September 8, 2026 |
4 min ReadEvery Identity Verification Breach Has the Same Root Cause: Data That Should Have Been Deleted
In late August, security journalist Brian Krebs uncovered a new dark web marketplace selling scanned driver’s licenses — claiming to have more than 153 million of them, U.S. and Canadian, along with millions of other ID, travel, and medical documents. His own license was posted as a free sample. The sellers claimed to have been pulling data out continuously for more than a year, and law enforcement opened an investigation days later. As of this writing, no vendor has been confirmed as the source of the leak.
Data breaches like this aren’t new
In August 2019, security researchers gained direct access to an unprotected database run by a biometric access control provider used by thousands of buildings worldwide. It held fingerprint data, facial recognition templates, and photos for more than a million people — no encryption required to read it. The company’s own response was cautious rather than an admission, but the researchers had already verified the exposure firsthand.
In June 2024, journalists reported that an identity verification service used by several major consumer platforms to confirm who their users really are had left an administrative dashboard exposed for over a year, reachable with credentials stolen by malware on an employee’s laptop. The dashboard held names, birthdates, ID numbers, and scanned government documents. The company confirmed the exposure in a statement, saying personal data was “potentially accessible” but that it had found no evidence of misuse.
Different companies, different products, same decision
Biometric access control and general-purpose identity verification aren’t the same business, and the two companies aren’t competitors. What they share is a five-year gap between two confirmed breaches, and the same underlying decision behind both: each one was holding a large, growing archive of exactly the documents an identity thief wants, for far longer than any individual verification required. Whatever turns out to have caused the marketplace leak, the shape of that story matches a pattern that’s already been confirmed twice elsewhere.
Verification companies are supposed to be the trustworthy ones
That’s what makes this kind of breach different from an ordinary retailer breach. Nobody chooses to hand their fingerprint or their ID scan to the vendor that ends up breached. They hand it to a gym, an app, a landlord, a bank — companies that outsource the actual verification to specialists precisely because those vendors are supposed to be better at handling identity documents securely than they are. The verification layer exists to reduce risk. When it becomes the leak instead, it does the opposite, and it does so at a scale no single retailer breach could match, because one vendor’s archive holds records from every business that ever used it.
Security investment fixes the wrong variable
Both companies presumably had security programs, incident response plans, encryption somewhere. Neither prevented the exposure, and in both cases the exposure sat there for a long time before anyone noticed: one database was unprotected outright, the other’s exposed credentials went undetected for more than a year. The question isn’t whether the next identity verification vendor will invest enough in security — most will say they do, and some will even be right. It’s whether they kept data they had already finished using. A dashboard that’s protected today and forgotten in eighteen months is still a dashboard. An archive that’s encrypted is still an archive. Security reduces the odds of a breach. It doesn’t reduce what’s lost when one happens anyway, because that number is set entirely by how much was kept.
The fix is structural, not another layer of defense
The alternative isn’t asking verification companies to verify less. It’s asking a different question of them: once you’ve confirmed someone is who they say they are, why do you still have the document? Verification against a source of truth, like checking directly with the institution or agency that already has the authoritative record, doesn’t require keeping a copy of somebody’s documentation as evidence you did your job. Deletion on a defined schedule, or no retention at all, means a breach eighteen months from now finds nothing worth stealing.
That’s the standard we hold ourselves to at Proxi.id: verify against the source, delete what we collect on a rolling basis, and never build the kind of archive that makes a company a target in the first place. The next marketplace, dashboard, or unprotected database is already being built by some vendor, somewhere, one unnecessary year of retained data at a time. The only reliable way not to be it is to not have the data when someone comes looking.
Ask your verification vendor what they keep
Proxi.id verifies against the source and deletes what it collects on a rolling basis — so there’s no archive of your customers’ documents sitting around waiting to be breached.
Talk to Us