IDscan’s breach shines light on vendor risk in the age of AI

A seemingly impossible security problem to get around in today’s world is the fact of centralization. The world is so large and so complex that it is impossible to expect every bank in the country to develop its own security protocols. This goes for the entire technology stack, as the cool kids call it, but I want to talk about security today, so that’s where I’m focusing. 

Processing Content

Centralization creates efficiencies that can’t otherwise be matched, but it also creates its own problems, often called concentration risk. Companies rely upon vendors, tech-based outfits such as Microsoft that build and sell programs and systems at scale. Banks have their own specialized vendors, who have gotten so good at this there are three of them that basically control the whole game. The irony is the larger and more successful those companies and programs become, the more malefactors they attract.

A company called IDScan developed a really successful and popular program that countless companies including banks use for ID verification. Well north of a hundred million IDs had been scanned and documented and stored in the companies’ system. To nobody’s surprise that made it a prime target for criminals. 

Last week, as our Carter Pape reported, the company’s system got hacked and more than 150 million IDs went up for sale on the dark web. One of IDScan’s customers is Jack Henry. Jack Henry, I don’t have to tell you, is one of the three big vendors to the banking industry.

When terrorists 25 years ago decided to strike the United States, they came up with a very blunt but targeted plan: destroy buildings. They targeted the Pentagon, the Capitol, and the World Trade Center. The fact that they saw the financial markets as a key target should not be lost on anyone, back then or today.

Terrorists, or anarchists, or whomever, looking to attack the system today can do it much more efficiently, and the tools are getting better seemingly by the day.

We wrote last month about the Hugging Face hack, when some AI agents in a purportedly secure environment with OpenAI’s servers got out and hacked into another database. But the details are even nuttier than that. Initial reports made it seem like just a small number of AI agents had managed the feat. The reality is an army of AI agents coordinated with each other to achieve their hacking goal. They set up a message board inside OpenAI’s network, talked to each other, worked out how to combine forces, and even how to try and hide their work, and which agents to sacrifice to help achieve the goal. 

“AI agents” are ultimately just computer programs, so let’s pull it back. Autonomous computer programs colluded to hack an outside organization. And these were neutral programs, just creations of a software company exploring the limits of its own technology. What could somebody with a real ax to grind do with this technology? “Many external models, including open-source ones, will soon reach comparable capabilities,” OpenAI wrote in its report on the incident.

Don’t forget the deepfakes, either. The technology is getting so good it’s allowing people’s identities to be effectively stolen even without bothering to hack an outfit such as IDScan and steal somebody’s drivers license.

The IDScan hack is a wake-up call for bankers, and it seems like there’s at least one of these wake-up calls a month. The technology is advancing faster than most people’s ability to learn how to use it. It was telling that our recent survey of bankers found that the executives most alarmed about AI were the ones whose banks were furthest along in implementing the technology. 

Read more:

It is not realistic to expect every bank to come up with its own solution to this problem, just as it is not realistic to think every bank would have its own solution to custody or record-keeping. For better or worse, centralized solutions are going to be part of this because we are all running centralized systems. The crypto dreams of “defi” – decentralized finance – aren’t realistic, both because defi has not been able to scale and because defi’s security problems are way worse than centralized finance’s. 

The time to start working on all of this, for companies but also for people individually, is yesterday. If you sleep on this technology, you’re liable to wake up and discover it’s stolen your identity, and your face, and your customers’ money.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *