Federal legislative action on intimate imagery and a confirmed 170-million-record identity breach together mark the most consequential 24-hour period for US privacy enforcement architecture in months. The TAKE IT DOWN Act is now Public Law No. 119-12, closing a gap in federal statute by criminalizing nonconsensual intimate imagery including AI-generated deepfakes and imposing platform takedown obligations. Simultaneously, IDScan.net has confirmed that its database of over 170 million scanned identity documents — 153 million of them driver's licenses — was subject to unauthorized access, with Brian Krebs reporting an ongoing compromise rather than a discrete exfiltration. These two developments, read together, reinforce a structural vulnerability in US identity infrastructure: the widespread practice of retaining raw document scans by third-party verification providers creates concentrated targets that downstream regulatory minimization requirements have not yet eliminated.
Watch level: PREPARE (social media platforms, content hosting operators, identity verification vendors, compliance counsel with US exposure)