This week, a significant threat actor began distributing digital scans of over 153 million driver licenses from the US and Canada on the dark web.
The compromised driver licenses were initially discovered on an identity theft service known as Nexus. Simultaneously, the threat actor was observed promoting the service on a Russian cybercrime platform, claiming control over identification data of more than 170 million people.
Details of the Data Breach
On Nexus, visitors were able to access a staggering 153 million driver licenses, alongside over 10 million identification cards, more than 3 million travel documents and international IDs, and approximately 580,000 medical cards.
Renowned investigative journalist Brian Krebs reported that a broad search on the Nexus platform returned around 153 million results, with only about 1.1 million originating from Canada.
The threat actor behind this breach alleged that the documents were obtained from a security breach at an identity verification company that collaborates with several Fortune 500 firms, as indicated by Krebs.
Implications for IDScan.net
After verifying the inclusion of his own driver license on Nexus, Krebs deduced that the documents might have been siphoned from the identity verification service provider IDScan.net. This Louisiana-based company specializes in fraud prevention, access management, and age verification services.
IDScan.net claims to collaborate with major brands across numerous sectors, including automotive, banking, gaming, and more, facilitating over 21 million verifications monthly at upwards of 20,000 sites.
While SecurityWeek reached out to IDScan for comments regarding the breach, no response has been received yet.
Response and Recommendations
Following the publication of Krebs’ article, the Nexus platform was promptly taken offline. Meanwhile, the FBI has reportedly launched an investigation into the potential data breach involving IDScan.
Some of the exfiltrated driver licenses allegedly belong to FBI personnel, heightening the severity of the situation.
Security expert Tim Rawlins from NCC Group emphasizes the need for organizations to anticipate potential identity evidence compromises. He recommends that businesses maintain a comprehensive inventory of identity data and scrutinize who collects it, its purpose, and its lifecycle.
Furthermore, Rawlins advises on establishing robust contracts with identity providers, ensuring secure logging, data segregation, retention policies, and incident notification mechanisms.
Individuals are encouraged to limit the sharing of their driver licenses except when absolutely necessary, and inquire if ID verification can be accomplished without scanning or retaining the document.
