IDScan Confirms 153 Million Driver’s Licenses Leak on Dark Web

www.news4hackers.com-idscan-confirms-153-million-driver-s-licenses-leak-on-dark-web-idscan-confirms-153-million-driver-s-licenses-leak-on-dark-web

IDScan acknowledges unauthorized access to customer data following exposure of 153 million driver’s license records on the dark web.

IDScan Acknowledges Data Breach

IDScan, an identity verification service based in Louisiana, confirmed a breach on its cloud platform, impacting information stored in customer accounts. The company disclosed the incident on September 4, stating it became aware of potential unauthorized activity on or around September 1. Immediate measures were implemented to secure systems, with an external team deployed to assess the compromise.

Breach Details

The affected data includes personal identifiers such as names and government-issued identification numbers from driver’s licenses and other official documents. IDScan emphasized that while the breach involved access to sensitive information, it is proactively informing affected individuals and providing complimentary credit monitoring and identity protection services. The firm also noted it is cooperating with federal authorities investigating the incident.

Dark Web Exposure and Discovery

The breach came to light after security researcher Brian Krebs reported that a dark web marketplace named Nexus was offering access to a database containing over 153 million scanned driver’s licenses from the United States and Canada, alongside 10 million ID cards, 3 million travel documents, and 579,000 medical records. Krebs received intelligence from an anonymous source on August 31 regarding a listing on the Russian cybercrime forum Exploit, which advertised data tied to more than 170 million North American individuals.

Verification and FBI Involvement

The source verified the authenticity of the leak by providing a sample of a Virginia driver’s license. Krebs validated the data’s legitimacy by cross-referencing records associated with himself and other volunteers, tracing the source to IDScan.net. This revelation prompted the FBI’s New Orleans field office to initiate a formal investigation. The probe reportedly intensified after Krebs shared information with a trusted contact indicating that Nexus was also selling the driver’s license of an FBI assistant director, though no records belonging to Director Kash Patel were found in the dataset.

Following the publication of Krebs’ findings, the Nexus marketplace vanished from the dark web.

Implications and Ongoing Concerns

The breach has raised significant concerns about the security of cloud-based identity verification systems and the vulnerabilities of large-scale data repositories. No further details about the breach’s origin or the threat actors involved have been disclosed at this time.



About Author

en_USEnglish