Cybercrime is converging on a single resource: verified identity data. One story shows 150 million driver's licenses stolen, another shows identity as the target in roughly half of confirmed malicious activity, and two more show attackers automating exploitation and monetizing at scale. The common thread is that identity is no longer just a target, it is the input that makes industrialized attacks possible.
The Warehouse and the Workbench
IDScan's breach matters less as a single incident than as an inventory problem. As TechCrunch reported, the ID verification company confirmed that more than 150 million driver's licenses and other government-issued identity documents were taken, along with full names. That is not a list of passwords a consumer can rotate. It is a durable, standardized credential that US banks, landlords, employers, and government agencies treat as proof of who someone is. Fraudulent access built on that data does not expire when a user changes a password.
Prophet Security's finding, reported by BleepingComputer, that identity was the target in roughly half of all confirmed malicious activity between May and July 2026 explains the demand side. Attackers are not just breaking in; they are collecting the material they need to be trusted. The four attack patterns Prophet described, and the reasons some succeeded while others were blocked, point to the same conclusion: defenses that stop network intrusion matter less when the intruder looks like a legitimate account holder with a legitimate document.
Automation Turns Steady Pressure into a Campaign
The PaperCut campaign, also covered by BleepingComputer, shows what happens when identity and automation combine. A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign against vulnerable PaperCut NG and MF servers, hitting 395 organizations. The count is the point. Hundreds of agents mean the campaign can probe, adapt, and retry at a volume no human team could sustain. Each individual intrusion may be blocked; the aggregate pressure is designed to find the organizations that are not.
The PaperCut flaws are the entry point. What the attacker does afterward depends on credentials, directories, and documents. That is why the IDScan theft and the PaperCut campaign belong in the same sentence. One supplies the identities; the other supplies the delivery mechanism. US technology companies sit between them, running the servers, issuing the credentials, and integrating the third-party identity checks whose compromise they may never see.
From Minecraft to Money Laundering
The Tom's Hardware story about a cybercrime ringleader who faces up to 20 years after pleading guilty to a racketeering charge, in a case tied to a $245 million heist, shows the economics have matured. The gang reportedly formed after meetups in Minecraft online. Its proceeds funded supercars, bodyguards, and private jets. This is not a hobbyist profile. It is an enterprise with payroll, security, and lifestyle spending, which means the underlying data-driven attacks have a reliable market.
The racketeering charge is significant for US companies because it treats the criminal organization itself as the target, not just a single intrusion. But the case also illustrates the lag. The characters in the story were living off proceeds while the identities that enabled the scheme circulated. Enforcement arrives after the data has been reused many times.



