S&P 500100.00-1.70%NASDAQ112.50-0.85%Apple125.000.00%Microsoft137.50+0.85%Google150.00+1.70%Amazon162.50-1.70%Tesla175.00-0.85%Meta187.500.00%Bitcoin200.00+0.85%Ethereum212.50+1.70%EUR/USD225.00-1.70%Gold237.50-0.85%Oil250.000.00%

 

The Wiregazette
From above of crop unrecognizable person driving modern yellow taxi car with GPS navigator on city street in daytime
Cybersecurity

153 Million Driver's Licenses Exposed in IDScan Breach; FBI, RCMP Investigate

4 分钟阅读

分享

Identity verification firm IDScan confirmed a breach of its cloud platform after a dark web service called Nexus sold access to over 153 million U.S. and Canadian driver’s licenses. The FBI and RCMP are investigating; multiple class-action lawsuits have been filed.

Identity verification service IDScan has confirmed that attackers breached its cloud platform and may have stolen data including full names, driver’s license numbers, and other government-issued identification numbers. The breach is tied to a dark web service called Nexus that sold access to more than 153 million driver’s licenses from the United States and Canada, along with millions of other identity documents.

IDScan stated that around September 1, 2026, its specialists became aware of potential unauthorized access. The company blocked the attackers, engaged third-party cybersecurity experts, and began notifying potentially affected users, offering free credit monitoring and identity theft protection services.

The dark web service Nexus, discovered by cybersecurity journalist Brian Krebs, advertised its database on a Russian cybercrime forum. Krebs verified the authenticity of the data by checking his own driver’s license — offered as a free sample — and licenses belonging to family members. He traced the origin of the documents to IDScan after observing that his license and his mother’s had been scanned nearly simultaneously during a car rental from Hertz, with file timestamps differing by only a few seconds.

According to Krebs’ reporting, Nexus claimed to have obtained the data by gaining unauthorized access to a major identity verification company and exfiltrating new records “continuously” for more than a year. In a single day, the number of licenses in the database increased by nearly 400,000. The service held over 153 million U.S. and Canadian driver’s licenses, more than 10 million other identity documents, over 3 million travel documents, and approximately 579,000 medical records.

Shortly after Krebs published his investigation, the Nexus site disappeared from the dark web. However, according to BleepingComputer, several threat actors have since claimed they are ready to sell a full copy of the data dump, though journalists have not yet verified those claims.

The breach has drawn attention from law enforcement on both sides of the border. The FBI confirmed it is “looking into the incident” but declined further comment due to the ongoing investigation. The Royal Canadian Mounted Police said it is “aware” of the FBI investigation and is monitoring the situation in coordination with domestic and international law enforcement and cybersecurity partners.

The scale of the incident is unprecedented. Zach Edwards, a threat researcher at cybersecurity firm Infoblox, told Reuters that “there’s never been a breach of driver’s licenses at this scale” and that the ongoing nature of the attack “created legitimate national security risks for high-profile individuals.”

Among the exposed records, Krebs identified driver’s licenses belonging to U.S. Defense Secretary Pete Hegseth, an FBI assistant director, and other senior government officials.

The breach carries significant potential for identity theft and fraud. Driver’s license numbers are commonly used as key identifiers in other databases, making the exposed data highly valuable for both cybercriminals and intelligence operations. As noted in reporting by Lawfare Media, similar stolen identity data has historically been exploited by nation-state actors, including Chinese espionage groups that previously used breached data from Anthem, Equifax, and the Office of Personnel Management to counter U.S. intelligence efforts.

Multiple class-action lawsuits have already been filed against IDScan. The company’s official statement did not mention the possible theft of scanned document images, and it configured its incident notification page with a “noindex” directive to prevent search engine indexing.

IDScan said it is cooperating with federal law enforcement and is acting with “an abundance of caution” in notifying all potentially impacted individuals. The company acknowledged that full access to the sensitive data on the dark web required payment, suggesting that not every person whose data was copied may have been exposed to the general public, but it is nonetheless offering credit monitoring and identity protection services.

分享

关于 Daniel Pryce

Technology & Innovation Reporter. Covers technology companies, venture funding, and the software and security issues that affect financial institutions and markets. He reports on product launches, funding rounds, and cyber incidents with market relevance. Startups and established tech firms both appear on his beat.

相关文章