Exposé

Your Passport Is Already Leaking

Governments and platforms now demand your ID to use the internet. The systems holding those IDs keep spilling them onto the open web — more than two million documents in a matter of months.

Here is what they may already have: your passport scan, your driver's license, possibly the selfie you took to prove the documents were yours. Not because you were careless — because someone you were required to trust was.

Over the past few months, a string of security lapses has exposed more than two million people's government-issued identity documents, according to reporting by TechCrunch. A hotel check-in system left roughly a million passports and driver's licenses open for anyone to see. A Canadian money transfer app, Duc, exposed driver's licenses and passports on an unsecured Amazon server. A prison payphone provider, Pay-Tel, publicly exposed the driver's licenses of more than 300,000 callers. A UK visa portal spilled thousands of applicants' passports and selfies online — and, at the time of reporting, hadn't fixed the leak.

None of these were sophisticated attacks. Most were simple misconfigurations — documents parked on servers with no lock on the door, discovered by researchers doing what criminals do quietly.

The timing could hardly be worse

These spills land in the middle of a global push to attach real identity to online life. Age-verification laws are spreading across the United States and Europe, requiring adults to hand over identity documents to access growing swaths of the internet. Platforms are leaning on know-your-customer checks that demand a passport or license scan before letting users in.

The logic of these systems assumes the documents stay secret. The record says they don't. Every new checkpoint creates a new stockpile, and 2026 has demonstrated what happens to stockpiles: the ShinyHunters extortion gang alone has taken some 40 million records from internet provider Charter, at least 6 million customer records from cruise operator Carnival, and data on more than 30 million students and staff from education platform Canvas. When market-research firm Klue was breached this year, the fallout reached nearly 200 companies — including security firms LastPass, HackerOne, and Jamf — through a single pilot credential issued in 2022 and never decommissioned.

And identity checks themselves are proving porous in both directions. TechCrunch reported in May that some children were defeating age-verification selfie checks with a fake mustache. Meanwhile, hackers hijacked tens of thousands of Instagram accounts by simply asking Meta's AI chatbot to send password reset codes to addresses they controlled, according to reporting by 404 Media and The New York Times.

The question nobody answers

A leaked password can be changed. A leaked passport cannot. Each of these documents anchors a person's legal identity for a decade or more, and each copy now circulating makes every identity-verification system that relies on such documents a little less trustworthy — which, in turn, is used to justify collecting even more.

The companies involved say the exposures have been closed. The laws mandating collection keep passing. What no regulator has yet explained is the math at the center of it: if the internet cannot keep two million identity documents off the open web in a single season, what happens when it is holding two billion?