FIELD NOTES
A personal record of travel, networks and small failures
TRAVEL NOTE

The Age-Verification Vendor Was Hacked—My Password Wasn’t the Most Important Thing Exposed

The email said an unauthorized party might have accessed the government-ID image I had submitted during an age appeal. I changed my password before finishing the second paragraph, enabled a new authenticator code, and signed out of every device. Then I reread the notice and realized none of those actions could change the photograph of my driving licence, the birth date printed on it, or the face beside it.

I had uploaded the document months earlier after a platform incorrectly classified my account as underage.

The appeal took less than five minutes. Photograph the ID. Take a matching selfie. Wait for access to return.

Once it did, I stopped thinking about the verification company behind the form.

The breach notice forced me to think about it all at once.

My immediate question was no longer whether an age-verification provider might be hacked. It had happened.

I needed to know what might have been exposed, what I could still protect, and how to avoid creating another permanent connection between my identity and private online activity.

The short answer

Perhaps the access supported legitimate functions. I still had no reason to introduce an unfamiliar company into a session involving age verification and paid adult content.

I protected the credential that was easiest to replace

Changing the password was sensible, especially because I had once used a similar version elsewhere.

It was also the simplest part of the problem.

In a 2025 incident involving a third-party service provider, Discord said an attacker accessed customer-support information that could include names, usernames, email addresses, IP addresses, limited billing details, support messages, and government-ID images. Approximately 70,000 users might have had ID photographs exposed through records connected to age-related appeals. Passwords were not part of the affected material. (Discord)

That distinction gave me a useful starting point.

A breach of an age-verification company does not automatically expose every page someone visited or every action taken on a platform. The damage depends on what the provider collected and which identifiers were stored beside it.

A record that says over 18: yes is one thing.

An ID photograph attached to a name, email address, IP address, selfie, and support conversation is something else entirely.

One confirms an age threshold.

The other can become a reusable identity package.

The official notice mattered more than the frightening email

A second message arrived later that morning.

It claimed my documents had already appeared on a criminal marketplace and invited me to “secure” them through a link.

I did not click it.

Instead, I opened the platform’s official website manually and found its incident page. The genuine notice described the affected service, the possible data involved, and how impacted users would be contacted.

That placed a boundary around the incident.

The attacker might have obtained information from my age appeal and support ticket. The notice did not say my password or complete activity history had been stolen.

The fake follow-up was trying to turn a real breach into a second compromise.

That is what exposed personal data makes possible. A phishing email becomes more convincing when the sender knows which platform you used, which address belongs to you, and enough detail to make the warning feel personal.

I saved the official notice, deleted the imitation, and wrote down the exact fields the company said might have been exposed.

Only then did the right response become clear.

An ID image changes what “secure your account” means

When a breach contains only an email address and password, the response begins with changing credentials and enabling stronger authentication.

A government document demands more.

The UK Information Commissioner’s Office advises people affected by a breach to contact the issuer when passport or driving-licence details are exposed, monitor financial accounts, remain alert to unexpected messages, and keep records of communication with the breached organization. (Org)

I followed that order.

I contacted the document issuer.

I enabled transaction alerts on my bank accounts.

I saved the incident date, case number, and the company’s description of the affected data.

I also checked whether the company offered identity monitoring or a dedicated contact for people whose documents had been exposed.

None of these steps produced an instant feeling of safety. They were still more useful than repeatedly changing passwords.

A password can be replaced.

A face, birth date, and government document number cannot.

The privacy failure began before the intruder arrived

The breach changed the way I judged age-verification systems.

Before it happened, I cared mostly about whether a check was quick and whether the provider said the upload was encrypted.

Afterward, I cared about what remained in its systems when the check was over.

Data-protection guidance for age assurance emphasizes collecting only what is necessary, explaining when third parties are involved, limiting retention, and avoiding hard identifiers when a simple yes-or-no age result will do. In many situations, retaining an identity document may be excessive. (Org)

The practical lesson was hard to miss.

A company cannot leak information it never collected.

It cannot lose an ID image that was deleted after producing the age result.

And a stolen confirmation that someone exceeds an age threshold is far less useful to an identity thief than a clear photograph of the document used to prove it.

Public anxiety about age checks often comes down to this same issue: normalizing ID and face uploads encourages more services to collect information that cannot be made private again after a breach. (Reddit)

That concern no longer felt abstract.

It changed the next decision I made online.


My established VPN solved the wrong layer of the problem

That evening, I opened a paid adult service I had used before.

It required a new age check.

My first instinct was to connect my regular VPN and assume the privacy issue had been handled.

The provider was established, widely reviewed, and backed by a large server network. It encrypted the hotel connection and replaced my public IP address exactly as expected.

Then its login page asked for the same email address named in the breach notice.

My password manager filled the form.

I stopped before pressing Sign in.

The provider had done nothing improper. Conventional accounts are normal, and its public history was a legitimate strength.

But the moment exposed the standard I had been using.

I was judging privacy tools by server count, speed, and reputation while overlooking the identity record required to use them.

After a breach had made me cautious about linkable data, I was about to attach another privacy service to the same inbox.

The VPN could hide the hotel’s IP address from the destination.

Its account system could not reduce the identity trail surrounding the session.

I closed the form.

A free extension asked me to trust another unknown company

I briefly considered a free browser VPN.

Installation would take seconds, and no payment was required.

Its permissions screen asked to read and change data across every website I visited.

Perhaps the access supported legitimate functions. I still had no reason to introduce an unfamiliar company into a session involving age verification and paid adult content.

The breach had already shown how a third-party provider could become the weakest link in a much larger service.

Adding another poorly understood intermediary felt like repeating the same mistake.

I removed the extension without connecting.

I did not need the option with the lowest price or the fastest installation.

I needed the one that asked for the least additional identity.

The smaller app did not ask who I was

OnlydogVPN was still installed from earlier testing.

It had fewer server locations, a shorter public history, and fewer independent ratings than the established provider. Those limitations had previously kept it in the backup folder.

Now one design choice mattered more than the larger provider’s map.

The smaller app allowed basic use without a conventional email-and-password account.

I opened it, selected the preset for private browsing, and connected.

No email form appeared.

No new password entered my manager.

No account-recovery address linked the VPN session to the inbox named in the breach.

Then I returned to the adult service.

The site still required age assurance. The VPN did not remove that requirement, nor should it have.

This time, however, the site offered facial age estimation instead of requiring another identity-document upload. Its notice said the service would receive an age result rather than my full identity.

I completed the check.

The library opened.

I downloaded the item I had purchased and confirmed that it played offline.

That was the result I wanted: legitimate access without creating another VPN identity record or submitting another government document when a less revealing method was available.

The next screen showed how much background traffic had disappeared

After the download finished, I returned to the smaller app.

Its blocked-request counter had increased during the session.

Advertising and tracking requests had been stopped while I moved through the age-check and content pages.

The counter did not erase the information needed for the age decision.

It showed that fewer unrelated companies received background traffic around that sensitive action.

After a breach, that difference mattered.

The goal was not to pretend I had become invisible. It was to reduce the number of services and identifiers surrounding an already private session.

The age provider needed enough information to establish that I met the threshold.

The VPN did not need my email address.

Unrelated trackers did not need another request from the page.

Each missing link made the activity harder to assemble into one reusable profile later.

A VPN cannot recover a stolen ID—but it can stop adding to the trail

I could not inspect the compromised vendor’s internal records or determine which copies of my document had been taken.

I could act on the confirmed scope, contact the issuer, watch for fraud and phishing, and reduce the amount of identity attached to future checks.

That was less comforting than a button labelled Secure My Identity.

It was also more honest.

The established VPN offered more countries, more reviews, and a familiar account system. None of those strengths addressed the lesson the breach had taught me.

The smaller app asked for less information before protecting the next session. After the required age check succeeded, it also reduced the unrelated requests surrounding it.

A VPN could not undo the theft of my driving-licence image.

But once that image was gone, the most useful privacy tool was the one that helped me avoid creating the next link.

Questions this experience may leave you with

What was actually causing the problem?

Perhaps the access supported legitimate functions. I still had no reason to introduce an unfamiliar company into a session involving age verification and paid adult content.

Why did the obvious fixes fail?

The UK Information Commissioner’s Office advises people affected by a breach to contact the issuer when passport or driving-licence details are exposed, monitor financial accounts, remain alert to unexpected messages, and keep records of communication with the breached organization. ( Org ) (Org)

What should you check first?

Before it happened, I cared mostly about whether a check was quick and whether the provider said the upload was encrypted.

What finally changed the result?

This time, however, the site offered facial age estimation instead of requiring another identity-document upload. Its notice said the service would receive an age result rather than my full identity.

What is worth remembering?

But once that image was gone, the most useful privacy tool was the one that helped me avoid creating the next link.