FB pixel

From face biometrics to ID forgeries: lax data security fuels ID fraud

From face biometrics to ID forgeries: lax data security fuels ID fraud
 

In a wave of data breaches over the last year, several organizations have carelessly exposed large troves of sensitive personal information, heightening fears of identity theft and fraud. In a step further than exposed data, 404 Media recently uncovered an underground site that sells videos and photos of real people to pass some biometric KYC checks for online services. The investigation reveals that these faces are being sold on the dark web and used to commit various forms of financial and identity fraud.

Fraudsters sometimes pay individuals to take photos and videos they can sell to others to carry out attacks, 404 reports, possibly in combination with fake ID document creation services like the recently-revealed OnlyFakes.

The creation and distribution of counterfeit identification documents using stolen personal information is not the only way identity verification is being compromised. In another recent incident, security systems company Blink recently exposed thousands of driver’s licenses and passports due to a security flaw. Cybernews reports that the breach was caused by a misconfigured Amazon Web Services (AWS) S3 bucket, which was left publicly accessible. The compromised data includes images of driver’s licenses, passports, and other identification documents uploaded by users for verification purposes.

Last year, Leverage Edu, an educational consulting firm, exposed over 100,000 student passports and other sensitive documents. The breach, also discovered by Cybernews, revealed that a misconfigured server allowed unauthorized access to a trove of personal information. The exposed data includes scanned copies of passports, academic records, and other personal details submitted by students seeking educational opportunities abroad.

Leverage Edu acknowledged the breach and assured affected individuals that steps are being taken to secure the compromised server and prevent future incidents. However, the exposure of such documents raised concerns about the potential for identity theft and fraud.

Adding to the growing list of data breaches, Evolve Bank & Trust and the LockBit ransomware group suffered a breach that impacted thousands of customers. According to a blog post by Socure, the breach involved unauthorized access to sensitive customer information, including social security numbers, account details, and transaction histories.

The implications of this breach were extensive, exposing fintech partners and their clients to a range of identity theft and fraud threats, from synthetic identity fraud to account takeovers.

Accordingly, Socure recommends service providers implement robust, passive liveness detection to protect against spoofed selfie biometrics.

Related Posts

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

OpenAI joins FIDO Alliance to help AI agent authentication push

OpenAI is the newest member of the FIDO Alliance, joining the passwordless authentication group to contribute to its efforts to…

 

iDenfy integrates reusable digital IDs to help businesses avoid onboarding fails

Businesses have long been dealing with a common behavioral issue when clients attempt their Know Your Customer (KYC) onboarding workflow:…

 

UK public mostly happy with ‘age verification’ laws, campaigners less so

Age assurance may not stop that many children from accessing online pornography, but it’s a good idea anyway, according to…

 

Authsignal brings identity orchestration to IATA as airlines modernize authentication

Authsignal has joined the International Air Transport Association’s (IATA) Strategic Partnership Program. The announcement follows IATA’s World Data Symposium in…

 

Self Labs acquires startup Loam to build agentic AI’s digital identity infrastructure

Zero-Knowledge Proof (ZKP) identity verification and proof-of-personhood (PoP) company Self Labs has completed the acquisition of U.S.-based AI agent and automation…

 

Arizona Wallet creator AstreaX launches digital ID app

Government software and digital identity developer AstreaX has officially launched its mobile wallet, which will be used by the U.S….

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events