Skip to main content
Emerging ThreatsData Breaches

AI-Powered Attacks Target ID Databases

Well-lit laptop screen displays dark web market listing in cluttered, organized room.

"A database of 153 million drivers licenses is for sale on the dark web."

153 million driver's licenses listed on the dark web

The source reports that a dataset containing 153 million drivers licenses is being offered for sale on dark web markets. That single figure frames the scale of the problem: copies of primary identification documents from tens of millions of people are circulating beyond the control of the organisations that collected them. The post presents that number as a prompt to reassess long-standing practices for collecting and storing ID documents.

"Current AI LLM Systems" and the acceleration of attacks

The source argues that the landscape is changing because "Current AI LLM Systems" can automate processes that previously required human attackers to discover and exploit vulnerabilities. Where once a skilled operator might probe a database or a workflow repeatedly, the source says generative systems can run those processes "many many times faster than humans." The implication offered is simple and stark: expect a rapid increase in attacks against databases that hold ID documents.

Are centralised ID-document databases sensible?

The source poses a direct policy question: "Is it wise or even sensible to hold databases of ID documents where attackers either external or internal to the holding organisation can reach them?" The answer given is blunt — "No but with exceptions" — and those exceptions are narrowly defined as "To those carrying out a task where ID is actually required." The point emphasises that truly legitimate need for primary ID is rare, and that widespread collection and storage of copies is therefore an unnecessary risk.

"Think of the children" and the drive to make ID compulsory for everything

The source criticises what it calls a "great stupidity" in recent efforts to make "ID compulsory for everything," citing a pattern of using any excuse to force access to and storage of copies of ID documents. One commonly invoked rationale is framed as the "faux excuse of the old, 'Think of the children'" together with appeals to "online access" to websites. The source also contends that such protections are illusory because "there is always an exploitable gap between tangible physical objects and intangible information objects that always exists at the sensor." It adds that children and adolescents are often capable of hacking systems, noting that cyber-crime statistics support that point.

What this means for technologists, policymakers, and the public

  • Technologists and security teams: Expect more automated, high-velocity probing and exploitation of systems that hold ID documents as "Current AI LLM Systems" are applied to attack workflows. The source implies an operational imperative to stop hoarding copies of primary IDs unless truly necessary.
  • Policymakers and regulators: The source urges a rapid "rethink" of requirements that force collection and storage of primary ID documents. It frames the current state of affairs as "well beyond a liability for each and every person," signalling a need for policy limits on when agencies or companies may demand and retain ID copies.
  • The general public and organisations that collect IDs: The source counsels restraint — only provide or retain primary ID where a task absolutely requires it. The broader takeaway is that routine expectations of producing scanned IDs for minor services expose individuals to outsized risk.

There is a practical through-line to the source's argument: if vast numbers of ID documents are stored in reachable databases, and automated AI systems can accelerate attacks against those holdings, then the simplest — and most effective — countermeasure is to stop collecting and storing what is not strictly needed. That bottom-line recommendation is presented not as a technological fix but as a behavioural and policy change: limit access, limit retention, and limit the demand for primary IDs.

If the sale of 153 million driver's licenses is the canary in the coal mine, the question the source leaves emphatic is this: why continue to build and centralise reservoirs of our most sensitive primary identifiers when fewer than a handful of tasks truly require them? The source urges a rapid re-evaluation — and warns that without it, the liability is no longer theoretical.

https://www.schneier.com/blog/archives/2026/09/drivers_license_data_for_sale.html