
153 Million Driver's Licenses Stolen, Nigerian Sextortion Rings, and Team PCP's OPSEC Failure
Welcome to The Low Down, the best show on the internet for hackers The Low Down is presented by Maze. LinkedIn: https://www.linkedin.com/company/mazehq/ X: https://twitter.com/Maze_Security Follow Us! https://www.instagram.com/lowdown.pod This week we're diving into massive identity verification breaches, the arrest of Team PCP supply chain attackers, and the certified pre owned router epidemic that's turning your home network into a botnet. Today we're talking about: ID Scan Breach: 153 Million Driver's Licenses Leaked Breaking down the massive data breach exposing 153 million driver's licenses, 10 million identification cards, 3 million travel documents, and 579,000 medical cards from ID scan dot net. How Brian Krebs traced his own leaked license back to a Hertz rental car transaction and marijuana dispensary visits at DEF CON. Why third party identity verification services create single points of failure when companies like Target, FedEx, GameStop, and hotels all use the same scanning infrastructure. The Identity Verification Debate: Privacy vs Security Examining the cultural backdrop of identity verification laws spreading across Europe and the UK's push to de anonymize internet activity in the name of protecting children. Why Discord now requires ID verification for adult content servers and Pornhub refuses to comply by shutting off access to entire states. The fundamental problem of companies being entrusted with sensitive documents they aren't equipped to secure and how driver's licenses are becoming the new social security numbers in account recovery flows. McKesson Healthcare Breach: 284 Million Patient Records Stolen Shiny Hunters claims responsibility for compromising McKesson, the pharmaceutical giant responsible for a third of all US drug transactions with 403 billion in annual revenue. Deep dive into Shiny Hunters' sophisticated MO combining social engineering over phone and text, fake company Okta logins using Evil Nginx proxies, and specialized teams ready to exfiltrate OAuth tokens at machine speed across geographically distributed locations. Team PCP Arrested: The Supply Chain Attackers Roll Up Australian authorities arrest the Team PCP threat actors behind massive NPM supply chain attacks including the Mini Shaihalud worm, LightLLM compromise, and Trivi security tool breach. How Flare's OSINT investigation traced the DeadcatX3 alias across GitHub, HackerOne, Hugging Face, and eBay to reveal real identity Ruben Thompson through catastrophic OPSEC failures. Why some in the security community are defending Team PCP as hackers of old exposing systemic flaws rather than profiting from stolen credentials. The Hacker Culture Divide: Altruism vs Cybercrime Exploring the thinning veil between career cybersecurity and hacker culture as the Free Team PCP movement emerges. Examining whether Team PCP was following the old school ethos of hacking to expose vulnerabilities without profiting versus crossing into criminal territory. Why they slurped up AWS credentials, Kubernetes secrets, and crypto wallet keys but never used them beyond NPM and GitHub propagation. The philosophical question of whether demonstrating supply chain fragility justifies the method. Meter AI Safety Org Compromised: The Irony of Expertise The nonprofit AI safety organization called in to analyze the Hugging Face OpenAI incident suffers their own breach with 600,000 dollars in API usage stolen. Why calling in Meter instead of actual incident response firms like Unit 42, CrowdStrike, or Mandiant represents the sidelining of cybersecurity expertise in AI safety conversations. Breaking down the vibe coded app with fail open vulnerability that silently disabled authentication and exposed agent orchestration dashboards to the public internet. NVIDIA Acquires Hugging Face: The 13 Billion Dollar Question NVIDIA purchases Hugging Face for 13 billion dollars as founders walk away with 3 billion each. Revisiting the conspiracy theory about potential collusion between OpenAI and Hugging Face to reposition OpenAI as the premier cyber model provider. The surge protector plugged into itself problem of Jensen Wong, Microsoft, OpenAI, and Oracle passing the same 100 million between multi trillion dollar valuations. Info Stealers Target Claude API Tokens Popular info stealer malware including Vidar, Luma C2, Steal C, and Redline add new functionality specifically for hijacking Claude sessions to rack up API usage bills. Why stealing AI tokens is more creative than crypto mining and represents a new monetization model for compromised systems. Nigerian Sextortion Rings: From Scams to Suicides 404 Media investigation follows cyber sleuths who flew to Nigeria to track down sextortion scammers targeting teenage victims with compromising photos leading to extortion and suicide. How the same tactics used by threat actor groups like The Comm and Shiny Hunters to recruit young males into cybercrime through blackmail. Breaking down
- Transcript









