PACER fees while also exposing the amount of banality of the government out of the public eye by pretending literally any fact about any well-known surveillance tech or commonly-used law enforcement tactics will somehow create nationwide criminal chaos if the general public finds out things it most likely already knows.
But more importantly, this shows how little the government cares about one of its offerings that mainly benefits people who aren’t government employees. While the government has no problem spending money to make sure its own are taken care of, the people paying the tab are seldom considered worthy of government investment. And I can pretty much guarantee the reaction to this hack will be even less access to presumptively public records, rather than the implementation of a robust system that repels hackers and provides better, cheaper access to records the public has already paid for once.
Shooting the messenger is still the preferred tactic for short-sighted entities that have been embarrassed on main by having their own carelessness publicly exposed. Two articles on Databreaches.net (run by “Dissent Doe“) covered the discovery and eventual consequences of a ransomware attack on HCRG Care Group, a UK-based private healthcare provider.
The ransom demanded by the Medusa ransomware gang wasn’t put in place to unlock the personal data obtained by the attackers. Instead, it was more like blackmail: a threat to publish the data unless HCRG paid it $2 million to “buy back” the purloined data.
This sort of thing happens all the time, unfortunately. The only unusual aspect of this particular ransomware attack is that the attackers appeared to have abandoned locking up data in favor of collecting payment to prevent distribution of the data.
Unfortunately, equally as common is what happened here: the threatening of someone who did nothing more than report on events that have actually happened. Dissent Doe’s site was served with an alleged injunction order from a UK court that (also allegedly) mandated removal of Databreaches’ previous reporting on this incident.
The takedown Demand, sent to Dissent Doe by HCRG’s law firm, Pinsent Masons, sure sounded extremely… um… excessively wordy:
We urge you to read the enclosed Order closely. As you are now on notice of the fact and terms of the injunction, pursuant to paragraph 22 of the Order, it would be a contempt of court for you knowingly to assist or permit a breach of the Order, including by publishing on your website some or all of the Confidential Information stolen during the cyber-attack. Breach of the terms of the Order may result in imprisonment, a criminal fine or having your assets seized.
Accordingly, you should take the necessary steps to ensure that none of the Confidential Information is published or disclosed on your website, and take down the following articles which contain descriptions and screenshots of some of the Confidential Information:
Having been so urged, Dissent Doe read the letter and the injunction order. Perhaps HCRG’s legal reps would have been better off “urging” them to “skim over this order to get the gist of it,” rather than directing them to “read” these documents “closely.”
Under closer examination, two things immediately stood out. First, nowhere in the legal documents is Dissent Doe or their website listed as a defendant. Second, this order was obtained without notice to Dissent Doe and the target of the order was never given a change to argue their case, much less file anything to object to the proposed injunction.
Here’s Dissent Doe, objecting to the order, albeit in blog post form:
The court did not offer any reason at all — much less a compelling one — not to notify journalists whose work it would be censoring. Nor did it provide any justification at all for censoring media coverage of HCRG’s ransomware attack even though there is nothing unusual about the incident or the reporting on it to date. If there was any civil law violated that would justify censorship, the injunction failed to state it.
[…]
If the injunction itself didn’t name DataBreaches.net and if it didn’t mention the two posts either by URL or even by description, then how could DataBreaches be sure that the court intended to order this site to remove those two posts and not just one of them, or neither of them? Shouldn’t a court order be quite specific as to whom it applies and what they are required – exactly – to do or not do? There was no such specificity in this injunction.
Lots of missing pieces, none of which add up to compliance, immediate or otherwise. However, there was a clause in the injunction order that made it explicitly clear Dissent Doe was under no obligation to comply with this strongly worded letter and vaguely worded court order:
Except as provided in paragraph (2) below, the terms of this Order do not affect or concern anyone outside the jurisdiction of this Court.
There it is. US entities are not subject to UK court jurisdiction. Paragraph (2) explains how a US entity might become subject to this court, but it would involve a whole lot of things that aren’t happening here, like Doe having an appointed legal representative residing in the UK and having been given notice of this legal action at a residence or place of business that is within the jurisdiction of UK law.
Doe sent a letter back to HCRG’s legal reps pointing out all these things that justified the site’s non-compliance with the completely ineffective injunction order they had obtained. Rather than take the loss in dignified silence, HCRG sent a letter to Dissent Doe’s domain registrar demanding the same removal of content. The registrar forwarded this request to Dissent Doe, who again pointed out why it didn’t apply to their site and, additionally, did not apply to the registrar either. After a brief conversation, the registrar dumped the service ticket generated by this bogus legal threat and informed Doe no action would be taken against their site.
At this point, the posts remain live. And, for the moment, HCRG’s lawyers are still silent. It’s been 10 days since the last effort by Pinsent Masons, so one assumes this self-own is over and its lawyers are gently explaining the legal concept underpinning their failure. Hopefully, this will be the end of it.
But even if it is, this sort of thing just never goes away, even if, in almost every case, these threats rarely manage to dislodge content breach/ransomware victims want to keep out of the public eye. It’s never about preventing people from accessing data that’s been obtained via illegal means. It’s always about minimizing public exposure. The faster they can bury reporting, the longer they can wait before having to inform their users and customers that their personal information is now in the hands of criminals. And the longer they can keep this out of the news, the longer they can enjoy the profit margins/share prices they’re used to, even if the long-term damage wouldn’t last nearly as long if they’d just rip the band-aid off and get on with treating the wound.
Here’s a final election day story. This time, it’s about an “election integrity” app being used by MAGA folks to spread absolute nonsense about the election, but also to confess their own illegal voter suppression schemes. And thanks to their crap security, it’s now being reported.
At a time when the facts-optional GOP likes to flip everything on its head (calling legitimate reporting they dislike “fake news,” or basic editorial decision making “election interference”), they’re now using “election integrity” as the term to mean “here’s how we best violate free and fair elections.”
The group True the Vote, which has been behind a ton of election conspiracy theories, created an “election integrity app” called “VoteAlert” that they encouraged the MAGA faithful to use to report any fraudulent election activity they came across. True the Vote is the group behind the ridiculously stupid “2000 Mules” conspiracy theory film (you know, the one widely promoted by Trump loyalists, but which its very MAGA publishing company later felt the need to retract, remove, and apologize for?)
Yet, as Wired points out in an article today, the app’s security was so piss poor that it exposed all sorts of private info of those using the app, including emails and the submitted comments by users. That allowed Wired’s excellent security reporter Dhruv Mehrotra to take a look at what people were using the app for, and apparently, “committing actual voter fraud” was on the list:
In a since-deleted VoteAlert post reviewed by WIRED, a user wrote: “I’m probably going to be fired for this but I was hired by the Riverside County Registrar of Voters as an Election Officer in Hemet, CA. Since I’m in charge at this polling center, I’m asking for citizenship ID of anyone that looks suspiciously like they’re not here legally.”
The post went on to suggest that the Riverside County Sheriff’s office wouldn’t intervene in her scheme. “It’s just a drop in the bucket but I’m going to do my part to stop election fraud,” she wrote. “Wish me luck🙏”
WIRED traced the email associated with the post to a California woman who describes herself as a person who is “FED UP with all the bullsh*t,” according to one app profile. “You’re only getting the hard, smack-your-face TRUTH from me.”
That is all very much illegal. You can argue over voter ID laws, but the fact is that California does not have one and it’s against the law to check citizenship status in California. And, no, this does not mean that non-citizens are voting. There are other systems that root that out, and what non-citizen is going to risk their presence in the country to vote?
Once again, it seems that every time we hear about claims of “voter fraud,” they seem to be coming from the MAGA world, accusing the Democrats of engaging in it. However, the very, very, very minimal number of cases of actual voter fraud being discovered almost always show it actually being conducted by MAGA folks who have been lied to and misled by Trump and others into believing the Democrats are doing it, thereby justifying their own illegal activities.
U.S. wireless giant T-Mobile gets hacked a lot. In fact, the company has been hacked eight times in the last five years, with several of the intrusions exposing the sensitive personal data of millions of T-Mobile customers. The last hack, revealed in a 2023 SEC filing, exposed the names, addresses, social security numbers, and other sensitive information of over 37 million T-Mobile subscribers.
It took half a decade, but the FCC has finally taken action, announcing last week that it struck a new settlement with T-Mobile related to the breaches. As part of the deal, T-Mobile has agreed to pay $15.75 million to ramp up its security standards and practices (money it should have already spent on the issue), and another $15.75 million civil penalties to the U.S. Treasury.
“Consumers’ data is too important and much too sensitive to receive anything less than the best cybersecurity protections,” FCC boss Jessica Rosenworcel said in a prepared statement. “We will continue to send a strong message to providers entrusted with this delicate information that they need to beef up their systems or there will be consequences.”
One could argue that a $15.75 million fine years after the fact isn’t quite the deterrent Rosenworcel insists, given T-Mobile’s made untold millions (or billions) of dollars over the last decade playing fast and loose with consumer privacy.
As with so many modern companies, T-Mobile over-collects data then doesn’t take the necessary steps to protect said data. It then lobbies state and federal lawmakers to ensure we don’t shore up U.S. privacy protections (as it did when Republicans gutted the FCC’s fairly modest broadband privacy rules, or when it lobbies to kill new federal privacy laws), and the cycle repeats itself in perpetuity.
T-Mobile has a bit of a history of being sloppy with the vast location data it collects on users, then fighting tooth and nail against whatever slapdash accountability U.S. regulators can feebly muster. T-Mobile recently dramatically expanded the company’s collection of user browsing and app usage data via a new program dubbed “app insights.”
So yes, it’s nice to see the FCC take belated action, but it shouldn’t be confused with more serious accountability for T-Mobile or its executives. Nor should anybody confuse occasional fines (which may be reduced if they’re paid at all), with having a real federal privacy law, consistent privacy enforcement, or antitrust reform preventing companies from becoming impossibly unaccountable in the first place.
As more and more governments try to pass more and more laws requiring age verification, some of us keep pointing out that age verification will cause a ton of harm. For all the talk of how it’s necessary to “protect the children,” the only way to verify ages is to collect a ton of private information on people, which then makes that information a target.
People like Jonathan Haidt in his new book like to pretend that there’s some magical way of doing privacy-protective age verification by outsourcing it to a third party, but that just passes the buck and makes that third party a target. Just a few weeks ago, we talked about this a bit in the context of Australia, where a third-party age ID verification vendor used by bars had a breach, leaking more than 1 million customer records.
Of course, some people would say, “but that’s a bar, that’s different than a website.”
Well, then, this new story should catch your attention. First reported by 404 Media, AU10TIX, an Israeli-based online identification company used by TikTok, ExTwitter, Uber, LinkedIn, PayPal, Fiverr and others has been leaking drivers’ licenses. For over a year.
The set of credentials provided access to a logging platform, which in turn contained links to data related to specific people who had uploaded their identity documents, Hussein showed. The accessible information includes the person’s name, date of birth, nationality, identification number, and the type of document uploaded such as a drivers’ license. A subsequent link then includes an image of the identity document itself; some of those are American drivers’ licenses.
The data also appears to include results from AU10TIX’s verification process, with a field for “liveness” reading “true”; the “probability” of that conclusion on a scale of 0 to 1, with a potential result being 0.9486029; and other fields called “DocumentAuthenticity” and “OverallQuality.” More results appear to relate to AU10TIX’s comparison of a photo of the person’s face to their uploaded document, with another section referencing a photo called “PhotoForFaceComparison.jpg.”
Another screenshot from the tool shows a line chart with one axis labeled “clientOrganizationName.” That axis includes “TikTok_Shop_Creator,” “Impersonation_XCorp,” and “uber-carshare-passport,” apparent references to the three tech giants.
Cool, cool. Nothing to be concerned about there at all.
Just last year, when Elon first hired this company to provide identification services for ExTwitter, we warned that these systems are not at all reliable and can be a threat to privacy. Turns out we were right.
As always, collecting unnecessary data makes you a target. And this data became a target and was exposed. The way we minimize that is not by forcing more companies to collect more such data. It’s to not need to collect such data in the first place.
This isn’t a case where someone just discovered this breach and no harm was done. Indeed, it appears that significant harm was done here:
The credentials appear to have been harvested by malware in December 2022, and first posted to a Telegram channel in March 2023, according to timestamps and messages from the Telegram channel that posted the credentials online. 404 Media downloaded these credentials and found the name matched that of someone who lists their role on LinkedIn as a Network Operations Center Manager at AU10TIX. The file contained a wealth of passwords and authentication tokens for various services used by the employee, including tools from Salesforce and Okta, as well as the logging service itself.
So this data has been out there for over a year. And shared. Widely. For over a year.
Can lawmakers please stop requiring more companies to harm everyone’s privacy this way? These breaches are only going to keep happening, and they’re only going to get worse the more and more ignorant policymakers keep forcing more companies to collect more such data, based on a myth that age verification will magically make the internet safe and wholesome. It won’t.
It’s almost laughable that these two stories happened so close to one another. The Australian government has just announced a pilot program to test an online age verification system:
And then, just hours later, it was reported that law enforcement is investigating an apparent breach of club and bar patrons’ personal data, which the venues are required to collect by law for people entering such establishments.
When we talk about the privacy and data risks of age verification, this is exactly the kind of thing we’re talking about. When you’re collecting that much sensitive private data, you become a target.
As the article linked above notes:
It is a legal requirement in NSW for licensed clubs to collect personal information from patrons on entry, under the state’s registered clubs legislation.
The information is required to be stored securely under federal privacy laws.
Sounds kinda like the age verification requirements for websites. You have to collect the info and then pinky promise to keep it secure. And it works until this happens:
An unauthorised website claims personal information of more than 1 million customer records from at least 16 licensed NSW clubs have been released online in a potential data breach.
Cybercrime detectives are investigating the reported breach with the website claiming to have records and personal information of senior government figures, including Premier Chris Minns, Deputy Premier Prue Car and Police Minister Yasmin Catley.
IT provider Outabox said in a statement it had become aware of the potential data breach of a sign-in system used by its clients by an “unauthorised” third party.
Hilariously, government officials are trying to play this down because it was just a breach rather than a hack. As if that makes a difference?
Gaming Minister David Harris said the government and police first became aware of the potential breach on Tuesday.
“We know that this is an alleged data breach of a third-party vendor, so it wasn’t a hack,” he said.
But this is exactly the concern regarding online age verification. Someone has to collect that information and then whoever is collecting the sensitive info becomes an immediate target, no matter how the data is accessed.
Incredibly, you might recall that just a few months ago we were giving the Australian government kudos for recognizing that age verification was a privacy and security nightmare. So, they knew that just last summer.
And yet, here we are with the latest announcement:
Despite those concerns from late last year, the government is now pushing ahead with a pilot to try and test some of those ideas.
Look, maybe head down to the nearest club in NSW to see how it’s working out before moving forward “despite these concerns”?
Meanwhile, if you think this breach isn’t that serious, well, for the million or so folks who visited one of those bars and clubs, things don’t look great:
Creator of the data breach tracking website haveibeenpwned.com, Troy Hunt, said the creators of the website had not released all of the information they had collected.
“Inevitably they do have the entire thing.”
He said the Outabox technology used by clubs scans patrons’ faces and matches them with their licence details.
Mr Hunt said people whose data has appeared on the site may need to replace their drivers licences.
“There are physical addresses, there are date of birth, there are names. That’s not good,” he said.
AT&T is under fire after a hacker last month posted the personal information (names, addresses, phone numbers, and social security numbers) of roughly 73 million customers to the open web. Troy Hunt, security researcher and owner of data breach notification site Have I Been Pwned, notes the data first appeared a few years ago courtesy of a hacker seeking payment.
In March the originally encrypted data was dumped on the open web. But since the data first appeared a few years ago, AT&T has been oddly cagey about where the data came from, insisting last week to outlets like Techcrunch that it didn’t originate with their systems:
“We have no indications of a compromise of our systems. We determined in 2021 that the information offered on this online forum did not appear to have come from our systems. This appears to be the same dataset that has been recycled several times on this forum.”
Yet Hunt has confirmed the data are from legitimate AT&T customers. If you’re an AT&T customer, you can search Have I Been Pwned to see if you’re part of the festivities. When Techcrunch pressed AT&T for more details, the company went silent. With AT&T refusing to own the leak, users don’t even get the traditional empty gesture of a year of free credit reporting.
AT&T’s denial suggests they either couldn’t track down the origins of the leak, which suggests substandard security and privacy standards and not-so competent investigators. Or it knows precisely where this data came from, and the trajectory of the transfer raises privacy questions they don’t want to answer because it could involve regulatory and reputational risk.
Knowing AT&T’s ethics fairly well as a multi-decade telecom beat reporter, I think it’s very possible it’s the latter. Big ISPs like AT&T have a long, rich history of playing fast and loose with consumer data, selling access to vast troves of location, behavior, and other consumer data to a universe of partners in a million different creatively dodgy ways, then routinely lying about the width and breadth of the practice.
AT&T is part of a wide array of companies across numerous industries that universally suck at user privacy and security, while simultaneously lobbying our corrupt Congress to ensure nobody passes a privacy law, regulates data brokers, or holds telecoms to meaningful account. The outcome was always obvious; especially once companies like AT&T effectively became trusted partners in U.S. domestic surveillance.
Data brokers like Experian and Equifax pose tempting targets for malicious hackers looking to find another source for personal info they can hawk online to other malicious people. The sad thing is, no one really needs to hack their databases. They’re more than willing to just leave them exposed.
In 2017, Equifax leaked personal info pertaining to nearly half the nation (143 million people). The credit reporting agency knew of the breach as early as July but didn’t get around to notifying affected people for another couple of months. A few wrist slaps later and Equifax is still making millions while affected US residents are being asked to make do with [squints at recently received Equifax settlement check] $7.85.
Experian has its own sordid history. Not only has it been fined multiple times for misleading people about access to free credit reports mandated by federal law, it was caught selling personal info to a Vietnamese fraudster who sold this illicitly obtained stash of PII to others.
Brian Krebs was the one who broke that story in 2013. He’s on the leading edge of this one as well, which shows Experian hasn’t gotten any better at protecting the massive amount of personal info it obtains from millions of Americans who have zero say in the matter.
Identity thieves have been exploiting a glaring security weakness in the website of Experian, one of the big three consumer credit reporting bureaus. Normally, Experian requires that those seeking a copy of their credit report successfully answer several multiple choice questions about their financial history. But until the end of 2022, Experian’s website allowed anyone to bypass these questions and go straight to the consumer’s report. All that was needed was the person’s name, address, birthday and Social Security number.
Asking people to input the Big Four of PII to access their credit report via an online form is already careless. Compounding this is Experian’s ongoing disinterest in fulfilling its federal obligations to supply free credit reports. The data leak involves Experian’s verification process that is triggered by visitors to freecreditreport.com, the website through which Americans can access their federally mandated free credit reports.
Brian Krebs was alerted to this leak by Jenya Kushnir, a Ukrainian security researcher who had come across the security hole while lurking on Telegram chat channels used by identity fraudsters. He decided to take the reported breach for a spin, starting with a stop at freecreditreport.com. From there, he was sent to Experian’s site for ID validation, where problems began to develop.
[W]hen I tried to get my report from Experian via annualcreditreport.com, Experian’s website said it didn’t have enough information to validate my identity. It wouldn’t even show me the four multiple-guess questions. Experian said I had three options for a free credit report at this point: Mail a request along with identity documents, call a phone number for Experian, or upload proof of identity via the website.
So far, so good, I guess. This would prevent fraudsters from utilizing info obtained from other breaches to access people’s credit reports. If only it had ended there. Turns out there’s a workaround, and it’s really not any work at all.
But that didn’t stop Experian from showing me my full credit report after I changed the Experian URL as Kushnir had instructed — modifying the error page’s trailing URL from “/acr/OcwError” to simply “/acr/report”.
Experian’s website then immediately displayed my entire credit file.
So, without successfully performing any ID verification, Experian allowed access to a full credit report via URL alteration. That should never happen, but it’s the sort of thing that happens all too frequently. Massive corporations that have all the expertise and money needed to secure personal info somehow fail to do so with alarming frequency. And when they’re exposed, they often try to find ways to shoot the messengeror punish those who interact with their sites in unexpected ways.
Experian was notified by Krebs last month but never responded. The breach method, however, was silently patched out of existence at some point between Krebs’ Experian experiment and its acknowledgment of his breach report four days later. Adding insult to injury, Krebs notes the report he obtained was full of errors, meaning he’ll have to interact with the service that failed to protect his info multiple times to get his credit report fixed.
And, once again, a credit reporting service — one that Americans can’t opt out of having their personal information shared with — has played fast and loose with the wealth of PII it collects and sells access to. Krebs’ full report is a great, if depressing, read that helpfully provides details on other times Experian has failed to properly secure this data. Unfortunately, the most Americans can hope for is that they won’t be cut off from accessing their free credit reports because of credit reporting service incompetence. If the Equifax breach is any indication of future results, these companies will continue to be careless because they’ve been assured they’ll never truly be punished for fucking things up.
When a Cellebrite device is hooked up to a seized phone, the operator presses a few buttons to pull pretty much every bit of data from the device. From there, investigators can try to find the evidence they’re seeking. While the FBI continues to claim device encryption is preventing law enforcement from accessing evidence, plenty of private companies are providing solutions to the problem the FBI claims is unsolvable without backdoors.
It looks as though Cellebrite cellebrited itself a few years ago. Somehow, during normal day-to-day business operations involving its Japanese stakeholder, it performed a data dump of epic proportions that ultimately made its way into the hands of Japanese regulators. Omar Benjakob has the exclusive report for Israeli news outlet, Haaretz.
Sensitive and confidential information relating to intelligence, defense and law enforcement agencies across the globe, including the FBI and Interpol, leaked from Israeli firm Cellebrite, according to court documents cleared for publication at Haaretz’s request.
The information is from 2015-2017 and includes almost half a million emails belonging to senior officials and directors at Cellebrite, their internal communications and exchanges with clients, invoices and even contracts.
These documents first ended up in the hands of Cellebrite’s main shareholder, the Japanese Sun Corporation. From there, they went to Japanese government authorities, who were investigating whether Sun Corporation made use of this sensitive Cellebrite info to engage in insider trading.
All of this was done without the knowledge of Cellebrite’s many customers, who had their internal discussions shared with a stakeholder (which may have been expected to have some access to proprietary info) and Japanese authorities. It also appears to have happened without the knowledge of Cellebrite, which then approached its legal reps to assess the potential fallout of this unexpected leak.
In one of the documents, lawyers hired by Cellebrite wrote: “It is our belief that should the knowledge that such sensitive information was provided to the Japanese authorities be disclosed to Cellebrite customers, it may cause severe reputational damage to Cellebrite (with such clients and others).”
“Cellebrite customers are likely to request to receive from Cellebrite complete disclosure relating to the information disseminated to the foreign authorities, in order to evaluate their exposure,” according to the legal opinion written at Cellebrite’s behest in 2018 and whose publication was cleared by Israeli courts last week.
It’s not just the proprietary info, insight into Cellebrite’s customer base, and internal communications that raise these concerns. It’s also a criminal act in many countries to disseminate sensitive information linked to national security efforts or criminal investigations, even if done inadvertently or without malice. The exposure of this leak could see Cellebrite investigated and charged for mishandling this sensitive information.
The leak shows plenty of government agencies around the world are either current or former customers, including the FBI, DHS, US Marshals Service, ICE, the Royal Canadian Mounted Police, Interpol, the UK Ministry of Defence, and, more oddly, entities like NASA and the Russian embassy in Tokyo.
With all this exposed, thanks to a lawsuit between Cellebrite and consultant David Spector, Cellebrite is playing belated defense, claiming this is nothing more than showboating by Spector and that its massive leak never harmed anyone, much less the now-publicly traded company.
The documents, Cellebrite said, were added to the lawsuit by Spector “for PR purposes only, and with the clear knowledge that this suit is baseless, does not hold water and does not hold any public interest.”
Cellebrite stressed that “the event described in this report happened five years ago and did not have any effect whatsoever on the company’s activities.”
Well, the “PR purposes” part of it appears to be working, even if that was not Spector’s intent. Cellebrite no doubt assures customers their communications, as well as the trade secrets that make Cellebrite worth purchasing, will be well-protected. A massive leak like this is far from reassuring.
As for this having no effect on the company’s activities… well, that remains to be seen. When the leak was still a secret, it may have had minimal effect. But now it’s public knowledge, and that could have some negative effects on Cellebrite’s future.