Comment by zero_k

2 days ago

If you are interested in the original, high-quality article: https://krebsonsecurity.com/2026/09/fbi-probes-service-selli...

Only in case you are interested in the original source, of course. If you like the copywrited version of it, you can go to techdirt :)

This comment is worrisome:

> My Chase bank account was hacked early this year despite having 2 factor authentication, and when I contacted them to ask how, they said because the person used my actual driver’s license to verify their identity and remove my security features from the account.

  • I feel like that should require an in-person visit, as troublesome as that might be. A picture of an ID is not the same thing as presenting the actual ID

  • Sometimes I feel it's a blessing that for even a minor change my banks make me visit the branch and ask for my real Govt issued IDs (often more than one) while also make me do the online auth (Govt ID; needs OTP and biometric) and still make me submit self-attested print-outs and then add a delay to it (and even reject once in a while if they feel the signature didn't match..and then the cycle restarts :D). I know, I know - there is a solution of this on hn and it will even scale handsomely. But I'd rather have my hard earned savings safe.

  • Wouldn't this also mean Gmail, Facebook, etc are no longer safe? The person can simply provide this documentation as proof they own the accounts and claim they were hacked.

    • Facebook is definitely safe. I provided my ID to try to regain access to a hacked account and they never even responded to the request.

> "The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit."

Mr Krebs is dealing with all this mayhem and idiocy with remarkable sang froid if I may say so. Good heavens.