FBI investigates breach of 153 million driving license records at IDscan.net
Scans of 153 million driver's licenses, traced to IDscan.net and including Pete Hegseth and Brian Krebs, were offered for sale on the dark web.
Digital scans of 153 million driver's licenses appeared for sale by a user on the Russian cybercrime forum Exploit, alongside over 10 million ID cards, 3 million travel documents, and 579,000 medical cards sold through a site called Nexus. KrebsOnSecurity traced the leak to identity verification provider IDscan.net, whose customers include car rental company Hertz, and victims reportedly include US Defense Secretary Pete Hegseth. The FBI has opened an official inquiry into the source of the images, and IDscan.net has not issued an official statement.
- 153 million driver's license scans offered for sale
- Leak traced to identity verification firm IDscan.net
- Hertz is a known IDscan.net customer
- Victims include Pete Hegseth and Brian Krebs
- FBI has formally requested information on the breach
Full article276 words · extracted from csoonline.com · click to collapse
Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth – and investigative reporter Brian Krebs, who has dug deep into the data breach on his blog KrebsOnSecurity.
The driving license details were offered for sale by a user of the Russian cybercrime forum Exploit, KrebsOnSecurity said. In addition to the 153 million driving licenses, the user also offered details ofmore than 10 million identification cards; more than three million travel documents or international IDs; and at least 579,000 medical cards through a site called Nexus. That site has now been taken down – although, of course, all the acquired data could always pop up on another site.
KrebsOnSecurity traced the leak to IDscan.net, an identity verification service used by car rental company Hertz. IDscan has a long list of client logos and case studies that it has since removed from its website.
IDscan has not yet issued an official statement about the breach, but Jillian Kossman, a marketing and operations leader at IDscan.net told KrebsOnSecurity, “I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” The investigation into the leak has gathered pace, with an official enquiry from the FBI into the source of the images.
However, the breach has revealed a vulnerability at the heart of enterprises’ use of ID verification systems: No matter how secure businesses’ IT systems and processes are, they are also dependent on the security of their suppliers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4218789/fbi-investigates-breach-of-153-million-driving-license-records-at-idscan-net.html