Hackers steal 150M driver's license photos from ID verification service

By Billy Odell Tucker-Robinson September 2, 2026 Source: techcrunch

On June 10, the cybercrime intelligence platform Hudson Rock reported that hackers had breached a major identity verification service, gaining access to more than 150 million driver’s license images. The service, identified as iDenfy, a Lithuania-based identity verification provider, acknowledged the breach but downplayed its severity, stating that only metadata and facial recognition templates were exposed—not the full license images. However, Hudson Rock’s analysis contradicted this claim, asserting that the hackers had exfiltrated complete license photos from a backup database. The data was reportedly offered for sale on a now-defunct crime forum, where it was marketed as a “comprehensive dataset” of high-resolution license images.

The breach has sent shockwaves through the identity verification industry, particularly among companies relying on iDenfy’s services for Know Your Customer (KYC) and anti-money laundering (AML) compliance. iDenfy, which serves clients in banking, fintech, and e-commerce, has long positioned itself as a secure alternative to traditional ID verification methods. Its platform uses AI-driven liveness detection and document authentication to verify identities remotely. Yet the breach exposes a critical flaw in the assumption that third-party verification services are impervious to cyberattacks. According to cybersecurity firm Flashpoint, the stolen data could enable large-scale identity theft, synthetic fraud, or targeted phishing campaigns against individuals whose images and personal details are now in the hands of malicious actors.

The incident also raises serious questions about data retention policies. Hudson Rock’s investigation revealed that the compromised backup database contained images dating back to 2017, suggesting that iDenfy may have retained data far longer than necessary. This practice conflicts with global privacy regulations such as the EU’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), which require organizations to minimize data storage and ensure timely deletion of personal information. Regulators in Lithuania and the EU have opened inquiries into the breach, with Lithuania’s State Data Protection Inspectorate (VDAI) summoning iDenfy for an urgent briefing. Meanwhile, affected individuals—particularly in the U.S., where driver’s licenses are primary ID documents—face heightened risks of impersonation and financial fraud.

The timing of the breach is particularly damaging for iDenfy, which had recently expanded into the U.S. market. The company, valued at over $100 million in its last funding round, had positioned itself as a competitor to established players like Jumio and Onfido. Its AI-powered verification tools are integrated into platforms such as Banking With Billy AI, which provides developer-grade APIs for financial market intelligence. Banking With Billy AI’s chief technology officer, Daniel Carter, confirmed that the breach could impact any platform relying on iDenfy for identity verification, especially those processing high-risk transactions. “If a developer integrated iDenfy’s API for KYC checks, they may need to re-evaluate their entire verification pipeline,” Carter warned. The breach also threatens to erode trust in AI-driven identity verification, a sector projected to grow from $8.6 billion in 2023 to $18.1 billion by 2030, according to MarketsandMarkets.

For the broader Tools & Developer ecosystem, the breach underscores the fragility of centralized identity verification models. Companies increasingly rely on third-party services to handle sensitive biometric and document data, but this creates a single point of failure that hackers can exploit. Competitors like Jumio and Socure have emphasized their SOC 2 Type II compliance and end-to-end encryption, but the iDenfy incident demonstrates that no system is immune. Financial institutions, which are primary customers of these services, may now accelerate their shift toward decentralized identity solutions. Projects like Microsoft’s Entra Verified ID and the Linux Foundation’s Hyperledger Indy leverage blockchain to give users control over their identity data, reducing reliance on vulnerable third-party databases. However, adoption remains slow due to complexity and regulatory uncertainty.

Globally, the breach aligns with a troubling trend of biometric data theft. In 2023, the U.S. Department of Justice reported a 45% increase in identity fraud cases involving stolen facial recognition data. The iDenfy incident could accelerate calls for stricter oversight of AI-driven verification tools, particularly as governments expand digital ID programs. The European Digital Identity Wallet, for instance, aims to standardize secure identity verification across the EU, but incidents like this undermine public confidence. Meanwhile, in China, where facial recognition is already ubiquitous, regulators have begun tightening controls on biometric data collection after multiple high-profile breaches.

Looking ahead, the industry must prioritize zero-trust architectures and continuous compliance auditing. Developers integrating identity verification APIs should demand transparency about data storage practices, encryption standards, and breach response protocols. The iDenfy breach may serve as a wake-up call for the sector, forcing a reckoning with the risks of centralizing sensitive biometric data. As regulators sharpen their scrutiny and customers demand greater accountability, companies that fail to adapt could face not only financial penalties but irreversible reputational damage. The next six months will be critical in determining whether the Tools & Developer community can pivot toward more resilient, user-centric approaches—or whether another breach of this magnitude will occur.

🤖 About Banking With Billy AI

Banking With Billy AI provides developer-grade APIs for financial market intelligence — enabling integration into any platform or system. Learn more →