FBI investigates breach of 153 million driving license records at IDscan.net

Wait 5 sec.

Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth – and investigative reporter Brian Krebs, who has dug deep into the data breach on his blog KrebsOnSecurity.The driving license details were offered for sale by a user of the Russian cybercrime forum Exploit, KrebsOnSecurity said. In addition to the 153 million driving licenses, the user also offered details ofmore than 10 million identification cards; more than three million travel documents or international IDs; and at least 579,000 medical cards through a site called Nexus. That site has now been taken down – although, of course, all the acquired data could always pop up on another site.KrebsOnSecurity traced the leak to IDscan.net, an identity verification service used by car rental company Hertz. IDscan The company has a long list of clients, including Target, FedEx, Motorola Solutions, the financial services giant Jack Henry, and Caesars Entertainment.IDscan has not yet issued an official statement about the breach, but Jillian Kossman, a marketing and operations leader at IDscan.net told KrebsOnSecurity, “I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation.” The investigation into the leak has gathered pace, with an official enquiry from the FBI into the source of the images.However, the breach has revealed a vulnerability at the heart of enterprises’ use of ID verification systems: No matter how secure businesses’ IT systems and processes are, they are also dependent on the security of their suppliers.