TL;DR: When you verify your X account with a government ID, your passport or driver's license goes to Au10tix, an Israeli company founded by former Shin Bet intelligence agents. Many of their engineers came from Unit 8200, Israel's NSA equivalent and the unit that birthed Pegasus spyware. In 2024, security researchers discovered Au10tix had left admin credentials exposed for over a year, potentially compromising millions of users' identity documents. X, TikTok, Uber, PayPal, and LinkedIn all use Au10tix. The company claims no data was stolen. The credentials were still working when researchers checked in June 2024.
What Is Au10tix?
Au10tix is an identity verification company that processes government IDs for some of the world's largest platforms [1].
When you verify on X:
- You upload a government-issued photo ID
- You take a selfie
- X sends both to Au10tix in Israel
- Au10tix verifies your identity using biometric matching
- Au10tix can retain your data for up to 30 days
Major clients include:
- X (Twitter)
- TikTok
- Uber
- PayPal
- Coinbase
- Fiverr
- Airbnb
As of July 2024, any X creator who wants to monetize their content must verify through Au10tix [2]. The verification is not available in the EU, UK, or European Economic Area, likely because European data protection laws would make the arrangement illegal.
The Intelligence Origins
Au10tix wasn't born in Silicon Valley. It emerged from Israeli intelligence [3].
The corporate structure:
- Au10tix is a subsidiary of ICTS International
- ICTS was founded in 1982 by former Shin Bet agents
- Shin Bet is Israel's domestic intelligence agency, comparable to the FBI
- ICTS originally provided airport and border security
The founders:
- Ron Atzmon, Au10tix founder and chairman, Israeli military veteran
- Gil Atzmon, Co-founder, Ron's brother
Multiple reports have connected Atzmon to Unit 8200, Israel's signals intelligence unit [4]. Israeli media have disputed these specific claims, stating Atzmon served in the Israeli Navy. However, the company's engineering staff includes confirmed Unit 8200 veterans.
Unit 8200: Israel's Cyber Elite
Unit 8200 deserves special attention. It's not just any military unit [5].
What Unit 8200 is:
- Israel's signals intelligence unit (equivalent to NSA)
- Provides 90% of Israel's intelligence material
- Staff of 5,000-10,000
- Functions as an incubator for Israel's tech industry
Companies founded by Unit 8200 alumni:
- NSO Group, Created Pegasus spyware, used to hack journalists and activists worldwide
- Waze, Navigation app (acquired by Google)
- Wix, Website builder
- Viber, Messaging app
- Over 1,000 companies total
80% of Israeli cyber tech firms were founded by Unit 8200 graduates. The unit explicitly functions as a pipeline from military intelligence to the private sector.
Au10tix's Unit 8200 connections:
Multiple Au10tix engineers worked in Unit 8200 before joining the company [6]. The company's leadership includes numerous Israeli military veterans across Air Force, intelligence, and other branches.
The Year-Long Data Breach
In June 2024, security researchers discovered something alarming [7].
What happened:
- December 2022: Admin credentials stolen via infostealer malware
- March 2023: Credentials posted on Telegram
- June 2024: Researchers checked, credentials still worked
- Exposure: Over 18 months
What was exposed:
- Names and birthdates
- Nationalities
- Images of passports and driver's licenses
- Facial scan data
- Authentication metrics
- Internal verification results
The source: an infostealer on the computer of Au10tix's Network Operations Center Manager [8].
The company's response:
"While PII data was potentially accessible, based on our current findings, we see no evidence that such data has been exploited."
Translation: "The door was unlocked for 18 months, but we don't think anyone walked in."
How Companies Responded
When the breach became public, Au10tix's clients had different reactions [9]:
| Company | Response |
|---|---|
| X (Twitter) | Silence |
| TikTok | No public statement |
| Coinbase | "Not aware" of customer data breach |
| Fiverr | Continued using Au10tix |
| Upwork | Switched to different provider |
Only Upwork switched providers. X, which had recently partnered with Au10tix, said nothing. Your government ID may have been sitting in an exposed database for over a year, and X didn't even acknowledge it.
Why X Chose Au10tix
X has been using Au10tix since around 2020. The partnership expanded significantly under Musk [10].
Timeline:
- 2020: Initial partnership
- 2023: X Blue users required to submit ID for verification
- July 2024: Mandatory ID verification for monetization
What X requires:
- Government-issued photo ID (passport or driver's license)
- Selfie for biometric matching
- Data sent directly to Au10tix in Israel
What you get:
- A note on your profile saying "government ID verified"
- Ability to monetize content
- Your biometric data in an Israeli database
The EU, UK, and EEA are excluded from this program. European data protection laws likely prohibit sending biometric data to a third-party company in Israel for indefinite storage.
The Legal Concerns
Privacy advocates have raised multiple issues with the Au10tix arrangement [11]:
Israeli law:
- Israeli security services can compel companies to share data
- No US oversight of how data is used once in Israel
- Intelligence community connections create inherent conflicts
Data retention:
- Au10tix can retain data for 30 days (per their popup)
- No independent verification of actual retention practices
- The breach showed data was stored in accessible logging platforms
Cross-border transfer:
- US users' government IDs are processed in Israel
- No GDPR-equivalent protection in the US
- Different legal frameworks, different protections
The Bigger Picture
Au10tix isn't just an X problem. It's an infrastructure problem.
A single company, with intelligence community origins and a documented data breach, verifies identities for:
- Social media (X, TikTok, LinkedIn)
- Financial services (PayPal, Coinbase)
- Gig economy (Uber, Fiverr, Upwork)
- Travel (Airbnb)
If Au10tix is compromised, millions of identity documents across multiple industries are at risk. And based on the 2024 breach, "if" should probably be "when."
This is what happens when identity verification becomes a monopoly controlled by a company with intelligence ties and poor security practices.
Protecting Yourself
If you've verified with Au10tix:
- Monitor for identity theft using free credit monitoring
- Consider placing a fraud alert or credit freeze
- Request data deletion if you're in a jurisdiction with that right
If you haven't verified:
- Consider whether verification is worth the privacy cost
- Remember: EU/UK users are excluded for a reason
- Your government ID becomes part of their database
For everyone:
- Be aware that "verification" often means third-party data collection
- Read the privacy popup before uploading ID
- Consider the intelligence community connections when evaluating risk
The Bottom Line
When you verify your X account, your government ID goes to Au10tix, a company founded by former Shin Bet agents with engineers from Unit 8200, the same military unit that produced Pegasus spyware.
In 2024, security researchers found Au10tix had left admin credentials exposed for over 18 months. The credentials were still working when discovered. The company claims no data was stolen. We have only their word.
X remained silent about the breach. They continue to require Au10tix verification for monetization. The EU, UK, and EEA are excluded, likely because their data protection laws would make this arrangement illegal.
This is what identity verification looks like when it's handled by intelligence-linked companies with documented security failures. Your passport is their data. What they do with it is up to them.
References
- Al Jazeera, X Blue users will need to send selfie, data to Israeli software company (August 2023)
- Calcalist Tech, Users demand X cut ties with Israeli verification company AU10TIX (2024)
- Middle East Eye, 'Deep concern' at social media company partnering with Israeli verification firm (2023)
- MintPress News, Twitter Using Israeli Tech Firm Headed by Ex-Military Officials (2023)
- Naked Capitalism, X Premium Users Face Stark Choice (June 2024)
- Hespress, Links between X and an Israeli company resurfaced (2024)
- Malwarebytes, Driving licences and other documents leaked by authentication service (June 2024)
- CloudDefense, Major Identity Verification Firm AU10TIX Exposes User Data (2024)
- Cointelegraph, Coinbase 'not aware' of customer data breach after Au10tix leak (2024)
- Jerusalem Post, Twitter to use Israeli software for verification (2023)
- EFF, Hack of Age Verification Company Shows Privacy Danger (June 2024)