
Srsly Risky Biz: America's drivers licence breach is a national security disaster
About this episode
Tom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences.
They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough.
Finally, they talk about how often cryptocurrency hackers claim to be white hat hackers. Its ludicrous, but suprisingly often it is a successful strategy.
This episode is also available on YouTube
Show notes
Get every episode summarized
Each time Risky Bulletin publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
260 searchable segments. Every word is indexed and playable.
Full transcript
Risky Bulletin — Srsly Risky Biz: America's drivers licence breach is a national security disaster. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Hey everyone, I'm James Wilson and welcome to this week's Seriously Risky Bizz. This is our Cybersecurity Policy and Intelligence Podcast and it is based on the awesome newsletter that my colleague Tom Uren writes. You can find Tom's newsletter, seriously Risky Business, over at our website Risky.bizz where you can read the newsletter and also subscribe to it so that it lands in your inbox every week. Tom will of course be along shortly to chat with me about the newsletter but first a big thanks to the sponsor for this week which is authentic. They make an open source IDP and I published an interview this week with their CEO, Fletcher Heisler, about how having a really good identity story for AI agents actually begins with a very flexible privileged access management system. So do check that out if that's something of interest to you. But back to Tom's newsletter, three topics for this week. The first one is this just gigantic breach of a US and Canadian driver's licenses that
was uncovered and reported by Brian Krebs of Krebs on Security this week. We then talk about how the US military has finally done far too little, far too late to prevent ad tracking from being able to allow adversaries to track troop movements. But then we also talk about how this incredible event this week with a hacker making off with $320 million worth of Bitcoin from the Liquid Network Exchange. But it's okay, there are a white hat. They returned a five percent of it. Does that allow them to get away with it? Will they get away with it? Will they ever be able to spend a cent of that? We'll go into this as well. But I'm going to drop you in here where Tom starts to talk about this incredible breach of an identity database that contains just an eye-watering number of drivers licenses for US and Canadian individuals. And not just the scale of it, but how it was uncovered by Brian Krebs.
But more importantly, what does this mean from a national security point of view? Enjoy. Brian Krebs, who runs Krebs on Security, he was tipped off that someone was selling a breach or access to identity documents on the dark web. He had a look, the site purports to have 150 odd million drivers licenses. And it said that it was getting it by basically kind of scraping from a top-tier identity verification service. And he observed that over the course of a day, it added I think an extra 400,000 records. That's a hell of a scrape. That's huge. Yeah. And so it seems like they had real-time access to whatever the system was doing and each time, maybe not real-time, but of these regular access. And each time a license was submitted, it was hoovering it up.
And so the drivers licenses were the most significant part. The vast majority of them were American. There was some Canadian as well. And it did a bit of sleuthing and figured out, I think it's this service. And I think based on talking to people who knew this is the way that it's happening. And it's, you know, some people had gone to Hertz, show a driver's license, boom, end up in the database that day. And so this is, I think the scale of the hack is huge or the breach. And the group responsible who called themselves Nexus, they said that they'd sucked it all up into a private database. So it wasn't as if they were querying the corporate database. They set it aside. So the data is gone. Yeah, it doesn't, this doesn't seem like an open API that they're just querying on demand. This seems like this is a persistent connection into this that they are downloading,
almost in real-time, as you said, these, these databases, these credentials and have stockpiled them. And just one thing I want to mention, the time you mentioned that Hertz was involved here. And yes, that's one of the correlation points that Brian Crabis found was that, he and his mum had scanned their licenses at Hertz, and that sort of, they ended up in this data said, but it's not Hertz that was breached. It's actually this identity provider ID scan. Is that your understanding as well? Yeah, so it seems like there's a variety of firms that do identity verification. And it's like this kind of vicious circle where so many licenses have been leaked that it's easy for people to make up for original ones. So you need a service to check that they're okay. And but the service that checks that's okay has turned out to be looks like it's vulnerable. So there's even more drivers licenses that are out there. So the virtuous cycle of fake IDs is no doubt set to continue. But there's more to this, right? You made the point in the newsletter here. You began with explaining that what the real value here for a, for a particularly for a
adversary or, you know, from a, I guess a national security perspective is the linking of these identifiers. And I found that fascinating because I hadn't sort of put two to get two and two together here is to just how interesting, important and I guess expansionary that this data said could be to the intelligence community. So talk us through that. So there's a, I guess a history here in the mid 2010s. The Chinese state went on a kind of data rampage, which describe it as, so they still stole data from the most sensationally from the Office of Personal Management, which manages US government security glareds. So that's got a wealth of information about people in the intelligence community. So that is really bad. But then they also in the years surrounding that stole data from places like Marriott, Hotel bookings, United Airlines, Flights, Anthem, which is a health insurance
company. And if you combine those data sets, you can really go a lot further. And there's a reporting from Zach Dorthman, who says that everyone in the intelligence community is completely convinced that the Chinese use this data to wrap up a whole lot of intelligence networks that the CIA in particular was running. And so working or being an agent for the CIA became very, very difficult around that time. So there's not been another string of similar hacks from that's been attributed to China since then. So a question is why would you not continue to get that data? One hypothesis is that you just buy it from data brokers and you've got a historical repository and you can just keep adding to it. That would make sense. Another is that you just naffle up these databases when they appear on the dark web. So in the piece I talk about Bellincat. So there's
the CIA people have told reporters they think the Chinese are using this. Bellincat is an investigative research outfit that takes the same sort of data in Russia and figures out what the Russians have been up to. And they've got published over the years some really interesting stories about how they've they've pivoted from one database to another and looked at people like identifying the suspects in the poisoning of Sergei Skryple, who was a former, he is a defector from the Russian KGB. I believe it was the KGB. Ended up in Britain was poisoned by three individuals with Novichuk nerve agent. And Bellincat also used the same sorts of data to find a Russian deep cover agent trying to penetrate an 8-0 headquarters in Naples. And so they go through the mechanics of how you pivot from one database to another. Now licenses are particularly good because you they're a key identity
document. You use them all the time to sign up for other services. So often the license number is kind of a key that you can pivot from one database to another. And by combining and pivoting off those databases you get a really complete picture of what someone has been up to. How useful is it now that they've got a guess a photo of this person as well? Right? It's one thing to have identified as you can pivot around but it is there. Is this really like the next level of usefulness to an adversary because as to now they can put a face to the name as well? I think that's particularly useful nowadays like maybe 10 years ago it would have been okay it's nice to have a photo but how can we use it? Nowadays there's a lot of really good facial recognition technology. So I think that does make a difference as well. And Bellincat's talked about things like people who weren't in databases before. That can be an indicator. And so this is a very comprehensive database. It gives you a lot of room to do that kind of analysis. And you can imagine that the
people who are staying in hotels booking rental cars they're the sort of people who are actually of interest to intelligence agencies. If you stay at home and you never go anywhere, never book into a hotel, never visit a rental car company. Probably you're not doing anything that is of interest to an intelligence agency. So in a way it's kind of self-selected for people who are are interesting, higher value. And so I think it becomes quite a valuable data set. And because it can be used for linking and because it was so comprehensive. I think I figured out maybe 60% of the US population. Yeah I saw that in the newsletter. 60% of all I think licenses you mentioned, which is just it's staggering in terms of coverage. But also you also mentioned the newsletter. This is not, I mean it's huge but it's not a nice later thing. You document a couple of the other breaches. And so I guess before we move on to the next story, what's the so what of this? What happens now? Do we get to see some sweeping regulation? Do we see government
intervention? Or do we just get to see more breaches too? Well my initial thought was there are some industries in the states that are regulated because they contain or deal with sensitive data. So there's health regulation about how you handle health information. There's stuff around the financial services industry because of for the same reason. And it seems to me that like there is a justification for having tighter regulation around identity verification because of the sensitivity of the data and because it affects so many people. I'm realistic though this current government and Congress is not going to do anything about it. I think it's all in the too hard basket. So the only positive news is there's been a whole suite of lawsuits already announced without even having confirmed proof that ID scan is the company that's been breached. I think it's good to highlight that there are financial costs to having poor security.
I'm also hopeful that maybe the FTC might do something. They've continued to look at data brokers who have been dealing with information very, very loosely and putting a bit of pressure there. So it's something that FTC might take up the Federal Trade Commission. All right. Let's wait and see what happens. Let's move on now to the US's sudden implementation of a measure around ad tracking. But I remember talking with you about this around June. I think that was when Reuters confirmed that there was commercial location data being used to target US personnel in the Middle East. At the time, I think they talked about some of the measures they were going to put in place and we all collectively just sort of rolled our eyes and said that does not sound particularly convincing. But now it turns out they weren't even doing the basics. Tom, what happened? Yeah. So at the time of that story, which was a couple of months ago, I looked at department of defense policy and it said, we should remove advertising identifiers from our
devices. So the story is that by default, some operating systems have an advertising identifier that is permanent and attached to the machine. And that gets data based all the time when you're dealing with the internet. And so the Apple's iPhone doesn't, but Google's does. It's a thing you can switch off. And the policy said we should switch it off. But it turns out they weren't switching it off because the latest letter we've got is that at least for some elements of the military, they only just switched them off recently in the last couple of months. So they had a policy that seemed to me to be the bare minimum. And they weren't necessarily implementing that. So Reuters has a story where it says, you know, the Air Force turned them off a couple of months ago, the Army turned them off particular devices within the last couple of months. So it's a very mixed picture. And so basically as a whole, the US military was not robustly implementing the policy
they already had is my takeaway. But even when you say that's the bare minimums, let's be clear, this is not the bare minimum in terms of a viable measure that will meaningfully or materially impact tracking of people, right? Because this is just one identifier. Isn't the whole ad tech ecosystem like almost at this stage designed to be resilient to these identifiers already being turned off by users? Yeah, yeah. So I think it is like it's a complicated picture. So the identifiers existed because they were really helpful for advertisers. Everyone wants to make money. Like that's the point of the internet if you've got a certain point of view. And so there are, I guess you would call them compensating controls for advertisers where they can use different techniques. And the big companies like Google, Facebook, Play this game where they appear to have protections that they kind of know don't necessarily work or their work around. And so I'm not convinced that
just switching off those identifiers is all that effective. Having said that, when you've got them, it's really like super easy analysis. So it is making things harder because you've got to do more steps to overcome that if you're an adversary. I mean, in this case, we're talking about a run. And I think the picture is also complicated because it's not necessarily the only way that you would do things. And so like if you're the US military, you're deployed in the Middle East, it is obvious that you've got bases. So like, so in a sense, removing identifiers, like, doesn't hide the bases, doesn't make them magically disappear. So it's a holistic picture of one of the things that are really revealed by this. The example we had was a particular, the story at least, was that a particular demountable had been struck. And that makes sense as a place you'd want to try and hide because it wasn't, I don't believe it was on a military base.
And so it was away from air defense, I suppose. And so you would want to keep that secret. I think probably removing the identifier would make it harder to identify that particular facility as a target. The difficulty created in that is only going to run up against how incentivize the adversary is, right? And an advertiser has shown they've got no problem at all overcoming this to make a buck. So I would imagine an adversary is also going to have not too much trouble overcoming this if the goal here is to successfully put warheads on, four heads in, in the battle space. Yeah, I think it's really problematic. And I think that my over all take away is that if they had taken the problem seriously five years ago, they would not be in this situation now. I think it takes some effort to figure out what is the right mix of controls between military own devices, personal devices, where bases are, you know, so maybe for that demountable, it is
no phones whatsoever anywhere nearby. Like maybe that is the sensible approach. And when the potential is for missiles to land on you, I think that's a reasonable mitigation, right? Yeah. But you've got to do the work to figure out if that's what you want to do. And they haven't done that. And that's evidence because they just only switched them off in the last couple of months when it's like, oh, OMG, there's this report, there's these reports that that's how we're being targeted. That's not good. Let's do something about it now. Yeah, but just so incredible to see so little being done, so incredibly late. You know, you mentioned there the internet's purposes to make money, at least in some people's view. Let's talk about the last story here, which is an incredible way that an individual has made quite a sum of money on the internet and on the blockchains in particular this week. We're talking about the liquid attack on, or the liquid network, I guess it is, cryptocurrency platform where there was a theft of $320 million worth of Bitcoin, but it's all right,
Tom, their White Hat Hackers and their Returned, right? So they've returned 85%. And this triggered discussion of skibits HQ, like returning 85% and keeping what, $40, $50 million, that's not White Hat hacking, that's not a bug bounty, that's just stealing a whole lot. And I actually looked at the history of this and there's actually a pretty successful track record of people stealing vast amounts of money, returning most of it and then at least so far getting away, Scott free, as far as I can tell, like there's no reports of arrests subsequently. And so this particular case, it's not necessarily done yet in the sense that they've returned 85%, there could well be a negotiation about, I'm going to return more, how much am I going to get to keep? Now the FBI, in previous cases, has said, look, it's not up to the victim to decide whether they've committed
a crime and whether they can get away, Scott free. Like we have the FBI's own agency, law is notionally independent. But is there a point in time when there could be an actual legally binding document created between the attacker and the victim here where they do actually nominate this as yes, we're contractually now ended into an agreement where we are paying this individual, I don't know, 5%. So one of the stories is, I think it was three years ago, this individual called Abraham Eisenberg, he executed what he called a trading strategy, a highly profitable trading strategy on this system called Mango Networks. And he took out through some sort of market manipulation, I think it was 120 million US dollars worth of cryptocurrency, that drove the entire exchange broke, he returned $67 million worth,
and that basically recapitalized it. And the governance mechanism of the exchange voted to give him $47 million worth of cryptocurrency. Wow. And so he was like, yeah, everything was legit, I followed the rules, it just so happens that the creators of the exchange didn't understand the implications of their rules. And so he was charged and prosecuted by the FBI, found guilty of market manipulation and fraud, and then a judge subsequently overturned that. And basically agreed with his premise that he didn't convince anyone of anything, he just looked at the rules and took advantage of the rules. Well, this is the fascinating thing about all of these defires, and you know, blockchains is, you know, there's this notion of the code is the law, and therefore, you know, does that not make all trades legal? Yeah, so I think I'm more of a realist, and I think
that the whole point of judicial systems is to prevent people making off with hundreds of millions of dollars that doesn't belong to them, no matter what the code says. Pregnantist may be realist, I don't know, but then I don't work in Wall Street or cryptocurrency, where it seems like occasionally this kind of thing does happen. It is lawful on you go. But to me, most of the advantage of of claiming you're a white hat is actually in the self deception. I think if you're a North Korean criminal cyber criminal, you used to stealing crypto currency, you've got a kind of pathway of I get the crypto, I launder it, job done. There's no need to, there's no need to deceive myself and think I'm a white hat. Right, I'm just doing doing my job is what I do. I think in these cases a lot of the people don't have that pathway of what am I going to do once I've got it? How do I launder it? How do I not ever get caught? And I think this gives them the belief that maybe I can steal
600 million dollars and get away with some of that and live my life peacefully ever afterwards without worrying about being hounded by the police. Well, that's the thing I was curious about. It's all good and well to have kept this 50 odd million dollars, but are they ever going to get to spend a cent of that? I think the historically what has happened is that they've often kept quite a large amount. And then they've, I think the first return, the first tranche is like, he's the good wheel tranche. Now let's get down to brass tax and negotiate what I actually get to keep out of the out of the rest. And so that has happened, I think with poly networks, it was one of the other ones I looked at. The hacker initially returned quite a large amount, kept I think $33 million. And that was eventually like negotiated down to, we'll give you a $500,000 reward. So still a pretty good payday. And I think it's small enough that like, let's be real, everyone who's working in this industry wants to
make out like a bandit and get a super rich. And so no one is incentivized to actually find the culprit and punish them. They all just want to move on so that they can also become super rich somehow with through some scheme. You can't be the next bandit if you're going to go and chase the bandits down. That's right. It's a waste of time to chase another bandit when you've got your own scheme. Amazing. I mean, look at it. It'd be utterly fascicle if it weren't just for the sheer volumes of money involved. But it's still as fast as it is. But it's it's fast as well with big dollar signs, which just makes it even more difficult to comprehend. But Tom, I will say I, it's funny that we were talking about this in the actual use of the money and how to loan to actually cut up this week with Jeff White, who's an investigative journalist, who's done series on the Lazarus Highs and also now the Conti Files. And he and I recorded a feature episode about exactly how the ransomware in particular paid by Bitcoin are being converted into hard cash and how this is not actually just
benefiting the ransomware actors, but also it actually sets up this interesting bilateral trade where street crime and drug dealers actually benefit out of this conversion of Bitcoin into hard cash, because they similarly want hard cash into Bitcoin. So that'll drop into the features feed next week. So do check that out as well if you're interested in how this becomes cash. So that's interesting. All right, Tom, great newsletter. This was a really cracking read. Thanks so much for dropping by, mate. I'll see you next week. Thanks James.
More episodes
More from Risky Bulletin

Risky Bulletin: Anthropic agents went hacking again
Risky Bulletin

Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal
Risky Bulletin

Between Two Nerds: Can AI defend critical infrastructure?
Risky Bulletin

Risky Bulletin: BEC campaign steals €35 million from French notaries
Risky Bulletin