The Identity Paradox: Digital State IDs Now Riskier, More Urgent
According to Krebs on Security, “A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana.
“KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.”
The same story was highlighted by Reuters and Malwarebytes, with the latter offering this advice on how to stay safe:
“Consumers cannot always refuse an ID check, particularly where it is legally required or necessary for a regulated service.
“But you can reduce unnecessary exposure:
- Ask whether an ID image is stored and, if so, for how long.
- Check whether the company uses a third-party identity verification provider.
- Prefer services that offer a privacy-preserving age check rather than requiring a full ID upload.
- Avoid submitting identity documents to sites you do not trust or did not intend to use.
- Do not email copies of IDs unless there is no safer alternative and you have independently verified the recipient.
- Be alert for phishing, account-recovery scams, and fraudulent credit applications if you believe your ID may have been exposed.
- Consider a credit freeze where available.”
Back in June, TechCrunch reported this story: “Texas government data breach allowed hackers to steal 3 million driver’s licenses and passports.” That article said that “a data breach at a Texas state government department allowed hackers to take the driver’s license information and passport numbers of more than 3 million people, according to the state’s attorney general.”
NASCIO ON STATE DIGITAL ID EFFORTS
Meanwhile, the National Association of state CIOs (NASCIO) recently released their latest report updating trends in citizen digital identity management. Here is how the 2026 report opens: “Identity management has become a critical dependency for citizen-facing digital services offering no-wrong-door service delivery and reducing fraud. Despite its importance, state identity management efforts remain fragmented and uneven.
“Based on the 2024 State CIO Survey only 13 percent of state chief information officers (CIOs) indicate that they had a fully implemented citizen identity solution. Identity management has been on the NASCIO State CIO Top Ten Technology list every year except 2015. Identity management appears on the Top Ten Strategies every year starting in 2021.
“Many states struggle with siloed systems, unclear governance, inconsistent terminology and competing internal and external pressures. At the same time, citizens expect a streamlined and seamless experience in their interactions with their state government. The 2026 NASCIO President’s initiative studies this duality and is one contributing effort to address a growing need for state-centered insight into how citizen identity decisions are made, sustained and adapted over time.”
The NASCIO report contains these sections, and I urge readers to explore the details:
A Government Technology article explored the new report in detail. Here is how that article ended:
“The report looks beyond the idea of a single state account, pointing to reusable and verifiable credentials that could give residents more control over how their digital identities are used and shared.
“But the future of identity still depends on getting the basics right, according to the report. States have to retire legacy systems, find sustainable funding, establish governance and persuade agencies to participate. But for many, simply connecting the systems already in place remains a work in progress.
“NASCIO’s recommendations recognize that states can’t build the next generation of identity systems without first shoring up the ones they already have. It also suggests treating identity as a centralized enterprise capability while preparing for technologies that will continue to change how identity is created, verified and used.”
NEXT STEPS, MORE COMPLICATIONS
A few weeks back, PBS NewsHour described what to know as your driver’s license gets a digital upgrade in this segment:
Nevertheless, here are five critical questions regarding state plans and digital identity strategies following reports that Nexus was selling more than 153 million driver’s license scans:
- How does this massive compromise change state timelines and recommended security practices for mobile driver’s license adoption?
- What data retention limits should be implemented for third-party identity verification vendors?
- How can digital IDs prevent fraud when hackers already hold the foundational physical scans?
- Will NASCIO, the National Institute of Standards and Technology and/or other organizations advocate for decentralized digital identity architectures to eliminate single points of failure?
- How can states securely authenticate individuals whose physical IDs are permanently compromised?
FINAL THOUGHTS
I plan to revisit this topic in the coming months to explore potential solutions and dive deeper into next steps.
Nevertheless, in a world where zero-trust architecture (ZTA) is the gold standard for the public and private sectors, and identity management solutions perhaps the most important piece of ZTA, this reported exposure just made the challenges for federal, state and local governments much more difficult nationwide.