en

KYC data is an irresistible honeypot for hackers, and we must change how it is collected

image
rubric logo Security

A dark-web service is reportedly offering more than 153 million American and Canadian driver’s license records for sale, and the FBI is investigating an apparent data breach involving the identity-verification provider IDScan.net. This is yet another case where some of the very mechanisms that are supposedly meant to protect the American public are being used to harm it. The problem is clear: current anti-fraud processes that require customer identification and verification empower fraudulent activity by handing criminals your sensitive information on a silver platter.

Cyberattacks targeting personally identifiable information (PII) have been prevalent for some time and are only getting worse. In 2017, Equifax — one of the largest credit reporting agencies in the U.S. — underwent a cyberattack that led to the compromise of nearly 148 million Americans’ sensitive personal information. Nearly 45% of Americans had their data stolen. The Department of Justice alleged that the Chinese People’s Liberation Army was behind the hack in a 2020 indictment, but this was merely a band-aid to the underlying and increasingly prevalent problem.

Laz Pieper is the research director at Coin Center, which defends the rights of individuals to build, use, and assemble free and open peer-to-peer networks, and the right to do so privately.

Most people have probably not heard of IDScan, but have handed a driver’s license to businesses that use its technology and services. As the name suggests, IDScan specializes in ID verification and provides hardware and software that scan, parse, and authenticate IDs for car-rental agencies, banks, hotels, casinos, cannabis dispensaries, retailers, and other businesses. Its systems can capture front-and-back images, extract personal information, compare an ID’s photograph with a selfie, and transmit or store the resulting data in a cloud portal for businesses to continue to access after authentication.

Despite any cybersecurity measures, its business model was always prone to attacks. Data is one of the 21st century’s most valuable commodities. Governments and corporations alike have designed schemes to acquire as much of it as they can from citizens and consumers, and in the process, have opened the door for cybercriminals and foreign adversaries to partake in the modern-day gold rush.

The most consequential data is, of course, PII, which is made up of highly sensitive details, including a person’s name and address, as well as their government-issued ID, such as a driver’s license or passport. To access a good amount of services in the U.S., Americans must identify themselves and the service providers must verify that they are who they say they are. This requirement can be both regulatory and commercial: the government wants to prevent fraud and illicit activity, but so do businesses. Unfortunately, the manner in which to do so has done little to prevent fraud and illicit activity, but plenty to empower them.

Note: The views expressed in this column are those of the author and do not necessarily reflect those of CoinDesk, Inc. or its owners and affiliates.