Image: KrebsOnSecurity
The prominent American identity verification provider IDScan seemingly suffered a catastrophic data breach. Hackers are currently selling stolen data on EXPLOIT, a notorious Russian cybercrime forum. This massive cache allegedly contains 153 million scanned copies of driver’s licenses, ID cards, and passports. Furthermore, it includes medical cards. These compromised documents primarily belong to users in the United States and Canada. International users who utilized passports for authentication may also find their documents exposed.
Cybersecurity Experts Verify the Leak
A hacker operating under the alias NEXUS is actively selling this compromised database. NEXUS claims the database holds 153 million scanned driver’s license records. It also purportedly contains over 10 million official ID card scans. Furthermore, it includes over 3 million passport scans and 579,000 medical card scans, featuring both front and back images.
Experts from KrebsOnSecurity independently verified the authenticity of this database. They utilized personal identification belonging to family and friends for confirmation. For instance, one friend recently rented a car using IDScan for verification. Investigators found this specific scan within the database. The recorded authentication timestamp perfectly matched the rental time.
The hacker claims they continuously extracted data from the target system over several years. Due to the exceptionally large volume, the hacker requires significant time to upload the data for sale. Consequently, security experts observed 400,000 new records added to the database within a single 24-hour period.
Data Volume Potentially Exceeds 30TB
The sheer volume of 153 million scanned documents is truly staggering. If each scan averages 1MB, the total data volume reaches 146TB. If compressed to 500KB, it equals approximately 72TB. Even at a highly compressed 200KB per image, the database still exceeds 30TB.
Considering this immense scale, IDScan likely utilized compression technology to reduce image fidelity and save storage space. Nevertheless, the total stolen data likely still exceeds 30TB. The hacker’s claim of spending years extracting this data appears logical. A rapid extraction of such massive data would inevitably trigger bandwidth alerts.
However, this situation strongly suggests significant inadequacies within IDScan’s security infrastructure. Their monitoring systems completely failed to detect this massive, ongoing data exfiltration. The hacker patiently and systematically stole everything over an extended period. This breach essentially exposes the personal identities of a massive portion of the American public. Because the data includes both front and back scans, the breach likely impacts roughly 75 million unique individuals.
IDScan Investigates as FBI Intervenes
IDScan likely discovered the database leak after seeing related online reports. The company subsequently notified its clients regarding a potential security incident. IDScan stated they immediately secured potentially affected systems and preserved crucial system logs. Furthermore, they contacted cyber insurance agencies and external legal counsel. They also hired an independent forensics firm and are actively cooperating with law enforcement agencies.
The Danger of Stolen Identity Documents
Scanned driver’s licenses and ID cards typically contain highly valuable Personal Identifiable Information (PII). This includes full names, dates of birth, residential addresses, document numbers, photographs, and signatures. Victims cannot easily replace much of this vital information. Criminals will likely utilize this stolen data for identity theft, financial fraud, and account recovery scams. They can also use it to bypass various Know Your Customer (KYC) authentication protocols.
Additionally, the New Orleans division of the Federal Bureau of Investigation (FBI) has launched a formal probe. Law enforcement agencies will thoroughly investigate IDScan, the hacker responsible for the leak, and the dark web platforms facilitating the sale. They aim to confirm the incident’s full scope and track the associated cybercriminal activities.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!