Verification became the leak
An unauthorized live feed of every ID verification let attackers bypass MFA for over a year. Why readable verification output stops being proof.
An unauthorized party had a live feed of every ID verification the company scanned. This ran for over a year. The feed was used to bypass multi-factor authentication. That is the position, and it does not soften.
Identity verification is a control. It exists to confirm a person is who they claim to be before access is granted. When that control produces a live feed an attacker can read, it is no longer confirming identity. It is broadcasting it. The scan that was supposed to prove identity became the data that defeated the check.
This is not a privacy incident dressed up as a breach. This is a control that was readable in real time by the kind of party it was built to stop. Everything that depended on that verification step inherited its exposure. MFA was one of those dependents, and MFA was bypassed.
What failed is the boundary around the verification data. Every ID the company scanned appeared on a feed available to an unauthorized party. Not a sample. Not a stored copy pulled later. A live feed, which means the data was available to the attacker at the same time it was available to the legitimate process. The scan and the theft of the scan happened together.
The verification control kept operating. Scans continued. Results were produced. From the outside, the system behaved as designed. That is the part leadership must hold. The control did not stop. The exposure was not ended for over a year while a second consumer read its output. Continuous operation and continuous compromise were the same condition, not two separate events.
Multi-factor authentication failed as a direct consequence. MFA assumes the factors it checks are known only to the legitimate parties. When the verification feed is readable by an attacker, one of those factors is no longer restricted to the legitimate parties. The attacker did not break the MFA mechanism. The attacker was handed the input the mechanism trusts. Whether access was gained beyond MFA bypass is not confirmed.
The mechanism is availability. A verification scan is proof of identity. Proof of identity holds value only while access to it is controlled. Every scan the company produced was available to an unauthorized party at the same time it was available to the legitimate process. Two parties held the same proof. At that point it is no longer proof of a single identity. It is a shared credential.
The feed was live. That word is the mechanism, not decoration. A stored copy is a single theft with a fixed blast radius. A live feed is continuous supply. For over a year, every new scan reached the attacker at the same moment it was created. There was no window that opened and closed. The exposure refreshed itself with every legitimate verification the company performed.
MFA was bypassed because it trusted a factor that was no longer restricted. The factor was not weak. The channel that carried it was open to an unauthorized reader. Where that channel opened, and how the feed was established, is not confirmed. What is confirmed is the result. The data that authenticated users was available to a party authenticating against them, and the control that relied on that data could not tell the difference between the two.
The mechanism is a single proof held by two parties at the same instant. A verification scan carries value only while one party holds it. The live feed placed every scan in the hands of an unauthorized reader at the moment of creation. Two holders, one proof. The value of proof is exclusivity. Remove exclusivity and the artifact stays identical while its function inverts. It no longer proves one identity to one system. It presents the same identity to whoever reads the channel.
MFA consumed that artifact as an input. MFA does not test where its input came from. It tests whether the input matches. When the same input is available to an unauthorized party, the match succeeds for that party on the same terms. The mechanism did not degrade the factor. It duplicated the factor’s availability. A duplicated factor authenticates every holder equally. The control held no property that separated the legitimate holder from the reader of the feed, because the data it checked was identical in both hands.
Live is the operative property. A stored copy is a fixed quantity of proof. A live feed is a production line. For over a year every scan the company generated was delivered to the unauthorized party as it was generated. The supply did not depend on a past theft. It depended on continued legitimate operation. Each valid verification the company performed refilled the attacker’s input. The control’s normal function was the attacker’s source. There was no separate exfiltration event to detect, because the exfiltration was the output itself.
The pattern is that a verification control whose output is readable by an unauthorized party becomes a supplier of the thing it verifies. Verification produces a value that downstream systems treat as proof. That value is proof only while its channel is restricted. When the channel is open to a second reader, the same control that confirms identity also distributes it. The function does not change. The audience does. One added reader converts a confirmation system into a distribution system for confirmed identities.
Every control that trusted the verification output inherited its exposure. MFA is the confirmed instance. The general form is that any downstream check consuming an upstream verification result assumes that result is exclusive to legitimate parties. That assumption is not a control. It is a dependency. When exclusivity is not enforced at the point the output is produced, every consumer of the output authenticates on data an unauthorized party also holds. The weakness is not located in any single consumer. It is located in the shared assumption that the output was private. Whether consumers beyond MFA existed is not confirmed. The structure that exposed MFA would expose any of them identically.
The example is the feed itself, read the other direction. The company built a control to decide who is who before granting access. That same control, once readable, told an unauthorized party exactly what a legitimate verification looks like at the instant it occurs. The mechanism that authenticated users became the mechanism that briefed the party authenticating against them. Same data, same moment, opposite purpose. The pattern holds wherever a verification output travels on a channel whose reader set is assumed rather than enforced. If the reader set is not controlled, the proof is not proof. It is a broadcast at zero delay.
Treat verification output as a credential, because that is what it became. A scan that authenticates is functionally a secret. Any channel that carries it must be enforced as restricted at the point of production, not assumed restricted by design intent. If exclusivity of the output is not enforced, the output cannot be trusted as a factor, and any control that trusts it is ineffective by inheritance. MFA here was ineffective. It did not fail to run. It ran against an input an unauthorized party held. A control that authenticates the attacker on the same terms as the user is not a control. State it plainly.
Continuous operation is not evidence of containment. For over a year the system produced correct verifications while an unauthorized party read them. Correct output and active compromise were one condition, not two. Any assurance model that reads “the control is running” as “the control is sound” would have reported healthy across the entire period. What must be true going forward is that the reader set of every verification channel is validated continuously, not established once and trusted after. Identity is the boundary. A boundary that is never checked against who is reading it is a boundary in name only.
The hard part is what the live feed proves about assumption. If a system allows an output to be read, it will be read, and the duration is set by the reader, not the owner. This ran for over a year. The endpoints of that window beyond its stated length are not confirmed, and that absence is itself the finding. A channel whose readers are not enforced offers no signal of when it opened or whether it is closed. What must now be true is short. No downstream control may trust an input whose exclusivity is not enforced at its source. Verification output must be governed as the credential it is. Everything else is restatement.
See also: NordVPN for tunneled traffic when operating outside controlled networks.
#ad Contains an affiliate link.
Keep Reading
access controlSaying you built it proves nothing
A contested 'vibe code' claim shows why self-reported origin accepted without verification is an unenforced control, not a trust boundary.
digital rightsdemand is not a control
Stop Killing Games gathered 13 million signatures and produced no EU law. The proposed approach lacked granular data access control and identity verification.
data breachFBI probes sale of 153 million license records
An FBI probe into a service selling 153 million driver's license records shows why static identity data cannot be rotated, recalled, or trusted as proof.
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.