Cybersecurity

IDScan.net Confirms Breach After 153M ID Scans Offered on Dark Web

Published 3 min readBy NewUJ Editorial Desk

Updated factual errors corrected

IDScan.net Confirms Breach After 153M ID Scans Offered on Dark Web
Photo: Stock illustration
0 0
XWhatsAppTelegramLinkedIn

IDScan.net, the Louisiana-based identity-verification vendor whose software checks government IDs at retailers, car-rental counters and cannabis dispensaries, has confirmed that an unauthorized third party may have reached data held in customer accounts on its cloud. In a notice dated September 4, the company said the intruder “may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud,” and identified the data involved as full names and driver’s license or other government-issued identification numbers. It said it learned of the possible unauthorized access on or around September 1, and that the records potentially affected are those that entered its system before that date.

The notice followed a dark-web listing that surfaced publicly on September 1, when security journalist Brian Krebs reported that a new identity-theft service called Nexus — advertised by a new user on the Russian-language cybercrime forum Exploit — was selling searchable access to what it claimed were more than 153 million US and Canadian driver’s license scans, alongside identification cards, travel documents and medical cards. In its sales thread, Nexus wrote that it had “been continuously exfiltrating new data for over a year.” IDScan.net has confirmed none of those figures and has not publicly linked itself to Nexus; that connection comes from Krebs’s reporting.

Krebs’s evidence is circumstantial rather than an admission by either party. His own Virginia license was offered as a free sample, and after asking more than a dozen friends and relatives for permission to search, he found nine of their licenses — each of those people confirmed traveling on or close to the dates timestamped on the images. Several had handed their licenses to a Hertz rental counter, and one researcher’s scan matched a visit to a Las Vegas dispensary; IDScan.net lists both Hertz and dispensaries among its clients. There were no passports in the data set, Krebs wrote.

The reach matters because most people in such data never chose IDScan.net. Its clients outsource age and identity checks to the company, which says its systems perform more than 21 million verifications a month at over 20,000 locations, so a license scanned at a shop door or a rental counter lands in a vendor’s cloud the customer has never heard of. Those same scans are what banks and online platforms accept as proof of identity.

What remains unknown is the scale. IDScan.net has not said how many individuals are affected, how long the intruder had access, or whether document images were taken alongside the numbers; it says third-party specialists are still determining the scope, that it is cooperating with federal law enforcement, and that it will offer free credit monitoring and identity protection to those it identifies. The FBI told TIME on September 3 that it was “looking into the incident” but declined further comment. Nexus went offline within hours of Krebs’s story, its login page replaced with the line “This service is no longer available.” Until the company or investigators publish a count, 153 million remains the seller’s claim.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.