Back
Dark web service sold 153 million scanned IDs taken from a live breach
SiTech AI Team2 წთ. საკითხავი

Dark web service sold 153 million scanned IDs taken from a live breach

More than 153 million driver's licence scans from the US and Canada went on sale after what appears to be a year-long leak from an identity verification company in Louisiana.

A new dark web identity theft service has been selling digital scans of more than 153 million driver's licences belonging to people in the United States and Canada, according to reporting by KrebsOnSecurity that Techdirt summarised on 3 September.

A breach that kept feeding the service

The service, called Nexus, claims the images come from an active breach at a major identity verification company whose customers include several Fortune 500 firms. In its introductory post it said it had been continuously exfiltrating new data for over a year into its private database. The figures support that claim: on the day the breach was revealed, and shortly before the site was taken down, the collection grew by nearly 400,000 records in 24 hours.

Krebs reported that the images appear to come from IDScan.net, an identity verification company based in Louisiana that works with thousands of dispensaries as well as Hertz, FedEx and Target. The New Orleans field office of the FBI has opened an official inquiry into the source of the images. Buyers could preview records before purchase with sensitive fields redacted, including customer photos where available.

Not only ordinary users

The database is not limited to private individuals. Krebs found the driver's licence of the sitting Secretary of Defense on sale for $100. Meanwhile the company's trust centre page, which promises responsible handling of sensitive identity data and compliance with privacy regulation, was still online days after the breach became public.

Why identity verification at scale is the problem

Larry Baldwin, a security researcher at Cybera, told Krebs the service creates several serious risks. Driver's licences are routinely accepted as proof of identity when opening new lines of credit, and leaked scans could expose people who do not wish to be found and cannot meaningfully change their appearance — at least not enough to defeat today's AI-based image matching. That group includes people fleeing domestic violence and those given new identities under the federal witness protection programme.

Techdirt's Mike Masnick argues the case shows that no age or identity verification scheme can be treated as safe. He points to earlier warnings that these databases are a privacy risk waiting to happen, and notes that the leak appears to have gone unnoticed inside the company for more than a year.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.