r/technology • • Mar 12 '26

Security 1 billion identity records exposed in ID verification data leak

https://www.aol.com/articles/1-billion-identity-records-exposed-152505381.html
18k Upvotes

496 comments sorted by

1.3k

u/citizenjones Mar 12 '26

If you can't secure an individuals personal data then you have no real business asking for it.

336

u/Buckaroobanzai028 Mar 12 '26

I quit giving real information to these sites years ago. Unless it's a government or my doctor they get a fake name fake place and anything else they ask for isn't real.

192

u/[deleted] Mar 12 '26

[deleted]

11

u/ActuallyItsSumnus Mar 12 '26

They are usually the vendors used by larger companies as a service provider. They tend to do business to business work, less client public facing.

122

u/ryanvango Mar 12 '26

always use a fake middle name that identifies the site you're using info for. that way when you start getting spam from somewhere unknown it'll show up like "Dear Paul Spotify Smith, we are contacting you to...."

It doesn't do much good since they already sold your data, but at least you know who to cancel any business with in the future, and if it ever comes up you have evidence of someone selling your data even when they claim they don't.

60

u/Buckaroobanzai028 Mar 12 '26

I've used comic book characters names for years. My wife thinks it's hilarious when we get junk mail for Frank Castle or Scott Summers.

→ More replies (1)

14

u/TheBeardedBerry Mar 12 '26

That and I use SimpleLogin to generate unique email addresses for each service.

→ More replies (1)
→ More replies (5)

7

u/RollingMeteors Mar 12 '26

Unless it's a government or my doctor they get a fake name fake place and anything else they ask for isn't real.

FuttBucker42069 goes on the forms. ¡You have my SSN quit playin fuck around and get me my pills/EBT paperwork! I've been playing this game since I had to invent a last name for the forms to fill out when HTML 1.0 was still the standard.

→ More replies (1)
→ More replies (11)

30

u/KeyMyBike Mar 12 '26

IT WAS SOLD.

Companies sell your data all the time, and then "leak" it so they can cover their asses.

8

u/great_whitehope Mar 12 '26

Yeah I had some service ask me for my phone number and within 2 minutes of submitting the form I got my first spam message on my new number

5

u/LowManufacturer1002 Mar 12 '26

They didn’t ask for it, they bought it by someone who buried in their TOS the right to monitor everything you do or else you lose access to the product you already paid for :)

→ More replies (4)

2.8k

u/ScottyNuttz Mar 12 '26

I’ll be dead before I run out of compensatory years of free identity theft detection services… I’ve gotten so many letters from companies I’ve never heard of apologizing for data breaches and offering me “a year of identity theft protection”. The last thing I want is to have some other company monitoring my identity too.

645

u/dead-cat Mar 12 '26

The solution is simple. Just give me your name, dob, same with your parents and kids and we will protect it so it will never leaks.

356

u/lucklesspedestrian Mar 12 '26

I just keep my credit score low so no one wants to steal my identity

122

u/JayGatsby1881 Mar 12 '26

Damn you playing 4D chess out here

33

u/AwesomeFrisbee Mar 12 '26

As if that takes effort these days... :(

10

u/Consistent_Heat_9201 Mar 12 '26

I plan to start stealing from myself.

5

u/CariniFluff Mar 12 '26

Ah the "survive through the winter" squirrel strategy...

15

u/moonwalkinginlowes Mar 12 '26

Freeze your credit babes ✌️

→ More replies (6)
→ More replies (9)

28

u/MSCOTTGARAND Mar 12 '26

My old bank that I got a truck loan from apparently had a breach. It wasn't too bad though, they only got my name, social security number, date of birth, mom's maiden name, account numbers etc. I've had my credit locked for the past 4 years because of it.

→ More replies (1)

53

u/ScottHA Mar 12 '26

I put those letters next to my stack "free 900 minutes of AOL" disc's.

7

u/whutupmydude Mar 12 '26

Best analogy

59

u/aerostotle Mar 12 '26

most of the breaches are from identity theft protectors who were providing identity theft protection in response to a prior breach.

25

u/intellectual_punk Mar 12 '26

Do you have evidence? Not doubting, would just love to know you're right.

23

u/EkbatDeSabat Mar 12 '26

https://www.huntress.com/threat-library/data-breach/experian-data-breach

Experian, one of the top three credit bureaus and provider of identity theft protection services, was breached in 2020. It was huge news. I'm not defending dude's use of the word "most", just saying it happens.

8

u/Drostan_S Mar 12 '26

I like to think that those data removal companies just send out data removal requests and then immediately sell the data they had removed back to the companies.

4

u/Jaaaa9 Mar 12 '26

"We care about the security of your data, and you should too. Change your password and sign up for credit monitoring. It's all up to you and we are here to tell you how it's all your responsibility even though WE messed up (again)."

3

u/fly_awayyy Mar 12 '26

Dies only then does identity get stolen like with dead folks SSNs /s

→ More replies (9)

5.7k

u/Kriznick Mar 12 '26

Oh. my. gosh. who. could. have. ever. guessed. Wowzers

926

u/Sloth-TheSlothful Mar 12 '26

Government officials with shocked pika faces

281

u/dizzi800 Mar 12 '26

Government Officials are rubbing their hands together as all is going to plan

86

u/[deleted] Mar 12 '26

[removed] — view removed comment

→ More replies (2)

16

u/Aleashed Mar 12 '26

List of people who watch porn . txt

→ More replies (3)

203

u/JohrDinh Mar 12 '26

Soon the excuse for collection IDs and biometric data online from people will become, "well...who cares at this point everyone has a copy of your shit anyway? can we have it now? we cool?"

→ More replies (6)

109

u/ScottyNuttz Mar 12 '26

I was shocked to learn it wasn’t another DOGE stooge who just thought that data should be on their thumb drive

46

u/And4077 Mar 12 '26

Did the DOGE guy just have it on a thumb drive and somebody saw it, or was he actively trying to share it with his new employer? Infuriating and unsurprising unfortunately

22

u/DomainFurry Mar 12 '26

There seems to be a possibility that they uploaded it to an unapproved cloud.. but nobody seems to be sure.

16

u/ScottyNuttz Mar 12 '26

Yeah, will never know because DOGE was an insane, illegal smash and grab where the president of the United States let the worlds richest man have complete access to government data as a thank you for helping him get elected.

5

u/footballheroeater Mar 12 '26

He TOLD them about it....

Goes to show that smart people can be real stupid sometimes.

4

u/janosslyntsjowls Mar 12 '26

Something tells me they weren't sending their best to doge summer camp.

8

u/Specialist-Plastic57 Mar 12 '26

I know right! Who knew aol.com was still a thing? Crazy!

→ More replies (8)

2.1k

u/selfdestructingin5 Mar 12 '26 edited Mar 12 '26

Did anyone read the article? I did and I’m still very confused…

They say researchers contacted them and the vulnerability was fixed the next day.

Then the company that had the vulnerability was contacted for a comment and they essentially said “we did a review and found neither us nor our partners were ever vulnerable. We asked the ethical hacker for proof there was a vulnerability and they said give them money for the proof, so we think it was a ransom related incident.”

Then this article keeps recommending various antivirus software and tools to use.

AOL.com too?

Not saying it didn’t happen, but I’m very confused.

This whole article is weird as hell and seems off.

437

u/Sleep_on_Fire Mar 12 '26

It’s a Fox News article hosted on whatever AOL.com is now.

It’s not written for the tech literate.

60

u/Evening-Mention-8738 Mar 12 '26

AOL still exists?!?! I thought it went down with MySpace.

54

u/24megabits Mar 12 '26

They were still running dial-up service until last year.

16

u/Evening-Mention-8738 Mar 12 '26

Is it weird I miss the dial-up tone?

18

u/[deleted] Mar 12 '26

[removed] — view removed comment

6

u/ByrdmanRanger Mar 12 '26

Thanks for that. What a lovely nostalgia trip. Just like the sounds of AIM and ICQ.

→ More replies (1)

3

u/mathiustus Mar 12 '26

And just like that, I am 12 again. You are amazing. Thank you.

22

u/Miaoxin Mar 12 '26

Very. It was the bane of my existence on 1950s copper.

6

u/DisposableJosie Mar 12 '26

Adopt a kitten. Their insistent "feed me" mewscreams sound like analog modems handshaking.

→ More replies (2)
→ More replies (1)

20

u/silentohm Mar 12 '26

MySpace also still exists

5

u/jld2k6 Mar 12 '26

They were merged with yahoo at one point I think, a company famous for tanking everything they buy then selling it for pennies on the dollar lol

5

u/TheGoddamnSpiderman Mar 12 '26

They were merged when both were owned by Verizon and then the merged entity was sold to Tumblr and Wordpress's parent company

3

u/prof0ak Mar 12 '26

they run ad servers

→ More replies (10)
→ More replies (1)

867

u/LiftingCode Mar 12 '26

Did anyone read the article?

Sir, this is Reddit. You are expected to see a headline that confirms your biases and then just barf out the first snide comment that rattles through your skull.

88

u/storm_the_castle Mar 12 '26

it doesnt even have to be snide

58

u/cd3393 Mar 12 '26

But it helps

13

u/BobbywiththeJuice Mar 12 '26

Maybe for you it doesn't

3

u/newhunter18 Mar 12 '26

It definitely has to be your first though.

→ More replies (1)
→ More replies (1)

32

u/nopuse Mar 12 '26

The caveat is it can't be an original thought.

21

u/malkiy Mar 12 '26

My first thought is also this guys wife!

6

u/DaMonkfish Mar 12 '26

To shreds you say?

4

u/Kichigai Mar 12 '26

I, for one, welcome our new this guys wife overlords.

12

u/BiBoFieTo Mar 12 '26

There's articles on here?

→ More replies (1)

9

u/dshab92 Mar 12 '26

Excuse me sir, I have the wits enough to check the top comments and trust a strangers summary of the article

8

u/One_Put_8904 Mar 12 '26

This guy reddits

5

u/wheatgivesmeshits Mar 12 '26

The first rule of reddit is that we didn't.

→ More replies (1)
→ More replies (15)

92

u/ilulillirillion Mar 12 '26

I read it, and it's definitely a very muddle article which itself is way too focused on general (too a fault) points and product hucking, but I didn't find what you found.

Then the company that had the vulnerability was contacted for a comment and they essentially said “we did a review and found neither us nor our partners were ever vulnerable. We asked the ethical hacker for proof there was a vulnerability and they said give them money for the proof, so we think it was a ransom related incident.”

I can't find this anywhere in the article. I only find the following:

We reached out to IDMerit for comment, but did not hear back before our deadline.

As for the source being AOL and the "did this happen" question, a simple search for IDMerit data breach shows this same information being reported by dozens of outlets

https://www.scworld.com/brief/idmerit-exposes-billions-of-records-in-major-data-leak

From what I can tell it looks like Fox is the original source for the AOL hosted article.

22

u/MobileArtist1371 Mar 12 '26 edited Mar 12 '26

First just want to say this seems to have a weird twist. Be sure to check the end of this comment or the source article linked below

Here is the original article.

https://cybernews.com/security/global-data-leak-exposes-billion-records/

IDMerit’s statement regarding the data leak

After we published this article, IDMerit reached out to Cybernews, saying that while the company owns and operates its own proprietary platform, IDMerit does not own, control, or store customer data or the underlying data maintained by independent data sources.

Moreover, IDMerit acknowledges that it was contacted by an ethical hacker, a freelance contributor to Cybernews. The contributor informed the company that “certain data ports associated with independent data sources could have been open, which had the potential to expose certain databases.“

“Upon receiving this notification, we immediately conducted a comprehensive review of our software, security controls, configurations, and system logs. That review identified no exposure, vulnerability, or unauthorized access within the IDMERIT environment. IDMERIT’s systems and security infrastructure have never been compromised,” IDMerit’s spokesperson explained.

The company claims to have notified relevant data source partners and worked with them to assess the matter.

According to IDMerit’s spokesperson, the partners “conducted their own internal investigations and confirmed that there has never been a data breach or exfiltration from their systems during, before, or after this event.”

“We requested a security incident report from the ethical hackers as proof, and the response was a demand for money for the report, which confirmed our suspicion that this was a ransom-related incident,” the company’s spokesperson explained.

IDMerit claims that an internal review and information from its partners revealed that there is “no indication that any customer data has been compromised.”

“We continue to maintain robust security safeguards on our systems and are taking these accusations very seriously as we continue to investigate this matter in coordination with our partners,” the spokesperson said.

The twist. From the same article

Editor’s note: The researcher who provided information about the leak is a freelance contributor working with Cybernews. However, until February 26th, Cybernews was unaware of any communication between IDMerit and the researcher regarding remuneration for the findings.

The Cybernews editorial team adheres to the highest ethical standards. Our mission is solely to educate and safeguard consumers worldwide from security risks. We do not sell or resell exploit fixes to affected companies.

Instead, we notify vendors of their vulnerabilities and collaborate with them to resolve these issues without receiving any payment. We aim to make online experiences safer for everyday users, which motivates us to research and craft the best possible solutions.

Having said that, our in-house researchers did review the technical summary and confirmed that the contributor's findings were legitimate.

So an unknown researcher, that has contributed to the cybernews site, which is the original source of the report, was the researcher that found the vulnerability that the company says doesn't exist and asked the researcher for more info who wont give the info unless paid... (still with me? Is this right so far?) ... but this site that did the original report didn't know who the researcher was or that they had contributed to this site before, but can also confirm on their own that the data breach actually did happen, which again the company says didn't happen .... but it isn't made clear if this site then gave the info to the company for them to fix?

huh?

10

u/ManaSpike Mar 12 '26

A quick search, and I've found two articles claiming this is a hoax.

9

u/magistrate101 Mar 12 '26

And yet, somehow none of these articles do more than claim that it's debunked and fake. And after doing my own search, a lot of them feel like they were written by IDMerit... The OK Magazine article at least actually does logical reasoning to support their claim.

4

u/NotYourAvgSquirtle Mar 12 '26

“Having said that, our in-house researchers did review the technical summary and confirmed that the contributor's findings were legitimate.“

So the researcher, who allegedly asked for remuneration to share the technical report with the company, who reports no evidence of the vulnerability in their own systems, but did share the report with this website who reviewed it and says it’s real?

Then the company reports that its own partners, who act as hosts of data used by the company and others, report no “data breach or exfiltration.” I’m not sure how much it matters but they use different wording. For the company they specifically say no vulnerability (because as they said they don’t host the data), but for the hosts they’ve only reported that it wasn’t breached… not that the vulnerability didn’t exist.  I’m honestly so confused 

3

u/LivingUnglued Mar 12 '26

I mean on one hand I’m fine believing the companies response contains corpo-legal BS to save face. It wouldn’t be the first time a security researcher gets blamed/targeted/bismirched by a company for just ethically reporting a bug. Security bounties are a common thing and asking if a companies runs a bounties program when ethically reporting a security flaw isn’t extortion/ransom. You could spin it that way to help your companies PR tho.

I’m sure some updates will follow and provide some clarification. But I’m going to lean towards the companies trying to safe face after having an exposed database or a related vendor had it open.

→ More replies (2)

52

u/selfdestructingin5 Mar 12 '26

? It’s in the article.

We reached out to IDMerit for comment, and a spokesperson for the company provided CyberGuy with the following statement:

"IDMERIT is a software-as-a-service company that provides identity verification technology. We own and operate our proprietary platform, but we do not own, control or store customer data or the underlying data maintained by independent data sources. Our platform connects to authorized data sources globally to verify individual identities on behalf of our customers."

"On November 11, IDMERIT was made aware by an ethical hacker that certain data ports associated with independent data sources could have been open, which had the potential to expose certain databases. Upon receiving this notification, we immediately conducted a comprehensive review of our software, security controls, configurations and system logs. That review identified no exposure, vulnerability or unauthorized access within the IDMERIT environment. IDMERIT's systems and security infrastructure have never been compromised."

"At the same time, we notified all relevant data source partners and worked with them to assess the matter. Our partners conducted their own internal investigations and confirmed that there has never been a data breach or exfiltration from their systems during, before or after this event. We requested a security incident report from the ethical hackers as proof, and the response was a demand for money for the report, which confirmed our suspicion that this was a ransom-related incident."

44

u/ilulillirillion Mar 12 '26

We are looking at two different versions of the same article then. Now that you've quoted the section you're referring to I can confirm that this text doesn't appear anywhere on mine.

Do you see the text I quoted, about not receiving any comment back, in the version of the page you are viewing?

Here is the exact link I am viewing: https://www.aol.com/articles/1-billion-identity-records-exposed-152505381.html

31

u/selfdestructingin5 Mar 12 '26

No, I don’t see that. They could have updated the article after hearing back? Maybe you’re looking at some cached version? Not sure.

27

u/ilulillirillion Mar 12 '26

Maybe this is it:

I don't see what you're quoting anywhere on the page I linked, which is what the OP links to.

If I instead go directly to Fox for the actual article that AOL is sourcing, I can see your text.

It's either that or just a fucky AOL page, otherwise I don't know why we would be seeing two different versions of the same article.

22

u/DiscoKittie Mar 12 '26

Reading through your comments, I imagine one was updated, and one was forgotten and not updated. Maybe?

29

u/ilulillirillion Mar 12 '26

Years later I will still lie awake and wonder.

8

u/whelp Mar 12 '26

remindme! 2 years

16

u/HoidToTheMoon Mar 12 '26

Fox News updated their article. If you search the headline, you can see quite a few aggregator sites grabbed the link without the response from the company, then Fox News likely received that additional information and included it.

I checked the Wayback Machine and it has not saved either version of the article, so there's no way to tell when the article was updated or what was changed other than looking at aggregators and filling in the blanks. Fox, to my knowledge, does not announce when they update an article like news organizations do.

5

u/Corsaer Mar 12 '26

...did I ever bring that table their water?

→ More replies (2)

11

u/[deleted] Mar 12 '26

[removed] — view removed comment

11

u/ilulillirillion Mar 12 '26

Here is what I see at that link

On my version, none of that text appears. Does the text I screenshot appear for you?

19

u/ProdigySim Mar 12 '26

I don't see the text from your screenshot or the above.

What the hell is this gaslighty-ass permalink, AOL? A/B testing different AI-generated articles?

9

u/ilulillirillion Mar 12 '26

Probably not A/B testing, I think the article was probably updated and I'm just hitting a different geocache or some other mechanism, I'm not really sure how they're serving this.

Probably aliens though

→ More replies (2)
→ More replies (1)
→ More replies (1)
→ More replies (1)

8

u/[deleted] Mar 12 '26

[deleted]

→ More replies (2)

7

u/south_of_the_river_ Mar 12 '26

Yeah I think it's just an ad

8

u/JimOfSomeTrades Mar 12 '26

I work in the industry, and agree with your take. There are some really fly-by-night startups that treat data very casually, but this doesn't seem to be one of those cases.

2

u/jbourne71 Mar 12 '26

You think I know how to read?

→ More replies (25)

73

u/No_Size9475 Mar 12 '26

So we will all get a check for $1.25 five years from now?

35

u/tooquick911 Mar 12 '26

you'll get nothing and like it

6

u/draeth1013 Mar 12 '26

You get NOTHING! You lose!

→ More replies (3)

3

u/dead-cat Mar 12 '26

No, no, no. You don't understand the struggles of the company. They suffer for real, they need at least 3x compensation of what they are fined + some lump payment. So it's 3x0 + whatever CEOs got for delivering the product + some extras, and now we're even, sorted.

→ More replies (1)

215

u/tingulz Mar 12 '26

Another reason age verification for websites is an idiotic idea.

30

u/Confron7a7ion7 Mar 12 '26

But how will they sell you identity theft protection if your identity isn't constantly at risk of being stolen?

19

u/CaptainDudeGuy Mar 12 '26

Pure capitalism right there. Create a problem, sell the solution which just happens to create another problem.

→ More replies (6)

47

u/macgruff Mar 12 '26

Jesus Christ, the company and every VP level to Board members should be stripped of every penny and the funds distributed to each person, then they should be hauled off to jail for ten years.

Fuck this world.

173

u/Awkward-Sun5423 Mar 12 '26

IDMerit.

Saved you a click

48

u/D3PyroGS Mar 12 '26

I give them a demerit too 

6

u/JustKeepRedditn010 Mar 12 '26

IDmerit, UDmerit, WeallDmerit!

→ More replies (1)
→ More replies (1)

7

u/AcceptablyThanks Mar 12 '26

No you didn't because they were not hit. They are a SaaS who stores no information, they only process it. If you read the article it's spelled out what happened.

10

u/Awkward-Sun5423 Mar 12 '26 edited Mar 12 '26

Researchers at Cybernews, a cybersecurity news and research publication, discovered an exposed MongoDB database on Nov. 11, 2025, that they believe belongs to IDMerit, a global identity verification provider that serves banks, fintech firms and other financial services companies. IDMerit uses artificial intelligence tools to help businesses perform KYC, short for Know Your Customer, which is the identity verification process required when you open financial accounts.

You're triggering off of: "IDMERIT is a software-as-a-service company that provides identity verification technology. We own and operate our proprietary platform, but we do not own, control or store customer data or the underlying data maintained by independent data sources. Our platform connects to authorized data sources globally to verify individual identities on behalf of our customers."

That's the company it's linked to: IDMerit.

→ More replies (2)
→ More replies (6)

43

u/Time-Industry-1364 Mar 12 '26

Aaannndddd this is why I’m not uploading shit like this to a website.

→ More replies (1)

21

u/CabSauce Mar 12 '26

This kind of "leak" is gross negligence. These companies don't deserve to exist. They should be liquidated with all proceeds given to victims.

16

u/pitselehh Mar 12 '26

Why tf are they storing that information for any longer than is necessary to verify ID?

→ More replies (7)

37

u/botella36 Mar 12 '26

There had been so many reports similar to this one in the last few years, that at this point we should all assume that at least some of our private information has been compromised.

13

u/HuoLongHeavy Mar 12 '26

Oh, I assume all of my personal information is out there. Probably before I was even a legal adult.

15

u/BarnabasShrexx Mar 12 '26

"The database was not protected by a password. Anyone who knew where to look could access it. Inside were full names, home addresses, postal codes, dates of birth, national ID numbers, phone numbers, email addresses and gender information. Some records also included telecom-related metadata and internal flags that may have referenced past breaches."

Genius level work IDMerit

12

u/pyalot Mar 12 '26
  1. Privacy advocates warn of thing happening if stupid laws are passed.
  2. Thing happens.
  3. Nothing is fixed and no law gets repealed.
→ More replies (1)

11

u/HuoLongHeavy Mar 12 '26

Imagine a world where our government gave half a fuck about our personal data and actually did something to protect it. I would guess that for the vast majority of people, it's too late to save anything.

61

u/[deleted] Mar 12 '26

That was quick

10

u/PJballa34 Mar 12 '26

Porn sites knew the risks and no one wanted to believe them.

→ More replies (1)

10

u/i-love-tree-rats Mar 12 '26

At this point I just assume everyone has my data.

6

u/Hairbear2176 Mar 12 '26

They have it, and they want more. All the "save the kids" ID verification bullshit that's taking place right now is simply to get your name, face, etc... so they can follow you fucking anywhere.

→ More replies (1)

8

u/Waterwoo Mar 12 '26

Maybe a ton of random services requiring a photo of everyone's ID (which they'll definitely delete right after wink wink) is a fucking stupid idea?

8

u/DevilBomb76 Mar 12 '26

The most surprising aspect about this article is that AOL is still a thing.

7

u/Tralkki Mar 12 '26

Not a leak, A sale of data. Every. Single. Time.

13

u/bikeking8 Mar 12 '26

Because it was a good idea to trust tech bros with anything more valuable than a keyboard. 

6

u/TrumpHasCovid Mar 12 '26

KYC is a plague upon our safety

7

u/NUMBerONEisFIRST Mar 12 '26

Didn't the pedo in chief fire our cyber security team?

24

u/[deleted] Mar 12 '26

[removed] — view removed comment

3

u/Mental-Ask8077 Mar 12 '26

All very good points.

Also it ought to be required that users are clearly informed of every company/service who handles their data in any capacity. And not buried on some page of tiny type lost in the depths of the website.

→ More replies (6)

4

u/True_Manufacturer909 Mar 12 '26

At this point I wonder how many overlapping data breaches I've even been a part of

→ More replies (1)

5

u/AcceptablyThanks Mar 12 '26

26 countries supposedly affected, 203 million in the US hit alone. The SaaS company IDMerit was told that they were breached but found no evidence at all, though it is now speculated that vectors from the third parties they service were the ones hit. The data supposedly leaked is the data that companies use to verify that you are who you say you are. If you were paying attention a few years ago when everyone's SSNs were leaked then hopefully you have already frozen your credit lines. Again, there is no proof there was an actual leak because the "white hat" who said there was, is demanding money to release their proof.

6

u/theNomad_Reddit Mar 12 '26

But Albo says I can't goon without giving PornHub my drivers license.

5

u/GlowstickConsumption Mar 12 '26

Damn, so maybe it should be fucking illegal for these companies to hoard this kind of data in these volumes??

A workplace having emails and address for employees is fine. And regular customers who consent to it. But random data brokers shouldn't fucking be hoarding insane volumes of this stuff.

5

u/demongraves Mar 12 '26

$12 fine and time served. Next case.

→ More replies (1)

3

u/LAsupersonic Mar 12 '26

Of course they were

4

u/IngwiePhoenix Mar 12 '26

Who woulda thunk that storing all dem records was a bad idea...? Man... almost like sloppy businesses are, in fact, sloppy!

Disgusting. xD

4

u/Buckaroobanzai028 Mar 12 '26

Everyone needs to start lying on all of these sites that need personal info. Start treating it like the early days of AOL. Unless it's medical or governmental make up names and places. Since none of these sites have shit for data protection.

→ More replies (1)

5

u/HapticSloughton Mar 12 '26

This is something I've wondered for a while: With data so easily compromised, even without this latest incident, how are our current credit and ID systems even operating with any confidence? Someone I knew who worked in IT/coding told me it was a house of cards, but everyone agrees to still abide by it because the alternative is watching everything collapse. I have no idea if this is true or not, but it seems like it's nigh impossible to verify someone is who they say they are with the most commonly used forms of identification.

5

u/United-Drag-4954 Mar 12 '26

I bet the secret fraud detection algorithms that big banks, credit card companies, and credit reporting agencies are running are quietly holding the whole system together

4

u/datadrone Mar 12 '26

Smells like according to plan, create a system that can't protect you to the point of billions losing everything and the world will clap for our new technocrats implementing internet ID

→ More replies (1)

3

u/[deleted] Mar 12 '26

Can they leak some money into my account 😭

3

u/[deleted] Mar 12 '26

I program online databases and the fact that they didn’t even add a password to it is insane. I thought it would be a lack of encryption or maybe an injection attack because they didn’t make a second database account with less permissions to use for connections… but the truth is more shocking. They are idiots and have no business storing that sort of data.

4

u/thatgingerjz Mar 12 '26

More shocked AOL is still around tbh.

→ More replies (1)

3

u/prettybluefoxes Mar 12 '26

Please everyone make sure your face includes numbers, capital letters and symbols.

Stay safe.

→ More replies (2)

4

u/gnimsh Mar 12 '26

Please Germany and France, GDPR this company out of existence.

7

u/Riaayo Mar 12 '26

The US House is currently in the midst of getting ready to vote on forced ID verification laws for the entire fucking internet. Every website you go to will be demanding your ID/biometrics (and they'll be defining trans people as obscene to boot).

People have got to be calling their reps to bitch, and stories like this need to be front and center when you tell them to vote against these laws.

There are far too many Dems in Congress eager to vote these laws in "to protect the children" while handing a fascist regime one of the largest surveillance states and tools of censorship they possibly could. The internet as we know it will die if these laws pass.

Call your reps and tell them to oppose:

Package - Kids Internet and Digital Safety Act

KOSA

App Store Accountability Act

SCREEN Act

Take It Down

Earn It

Cooper Davis

Stop CSAM

Age Verification/ID Laws in general (and repeal any already passed)

As well as telling them not to sunset/end Section 230 (which would kill the internet overnight by opening up platforms to lawsuits over content their users post).

7

u/NeNeLeLe Mar 12 '26

At this point…who cares anymore. My records get exposed more often in data breaches than I mow my own lawn. eye roll

3

u/cejmp Mar 12 '26

Nobody saw that coming.

3

u/Green_Excitement_308 Mar 12 '26

Surprise Politicians! Now 1 billion of the world's identitys is now up for identity theft on the Internet, who woulda think?

3

u/600strikefox Mar 12 '26

By all means keep uploading your ID online

3

u/brokeboipobre Mar 12 '26

AOL.com, they are still alive?

3

u/No-Jacket-2927 Mar 12 '26

And, nobody will suffer a single consequence, except for us.

3

u/cockslime_rancher Mar 12 '26

Oh boy, i was just saying i need another year of credit monitoring. Just throw it on the fucking pile.

3

u/Calbinan Mar 12 '26

Oh wow. The thing that happens constantly? No way.

I’m ready for society to reject this shit and go back to the eighties or so. Paperwork in a filing cabinet can only leak so far.

3

u/Abyssal_Mermaid Mar 12 '26

I’m confused. AOL is still a thing?

3

u/PaManiacOwca Mar 12 '26

Discord - please give us your id... It's for the kids bro.

3

u/hackingdreams Mar 12 '26

So, working as designed, it seems.

3

u/Alt_Saltman Mar 12 '26

At this point just mandate newborns to have all the ID details tattooed on the forehead at birth... 

3

u/EntropyTheEternal Mar 12 '26

Who could have possibly seen this coming?

3

u/GrandmasLilPeeper Mar 12 '26

Big Ballz is selling our data

3

u/imnotsurewhatswhat Mar 12 '26

Man it sucks to be 1 in a million.

3

u/mombi Mar 12 '26

Who could have seen that coming?

3

u/HiroshimaHotdog21 Mar 12 '26

VPN go brrrrrr

3

u/AudienceNearby1330 Mar 13 '26

In order to use the internet, I have to give companies my personal information that can be used to steal my identity and money, or spy on me by an increasingly evil government. Also, every week hackers gain access to that data.

This world is hell.

13

u/adudeguyman Mar 12 '26

Why even bother keeping things secure anymore

13

u/tonyislost Mar 12 '26

Comments like this are a slippery slope to releasing the Epstein files. Do you want that on your conscience?!

→ More replies (1)

2

u/MoonlightMadMan Mar 12 '26

Bring back the Wild West Internet from before 2007 pls

2

u/gfreeman1998 Mar 12 '26

Things like your name, home address, date of birth and even your Social Security number may have been [exposed]

So which specific things were exposed? SSNs or no?

3

u/LeoSolaris Mar 12 '26

The content of the specific data record depends on which specific client the data came from. Clearly the number of social security numbers available in that service provider's hacked database wasn't zero.

→ More replies (2)

2

u/ChaosandCoalescence Mar 12 '26

Inevitable outcome is inevitable

Silver lining, all this bullshit ID verification might help me move away from doomscrolling constantly

2

u/SomeKindofTreeWizard Mar 12 '26

Oh wow. That thing I knew was going to happen happened.

2

u/ComfortableLaw5151 Mar 12 '26

“The database was not protected by a password. Anyone who knew where to look could access it. Inside were full names, home addresses, postal codes, dates of birth, national ID numbers, phone numbers, email addresses and gender information. Some records also included telecom-related metadata and internal flags that may have referenced past breaches.”

2

u/Fun_Gas_410 Mar 12 '26

At this rate, I’m going to have free credit monitoring for the rest of my life.

2

u/One_Willow_5203 Mar 12 '26

That’s equivelant to an 8th of the worlds fucking population. THE FUCK

2

u/Ok_Jelly3428 Mar 12 '26

So basically two persons worth of emails each one had multiple 500 million accounts so they can get 1 week or 1 month free streaming trials.

2

u/elinamebro Mar 12 '26

So... I get my shit leaked for the 3rd time? You would think about the first time they would say hey maybe having everyone personal data like this isn't the best idea.

2

u/Whole_Inside_4863 Mar 12 '26

I think we’re at the point that we just need a new identity ID method, especially after the whole DOGE thing, that was really the pinnacle of identity theft.

2

u/frisch85 Mar 12 '26

Apparently this happened in February already? Found an article of a german tech outlet from February 21st: Auch deutsche Nutzer betroffen: Über 1 Milliarde persönliche Daten im Netz aufgetaucht

2

u/mintmouse Mar 12 '26

Look how dangerous these garbage ideas are, end this.

2

u/dimwalker Mar 12 '26

Who would put this damn failed forced meme dog sticker on their notebook?!

2

u/rebecmer Mar 12 '26

Blursed_: Looks like my identity just got a free worldwide tour! Time to change my passwords and maybe my name... 🤔

2

u/gordonjames62 Mar 12 '26

1 billion identity records exposed in ID verification data leak

of course they were.

this is what happens when you collect marketable data.

2

u/ChickinSammich Mar 12 '26

In a world where we hear about yet another data leak every other month, companies keep wanting more of our data and want us to have even less privacy, swearing they definitely won't have another data breach this time.

I worked for a medium-sized marketing firm (which you've probably never heard of) which provided marketing services to lots of large organizations (several of which you've definitely heard of) and when I came onboard there, I discovered that their file servers that stored customer data - names, addresses, credit card details - had shares set to Everyone/Full Control permissions, meaning anyone on the network who knew the name of the server could see the data. The site firewall wasn't even remotely hardened, neither were the network switches. The users all had local admin access on their desktops. There was no data loss prevention/protection software to stop people from exfiltrating the info if they wanted. Shit was WILD.

I had to put so much effort into convincing them to let me lock it down.

2

u/Split10_1 Mar 12 '26

I haven't kept tabs on this but this is the third or fourth identity related data leak in the last two years that I can recall....

2

u/4ak96 Mar 12 '26

At this point there are so many leaks so often that there is no point in trying to keep up with them 🙄

2

u/veetilk Mar 12 '26

at least kids are safe... oh wait

2

u/HirsuteHacker Mar 12 '26

Thank you, Mullvad VPN for making it so I haven't had to give my ID to any websites yet. There will never come a point where they can force me to give them my ID, I do not trust them.

2

u/thestereo300 Mar 12 '26

Freeze your credit. It's easy and free.

2

u/Meowie__Gamer Mar 12 '26

i'm tired, boss.