ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Multiple Class Action Lawsuits Filed Against IDScan

criticalData breachimportance 90
AI summary · glm-5.3-flash

At least four class-action lawsuits filed against IDScan.net over an alleged breach exposing 153 million driver's licenses; FBI investigating.

At least four class-action lawsuits were filed in the US District Court for the Eastern District of Louisiana against IDScan.net following reports of a potential mega-breach of driver's license data. A Russian cybercrime forum service called Nexus claimed over 153 million driver's licenses, mainly American and Canadian, plus over 10 million ID cards, travel documents, and medical cards. The FBI is investigating the incident, which was first reported by journalist Brian Krebs, and IDScan.net says it is investigating. IDScan.net provides B2B ID verification services for clients including Hertz, FedEx, and hundreds of US cannabis dispensaries.

  • Four class actions filed in Eastern District of Louisiana court
  • Nexus forum service claimed 153M+ licenses and 10M+ ID cards
  • Nexus taken down shortly after Krebs published his findings
  • IDScan.net serves Hertz, FedEx, and hundreds of cannabis dispensaries
  • Law firms advise victims to document ID scans and verify providers used
Full article465 words · extracted from infosecurity-magazine.com · click to collapse

Law firms are circling after reports emerged last week of a potential mega-breach of driver’s license information.

At least four class-action lawsuits have been filed in the US District Court for the Eastern District of Louisiana against IDScan.net, the company at the center of the allegations.

The plaintiffs are seeking damages and want the company, which provides ID verification and fraud prevention services, to improve its internal security posture.

The FBI said last week that it is investigating the incident, which was first reported by journalist Brian Krebs.

Read more on IDScan.net: FBI Probes Possible Breach of 153 Million Driver’s Licenses.

At least two other major law firms, Hall Attorneys and Markovits, Stock & DeMarco, are currently investigating claims from potential victims.

“If you rented a vehicle, visited a cannabis dispensary, or otherwise had your driver’s license or other identification document scanned or verified through IDScan.net’s systems, you may be entitled to compensation and other legal remedies,” reads one note on the website of Markovits, Stock & DeMarco.

Drivers in the Crosshairs

A service dubbed “Nexus” on a Russian cybercrime forum had claimed to have over 153 million driver’s licenses for mainly American as well as Canadian drivers, alongside over 10 million ID cards, travel documents, medical cards and more.

Nexus was taken down shortly after Krebs published his post, but he tracked activity from his own and other identified victims’ movements to link the data to New Orleans-based IDScan.net.

The firm provides B2B ID verification services for a range of big-name businesses including car rental giant Hertz, FedEx, and hundreds of cannabis dispensaries across the US.

"When you look at data brokers and the sheer amount of information they collect, purchase, acquire, aggregate and store over time, it’s absolutely staggering. And this particular breach appears to be staggering in its own right,” said Black Hills Information Security owner, John Strand.

“I do think we need to start treating this type of data with protections similar to what we provide for protected health information. Maybe that means bringing some of it under HIPAA-like protections or creating a regulatory framework that treats large collections of personal data with the same seriousness.”

Hall Attorneys urged individuals who think their data may have been involved in the breach to do the following:

  • Identify the business, location, approximate date, and reason your ID was scanned or uploaded
  • Ask whether the business used IDScan.net, VeriScan, DIVE, or another ID-verification provider
  • Ask whether front-and-back images, infrared or ultraviolet captures, a selfie, or parsed ID fields were retained and whether your record is within any incident review
  • Keep the request and response. Don’t send an unredacted ID image, Social Security number, or account password in an initial inquiry
  • Treat unsolicited breach-check links as suspicious

IDScan.net reportedly said it is investigating the incident.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/multiple-class-action-lawsuits/