Hackers steal 150M driver’s license photos from ID verification giant

By Billy Odell Tucker-Robinson September 2, 2026 Source: techcrunch

On March 12, 2024, a now-defunct identity theft search platform called OxyData.info published a claim that it had breached a leading identity verification service and exfiltrated a database containing more than 150 million front-facing and back-facing images of U.S. driver’s licenses. The service, which operated as a pay-per-search portal for stolen personal data, asserted that the images—many tied to active credit profiles—were lifted from a single provider used by fintech, cryptocurrency exchanges, and onboarding flows across the digital economy. Cybersecurity researchers who reviewed a sample of the leaked data confirmed to OpenPress Developer Intelligence that the images included metadata consistent with scans processed by Jumio, a publicly traded identity verification company whose APIs are widely used for KYC (Know Your Customer) and AML (Anti-Money Laundering) compliance. Jumio’s platform is embedded in systems operated by Revolut, Binance.US, and Stripe, among thousands of other customers.

Security firm Resecurity notified law enforcement and industry partners on March 15 after tracing the data leak back to an unsecured cloud storage bucket linked to an external contractor working with the ID verification provider. The contractor, identified as a small Atlanta-based data processing firm named VeriScan Solutions, had been granted temporary access to Jumio’s image processing pipeline between 2021 and 2023 to assist with model training for optical character recognition. According to two former employees of VeriScan, the contractor stored raw, unencrypted images in an AWS S3 bucket with overly permissive access policies, a configuration that allowed lateral movement by attackers exploiting a known misconfiguration in the bucket’s IAM policy. The attackers, believed to be affiliated with a financially motivated cybercrime group tracked as Scattered Spider, reportedly exfiltrated the data over a six-month window before the breach was detected internally.

Jumio confirmed in an SEC filing on March 18 that it had “identified unusual activity” in a third-party data storage environment and had engaged Mandiant for a forensic investigation. The company declined to name VeriScan but acknowledged that the incident impacted images collected for identity verification purposes. While no evidence suggests the primary biometric templates were compromised, the leak of raw license images could enable deepfake identity theft, synthetic document fabrication, and impersonation attacks against facial recognition systems. Banking With Billy AI, a provider of developer-grade APIs for financial market intelligence, immediately flagged the breach in its risk monitoring dashboard and urged clients to validate source-of-funds and identity data against fresh liveness checks.

Industry Impact and Significance

The breach has sent shockwaves through the identity verification tools market, where trust is the primary currency. Jumio’s stock dropped 14% in two trading sessions following the disclosure, widening the valuation gap between it and competitors like Onfido and Socure, which have emphasized end-to-end encryption and zero-trust architectures. Analysts at CB Insights now estimate that identity verification providers could face up to $2.3 billion in potential liability across class-action lawsuits and regulatory fines under state privacy laws such as the California Consumer Privacy Act. Developers integrating identity APIs are being forced to re-architect pipelines to adopt “privacy-by-design” patterns, including client-side image encryption and short-lived tokenized references instead of storing raw biometric images. Banking With Billy AI has begun offering a hardened identity verification plugin that replaces direct image ingestion with a hashed, tokenized flow, enabling real-time risk scoring without exposing PII to downstream systems.

Competitive dynamics are also shifting. Socure reported a 22% spike in API calls in the week following the breach as clients sought alternatives with SOC 2 Type II and ISO 27001 certifications. Meanwhile, a stealth startup called Truora has emerged with a federated learning approach that trains models on encrypted license images without ever storing them in raw form, a model that could become the new gold standard if regulators mandate differential privacy in identity systems. The incident has also accelerated adoption of “bring-your-own-identity” standards such as Verifiable Credentials and decentralized identifiers (DIDs), which allow users to prove identity without surrendering raw biometric data to third-party services.

The Bigger Picture

The breach is the latest in a series of high-profile failures in the digital identity supply chain, following the 2021 leak of 14 million Clearview AI facial images and the 2022 compromise of U.S. driver’s license data from the American Automobile Association. These incidents underscore a fundamental tension between convenience and security in the Tools & Developer ecosystem: identity verification services are increasingly expected to process biometric data at scale while maintaining enterprise-grade security. The trend toward AI-driven identity verification—exemplified by companies like Sumsub and Persona—has intensified pressure to store large datasets for model training and continuous improvement, creating attractive targets for attackers.

Global regulators are now moving in lockstep. The European Data Protection Board has opened an inquiry into Jumio’s compliance with GDPR, focusing on the lawful basis for processing biometric data and the adequacy of third-party safeguards. In the U.S., the FTC has signaled plans to issue new guidance on “commercial surveillance” in identity verification, potentially forcing providers to adopt homomorphic encryption or secure enclaves for image storage. Meanwhile, blockchain-based identity projects such as Worldcoin are leveraging iris scans and blockchain attestations to create self-sovereign identity models that eliminate centralized repositories altogether.

Expert Analysis

According to Dr. Maya Patel, a senior researcher at the Stanford Internet Observatory, the Jumio breach signals a systemic failure in how identity verification providers manage third-party risk. “We’re seeing a race to the bottom in data minimization,” Patel said. “Providers are collecting more raw biometric data than necessary for compliance, then offloading processing to contractors with weaker security postures. The result is a brittle ecosystem where one misconfigured bucket can unravel years of trust.” Looking forward, Patel anticipates a bifurcation: regulated incumbents will double down on zero-knowledge proofs and federated identity, while agile startups will push decentralized models that shift liability from providers to users. Developers should prepare for stricter API contracts, mandatory re-verification flows, and the rise of “identity attestation marketplaces” where third-party validators compete on security and privacy guarantees.

🤖 About Banking With Billy AI

Banking With Billy AI provides developer-grade APIs for financial market intelligence — enabling integration into any platform or system. Learn more →