FBI Probes Service Selling 153M+ Drivers Licenses (krebsonsecurity.com) 60
A dark-web identity theft service called Nexus claims to be selling scans of more than 153 million U.S. and Canadian driver's licenses, along with millions of other identity documents. "Based on interviews with individuals whose licenses are available for purchase through the service, it appears to be siphoning images collected by a widely used Louisiana-based identity verification company," reports KrebsOnSecurity. The outlet also reports that the FBI's New Orleans field office has launched an official inquiry into the source of the images. From the report: On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit. The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.
[...] The people behind Nexus claim the license images are coming from an active breach at "a major identity verification company" whose customers include multiple Fortune 500 companies. "We have been continuously exfiltrating new data for over a year into our private database," the service enthused in its introductory post on Exploit. "Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available." Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis. KrebsOnSecurity traced the apparent source by comparing timestamps on stolen license images with when their owners had their IDs scanned, including at Hertz rental counters and a Planet13 dispensary. Both companies use identity-verification services from Louisiana-based idscan.net, whose technology also scans IDs using infrared and ultraviolet light.
Since the story was published, Krebs reports that the Nexus identity theft service website "vanished from the darkweb, replacing its login page with a plain text message that reads, 'This service is no longer available.'"
[...] The people behind Nexus claim the license images are coming from an active breach at "a major identity verification company" whose customers include multiple Fortune 500 companies. "We have been continuously exfiltrating new data for over a year into our private database," the service enthused in its introductory post on Exploit. "Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available." Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis. KrebsOnSecurity traced the apparent source by comparing timestamps on stolen license images with when their owners had their IDs scanned, including at Hertz rental counters and a Planet13 dispensary. Both companies use identity-verification services from Louisiana-based idscan.net, whose technology also scans IDs using infrared and ultraviolet light.
Since the story was published, Krebs reports that the Nexus identity theft service website "vanished from the darkweb, replacing its login page with a plain text message that reads, 'This service is no longer available.'"
In A Surpise To Only The Stupidest Of People (Score:5, Insightful)
The KYC verified identities are leaking exactly was expected.
The present age verification laws are creating FAR more problems than they solve.
This will come as a surprise only to the stupidest and most moronic people around. A cohort that vastly outnumbers the rest.
Re:In A Surpise To Only The Stupidest Of People (Score:5, Insightful)
These are not online age verifications, the dispensary may be age related, but it's also residency so they know how much you can purchase, Hertz on the other hand is not going to rent you a car if you don't have a valid license.
Re: (Score:3)
Why they'd feel the need to keep the scans in a database, I do not know. Seems unnecessary and didn't do them any favors.
Re: (Score:2)
Hertz can either keep the IDs or they could go through a service that wraps the DMV APIs for each state, like IDscan.net.... oops!
Re: (Score:2)
Any idea if there is an important reason they would need to keep copies of the IDs they scan? Maybe a legal requirement?
Re: (Score:2)
Re: ok? (Score:2)
Keep a photograph of your license in a database accessible from any Hertz location.
Re: (Score:2)
Re: (Score:2)
So why does that mean that the licenses need to be uploaded into a central database? It's not enough for the clerk to just LOOK at the license?
Hertz was founded in 1918. I could be wrong, but I'm pretty sure they didn't have central databases of driver license images back in 1918, and yet somehow Hertz seemed to operate just fine. I'd go so far as to say Hertz was operating in the 21st century without a third party central database of driver licenses.
From my experience over the decades, it wasn't enough for them to just look. They had to take your license, hold it up near their face and squint at it, then set it at the top of the keyboard of their mainframe terminal and peck in a few characters. Then they had to pick it up again, squint and peck some more, then repeat this cycle for at least a couple of minutes.
This was of course followed by scrawling a dozen circles on the reams of fine print for you to put your initials in, topped off by a long argume
Re: (Score:2)
You're missing the point.
Leaks of personal information like this are only possible because some company decided to collect and store it all in one place. It's never a matter of if, but only when, a database will be breached and data leaked.
The age verification laws will create even more vast databases of personal information; names, addresses, financial information, various service accounts, even deep information about each person's habits and preferences. All in the hands private businesses who were the lo
Re: (Score:3)
Re: (Score:1)
Re: (Score:2)
Re: (Score:2)
Which is what the OS age verification was supposed to solve - the OS verifies your age and that's it. You don't have to send your ID to a million third party agencies. Of course, these agencies don't have to worry about OS verification taking over since not every OS will have that functionality (usually phrased as "open source OS exclusion").
All those Linux users will be keeping those third party services alive.
Re: (Score:2)
Where could they get all this data I wonder. Image someone allowed Musk to just put together a crack team to suck all the data the gov has on everyone into a AI model and not understand the implications. I get this is separate but still.. that should be the bigger story.
Flock, is that you (Score:2)
The only thing these idiots did wrong is they forgot to get law enforcement to pay for the service- then its just policing!
Once again (Score:2)
Private industry doing it better than the government.
Holy crap! (Score:5, Interesting)
170 million? That's fairly close to being half of the combined population of USA and Canada!
When you adjust for the people who don't have driving licences, that would seem to be pretty close to the total number of legal drivers in the two countries. Ouch!
Re: (Score:2)
Re: (Score:1)
half of the combined population of USA and Canada!
Soon just half the population of the USA.
[ducking and running]
Charge an excise tax on leaked data (Score:3)
Of $500 per record.
That will clear up these leaks real quick
Re: (Score:2)
who's doing the enforcement?
Re: (Score:2)
Re: (Score:2)
More like increase costs for everyone as cyber insurance rates go through the roof and are passed on to the customer.
Re: Charge an excise tax on leaked data (Score:2)
Good
Destroy surveillance capitalism
Re: (Score:2)
Re: Charge an excise tax on leaked data (Score:2)
I hope the government gets nothing.
The point is to force security, or bankrupt the surveillance industry.
Both are acceptable
The penalties have to be severe
"Selling" isn't the root problem (Score:5, Informative)
Of course, the next obvious step if they can't sell them is to simply release the entire batch into the wild. And how dare any of you think this might somehow be the fault of sweet innocent idscan.net for inadequately protecting the highly sensitive data they were grudgingly entrusted with in the first place.
We need a hell of a lot more CEOs in prison, and we need any politicians that requires / supports / allows this bullshit to join them. Of course, absolutely none of that is going to happen because Joe Sixpack has zero clue any of this is going on; and even if he somehow catches wind of it from a Facebook meme, oh well, it's just one more breach, who cares, he gets notices of those on a monthly basis and has been intentionally trained to treat them as junk mail.
Re: (Score:2)
Yeah I do this when I play Whack-A-Mole. I hit one singular Mole into the hole, then I camp that hole ignoring all others while I proclaim that I have eradicated all Moles, everywhere.
Everyone believes me at my word because if skeptical, everyone will just attack that person with my fictional baby-saving eldery-helping image and not my real drunk-kid-knocking-on-the-wrong-door-with-hands-up actions..
Who (Score:5, Interesting)
"a major identity verification company"
Why is their identity being protected?
Re: (Score:3)
Re: (Score:2)
Re: Who (Score:5, Informative)
I've wondered about this (Score:3)
You thought this too (Score:2)
This is why (Score:5, Insightful)
This right here is why people are so adamantly against giving websites a copy of their ID card
to prove their age.
These vendors then become priority targets for ID theft since the laws, as currently written, do
not force them to take security of said data very seriously. When there is a breach, the company
gets a slap on the wrist, a laughable fine and then it's right back to business as usual.
In the meantime, everyone who gave their ID to said company is now on the hook for potential
ID thieves and the nightmare that goes with it should they draw the short straw.
Before we implement any sort of mandatory age verification that requires your ID going into any
sort of digital online storage, the laws need to be rewritten to make the financial penalties so painful,
that the company in question will find it cheaper to simply do security the right way the first time.
Re: (Score:2)
This right here is why people are so adamantly against giving websites a copy of their ID card
to prove their age.
This leak wasn't from websites getting a copy of an ID card. This was from physical stores: car rental offices and dispensaries.
Re: (Score:2)
This was from physical stores
How do you think these "car rental offices and dispensaries" capture and transfer ID images? Pretty much the same way web sites take a picture of your ID. It's just using a specialized scanner. But otherwise an image upload.
Re: (Score:2)
How they got the copy is largely, irrelevant. The business took a copy of an Id. card and stored it on a internet-facing computer: What happens next is a matter of "when", not "if". The task of 'preventing' crime is enabling criminals. It's much worse because IdScan are in the business of storing Identity Documents and they failed their core function. That should be punished with fines that prevent CxOs getting a bonus or pay-rise for a decade, even when they change corporations.
Would cold/offline storage have helped? (Score:1)
Assume there's a legitimate company out there that will verify driver's licenses. Do they really need to store everything "online"? No, they do not.
They can store it "offline" with a 1- or 2- minute delay to access the data, caching it in "online" systems for maybe 15 minutes.
This, plus alarms when large amounts of data is being moved from "offline" to "online" in a short period of time, would've either made this leak slower than it was or, more likely, led to this year-long leak being discovered and plug
Re: (Score:2)
FaaS - Fascism as a Service (Score:1)
Nothing to see here, just normal day-to-day government work circumventing the 4th amendment by outsourcing data collection to the private sector. This kind of thing happens all the time.
Move along, Citizen!
Re: (Score:3)
Digital IDs (Score:2)
They can use this data to confirm your identity to any other 3rd Party. Just like OAUTH, they only need to send a token out as confirmation.
write on it with a pen (Score:4, Interesting)
If I ever have to upload an image of an ID (which is pretty rare) I always write on it "submitted to XXXX for" with the purpose and the date. It doesn't prevent leaks but if the ID shows up later in a breach like this, we know who is responsible.
I have never had an ID picture rejected for doing this.
Re: (Score:2)
It's a good idea.
I just was renewing my dl with the state of MN and to avoid really stupid amounts of time in registration (going from a normal to "enhanced" id they have you upload not just the front and back of your dl but also your passport. So I instead accepted that I'm going to spend my whole fucking day in their office.
Re: (Score:2)
It's a good idea.
I just was renewing my dl with the state of MN and to avoid really stupid amounts of time in registration (going from a normal to "enhanced" id they have you upload not just the front and back of your dl but also your passport. So I instead accepted that I'm going to spend my whole fucking day in their office.
This ^^^^
Sometimes we have to accept that doing the job right will take longer. Especially when it comes to the convenience/privacy dichotomy.
Re: (Score:2)
Let me know how that works for you when your ID is scanned by a local business such as a liquor store or pharmacy.
Re: (Score:2)
Let me know how that works for you when your ID is scanned by a local business such as a liquor store or pharmacy.
Then I write the name of the guy doing the scanning as well. "Scanned by Bob at LiquorMart 2026/04/09"
If Bob objects, I know to take my ID and never return to that store.