S&P 500100.00-1.70%NASDAQ112.50-0.85%Apple125.000.00%Microsoft137.50+0.85%Google150.00+1.70%Amazon162.50-1.70%Tesla175.00-0.85%Meta187.500.00%Bitcoin200.00+0.85%Ethereum212.50+1.70%EUR/USD225.00-1.70%Gold237.50-0.85%Oil250.000.00%

 

The Wiregazette
A conceptual image highlighting the issue of data breaches, featuring bold text on a textured background.
Cybersecurity

IDScan Breach Exposes 153 Million Driver’s Licenses, Triggers Identity Theft Fears

4 分钟阅读

分享

Identity verification firm IDScan.net confirmed that attackers breached its cloud platform, potentially exposing up to 153 million U.S. and Canadian driver’s licenses sold on a dark web service. The FBI is investigating, and the RCMP said it is monitoring the situation.

Identity verification provider IDScan.net confirmed that its cloud platform was breached, with attackers potentially exfiltrating personal data tied to millions of driver’s licenses. The incident has triggered law enforcement investigations and raised alarms about mass identity theft and national security risks.

Breach Confirmed

IDScan.net said in a statement that around September 1, 2026, it became aware of potential unauthorized access to its cloud platform. The firm blocked the attackers and engaged third-party cybersecurity experts. Preliminary findings indicate that an unauthorized third party may have accessed and copied information stored in customer accounts.

The exposed data may include full names, driver’s license numbers, and numbers from other government-issued identity documents. IDScan.net said it is notifying potentially affected individuals and offering free credit monitoring and identity protection services. The company added it is cooperating with federal law enforcement.

The breach first came to light through an investigation by cybersecurity journalist Brian Krebs. He discovered a dark web service named Nexus that sold access to more than 153 million scans of U.S. and Canadian driver’s licenses. Nexus also claimed to hold over 10 million other identity documents, more than 3 million travel documents, and approximately 579,000 medical records.

Krebs verified the authenticity of the data by checking his own license and those of nine others. He traced the origin of the scanned documents to IDScan.net after finding that his and his mother’s licenses were scanned nearly simultaneously during a car rental with Hertz. The file timestamps in the Nexus database differed by only seconds.

After Krebs published his findings, Nexus disappeared from the dark web. Hackmag reported that several threat actors later claimed to be ready to sell a full copy of the stolen dump, though journalists have not verified those claims.

Scope and Impact

The scale of the breach is massive. The database of U.S. licenses alone represents roughly 63% of all active driver’s licenses in the country, according to Lawfare Media. Krebs reported that the database included licenses of high-ranking government officials, including U.S. Secretary of Defense Pete Hegseth, an assistant director at the FBI, and other senior officials.

Zach Edwards, a threat researcher at cybersecurity firm Infoblox, told Reuters, as reported by Global News, that the incident was unprecedented. “There’s never been a breach of driver’s licenses at this scale,” Edwards said. He added that the ongoing ingestion of new data meant the attack created legitimate national security risks for high-profile individuals.

Krebs noted that in a single day the number of licenses in the Nexus database increased by nearly 400,000, suggesting continuous exfiltration of new data over at least a year.

National Security Implications

Lawfare Media’s analysis highlighted the national security dimension. Driver’s licenses are key identity documents used in many government databases. Stolen identity data can fuel intelligence operations by foreign adversaries. The analysis cited past incidents where Chinese cyber espionage groups used data from breaches of Anthem, Equifax, and the Office of Personnel Management to counter U.S. intelligence efforts.

Examples from investigative group Bellingcat showed how hacked travel records helped identify a Russian GRU agent in Italy and suspects in the Skripal poisoning. “If a small investigative outfit is hoovering up Russian data when it is leaked, you can bet your bottom yuan that China’s intelligence services are doing the same for any American data that pops up,” Lawfare wrote.

Response and Lawsuits

The RCMP said in a statement it is “aware” of the FBI investigation and is monitoring the situation. “The RCMP remains committed to investigating reported cybercrime, including breaches of data,” it said, adding that it could not confirm details of an ongoing investigation.

The U.S. FBI said it is “looking into the incident” but declined further comment due to the active investigation.

Even before IDScan.net officially confirmed the breach, multiple class-action lawsuits had been filed against the company, according to Hackmag and Lawfare. Hackmag also noted that IDScan.net configured its incident notification page with a “noindex” directive, preventing search engines from indexing it.

IDScan.net has stated it is acting “with an abundance of caution” in notifying all potentially impacted users. The firm has not disclosed the total number of affected individuals or geographic breakdown. The breach ranks among the largest-ever exposures of government-issued identity documents in North America, creating heightened risks of identity theft and fraud for tens of millions of people.

分享

关于 Daniel Pryce

Technology & Innovation Reporter. Covers technology companies, venture funding, and the software and security issues that affect financial institutions and markets. He reports on product launches, funding rounds, and cyber incidents with market relevance. Startups and established tech firms both appear on his beat.

相关文章