The Washington State Department of Licensing says over 250,000 licensed professionals may have had personal data exposed, including SSNs, in a database breach
Context & Ripple Effects
Washington has been here before: Premera Blue Cross was hit by a sophisticated hack affecting up to 11 million people in early 2015 (Premera's breach), and the state later sued Uber for failing to promptly notify users after a database intrusion (the state's Uber notification lawsuit). Now the exposure sits inside the state itself — the Department of Licensing says more than 250,000 licensed professionals may have had personal data, including Social Security numbers, exposed in a database breach.
First-order effects
- Over 250,000 licensed professionals face direct identity-theft risk from exposed SSNs, and the Department of Licensing must run notification and remediation for them.
Second-order effects
- Given the state's own precedent of suing Uber over slow breach disclosure, the agency's notification timeline will draw heightened legal and political scrutiny from within Washington's government.
Third-order effects
- The breach joins a string of SSN-centered exposures — including the National Public Data leak of millions of SSNs — strengthening the case that licensing systems should stop treating SSNs as primary identifiers and that states will keep enforcing notification duties aggressively.
The trend: Government-held identity databases are becoming a recurring breach frontier, with SSN exposure pushing regulators toward stricter notification enforcement and away from SSN-based identification.