
Recently, an IDScan hack has exposed a collection of driver’s license scans on a dark web identity theft service. More than 153 million U.S. and Canadian driver’s license scans appeared for sale through Nexus.
Currently, the FBI is investigating how the records reached the service. Meanwhile, IDScan confirmed an unauthorized party accessed customer data stored in its cloud.
The IDScan Hack Exposed 153 Million Driver’s Licenses
On the 1st of September, the IDScan hack surfaced when a large database appeared on a cybercrime forum. The files included driver’s licenses from people in the United States and Canada.
In addition, the database reportedly contained more than driver’s licenses. It included over 10 million identification cards, more than three million travel documents and international IDs, plus at least 579,000 medical cards.
However, 153 million does not represent a confirmed count of unique people. The figure describes records advertised through Nexus. The company has not publicly explained how the attacker gained access. Therefore, the exact entry point remains unknown.
Driver’s Licenses Are Hard to Replace
Driver’s licenses contain information that can help prove someone’s identity. Therefore, the IDScan hack creates serious concerns for people whose records appear in the database.
Unlike a password, a driver’s license cannot receive a new secret value after exposure. Criminals could potentially use legitimate identity information when attempting fraud.
Moreover, the attack also highlights risks from storing sensitive identity records through third-party verification services. Businesses depend on such providers to check documents during everyday transactions.
The FBI Investigation Continues
Consequently, the FBI has opened an investigation into the reported exposure. At the same time, IDScan says it secured its systems and brought in outside specialists to examine the incident.
Furthermore, the IDScan hack also coincided with Nexus disappearing from the dark web. Still, investigators do not yet know how widely criminals may have copied or obtained the records.However, IDScan says potentially affected individuals will receive notifications. The company also says it will provide free credit monitoring and identity protection services.
The attack remains under investigation, leaving questions unanswered. Investigators still need to determine how attackers accessed the information and what they copied.
Ultimately,the final scope remains unclear. Until investigators establish more, the 153-million figure should remain a database count, not a confirmed victim total.
