TL;DR: When you verify your X account with a government ID, your passport or driver's license goes to Au10tix, an Israeli company founded by former Shin Bet intelligence agents. Many of their engineers came from Unit 8200, Israel's NSA equivalent and the unit that birthed Pegasus spyware. In 2024, security researchers discovered Au10tix had left admin credentials exposed for over a year, potentially compromising millions of users' identity documents. X, TikTok, Uber, PayPal, and LinkedIn all use Au10tix. The company claims no data was stolen. The credentials were still working when researchers checked in June 2024.

What Is Au10tix?

Au10tix is an identity verification company that processes government IDs for some of the world's largest platforms [1].

When you verify on X:

  1. You upload a government-issued photo ID
  2. You take a selfie
  3. X sends both to Au10tix in Israel
  4. Au10tix verifies your identity using biometric matching
  5. Au10tix can retain your data for up to 30 days

Major clients include:

  • X (Twitter)
  • TikTok
  • Uber
  • PayPal
  • LinkedIn
  • Coinbase
  • Fiverr
  • Airbnb

As of July 2024, any X creator who wants to monetize their content must verify through Au10tix [2]. The verification is not available in the EU, UK, or European Economic Area, likely because European data protection laws would make the arrangement illegal.

The Intelligence Origins

Au10tix wasn't born in Silicon Valley. It emerged from Israeli intelligence [3].

The corporate structure:

  • Au10tix is a subsidiary of ICTS International
  • ICTS was founded in 1982 by former Shin Bet agents
  • Shin Bet is Israel's domestic intelligence agency, comparable to the FBI
  • ICTS originally provided airport and border security

The founders:

  • Ron Atzmon, Au10tix founder and chairman, Israeli military veteran
  • Gil Atzmon, Co-founder, Ron's brother

Multiple reports have connected Atzmon to Unit 8200, Israel's signals intelligence unit [4]. Israeli media have disputed these specific claims, stating Atzmon served in the Israeli Navy. However, the company's engineering staff includes confirmed Unit 8200 veterans.

Unit 8200: Israel's Cyber Elite

Unit 8200 deserves special attention. It's not just any military unit [5].

What Unit 8200 is:

  • Israel's signals intelligence unit (equivalent to NSA)
  • Provides 90% of Israel's intelligence material
  • Staff of 5,000-10,000
  • Functions as an incubator for Israel's tech industry

Companies founded by Unit 8200 alumni:

  • NSO Group, Created Pegasus spyware, used to hack journalists and activists worldwide
  • Waze, Navigation app (acquired by Google)
  • Wix, Website builder
  • Viber, Messaging app
  • Over 1,000 companies total

80% of Israeli cyber tech firms were founded by Unit 8200 graduates. The unit explicitly functions as a pipeline from military intelligence to the private sector.

Au10tix's Unit 8200 connections:

Multiple Au10tix engineers worked in Unit 8200 before joining the company [6]. The company's leadership includes numerous Israeli military veterans across Air Force, intelligence, and other branches.

The Year-Long Data Breach

In June 2024, security researchers discovered something alarming [7].

What happened:

  • December 2022: Admin credentials stolen via infostealer malware
  • March 2023: Credentials posted on Telegram
  • June 2024: Researchers checked, credentials still worked
  • Exposure: Over 18 months

What was exposed:

  • Names and birthdates
  • Nationalities
  • Images of passports and driver's licenses
  • Facial scan data
  • Authentication metrics
  • Internal verification results

The source: an infostealer on the computer of Au10tix's Network Operations Center Manager [8].

The company's response:

"While PII data was potentially accessible, based on our current findings, we see no evidence that such data has been exploited."

Translation: "The door was unlocked for 18 months, but we don't think anyone walked in."

How Companies Responded

When the breach became public, Au10tix's clients had different reactions [9]:

Company Response
X (Twitter) Silence
TikTok No public statement
Coinbase "Not aware" of customer data breach
Fiverr Continued using Au10tix
Upwork Switched to different provider

Only Upwork switched providers. X, which had recently partnered with Au10tix, said nothing. Your government ID may have been sitting in an exposed database for over a year, and X didn't even acknowledge it.

Why X Chose Au10tix

X has been using Au10tix since around 2020. The partnership expanded significantly under Musk [10].

Timeline:

  • 2020: Initial partnership
  • 2023: X Blue users required to submit ID for verification
  • July 2024: Mandatory ID verification for monetization

What X requires:

  • Government-issued photo ID (passport or driver's license)
  • Selfie for biometric matching
  • Data sent directly to Au10tix in Israel

What you get:

  • A note on your profile saying "government ID verified"
  • Ability to monetize content
  • Your biometric data in an Israeli database

The EU, UK, and EEA are excluded from this program. European data protection laws likely prohibit sending biometric data to a third-party company in Israel for indefinite storage.

The Bigger Picture

Au10tix isn't just an X problem. It's an infrastructure problem.

A single company, with intelligence community origins and a documented data breach, verifies identities for:

  • Social media (X, TikTok, LinkedIn)
  • Financial services (PayPal, Coinbase)
  • Gig economy (Uber, Fiverr, Upwork)
  • Travel (Airbnb)

If Au10tix is compromised, millions of identity documents across multiple industries are at risk. And based on the 2024 breach, "if" should probably be "when."

This is what happens when identity verification becomes a monopoly controlled by a company with intelligence ties and poor security practices.

Protecting Yourself

If you've verified with Au10tix:

  • Monitor for identity theft using free credit monitoring
  • Consider placing a fraud alert or credit freeze
  • Request data deletion if you're in a jurisdiction with that right

If you haven't verified:

  • Consider whether verification is worth the privacy cost
  • Remember: EU/UK users are excluded for a reason
  • Your government ID becomes part of their database

For everyone:

  • Be aware that "verification" often means third-party data collection
  • Read the privacy popup before uploading ID
  • Consider the intelligence community connections when evaluating risk

The Bottom Line

When you verify your X account, your government ID goes to Au10tix, a company founded by former Shin Bet agents with engineers from Unit 8200, the same military unit that produced Pegasus spyware.

In 2024, security researchers found Au10tix had left admin credentials exposed for over 18 months. The credentials were still working when discovered. The company claims no data was stolen. We have only their word.

X remained silent about the breach. They continue to require Au10tix verification for monetization. The EU, UK, and EEA are excluded, likely because their data protection laws would make this arrangement illegal.

This is what identity verification looks like when it's handled by intelligence-linked companies with documented security failures. Your passport is their data. What they do with it is up to them.

References

  1. Al Jazeera, X Blue users will need to send selfie, data to Israeli software company (August 2023)
  2. Calcalist Tech, Users demand X cut ties with Israeli verification company AU10TIX (2024)
  3. Middle East Eye, 'Deep concern' at social media company partnering with Israeli verification firm (2023)
  4. MintPress News, Twitter Using Israeli Tech Firm Headed by Ex-Military Officials (2023)
  5. Naked Capitalism, X Premium Users Face Stark Choice (June 2024)
  6. Hespress, Links between X and an Israeli company resurfaced (2024)
  7. Malwarebytes, Driving licences and other documents leaked by authentication service (June 2024)
  8. CloudDefense, Major Identity Verification Firm AU10TIX Exposes User Data (2024)
  9. Cointelegraph, Coinbase 'not aware' of customer data breach after Au10tix leak (2024)
  10. Jerusalem Post, Twitter to use Israeli software for verification (2023)
  11. EFF, Hack of Age Verification Company Shows Privacy Danger (June 2024)