Foreign media, citing independent security journalist Brian Krebs, reported that a service provider used to verify government-issued identification documents may have been hacked, with potentially large numbers of driver’s license and passport images stolen. If true, this would be one of the largest single identity document breaches known in recent years.
Dark web sites claim to possess vast amounts of identification documents
The report mentions that a身份盗窃 website named Nexus appeared on the dark web this week, claiming to offer access to over 150 million driver’s licenses and passports belonging to residents of the United States and Canada.
An advertisement posted on a Russian cybercrime forum claims that the data originated from “a large identity verification company” and that approximately 500,000 new files are added daily. This suggests that the attackers may have had near-real-time access to the company’s systems.
The suspected source points to IDScan
After comparing the leaked sample, Krebs and security researcher Zach Edwards concluded that the Louisiana-based company IDScan may be the source of the data. The company provides identity verification services to numerous technology and consumer brands, processing tens of millions of identity verification requests globally each month.
TechCrunch reported that Jimmy Roussel, CEO of IDScan, did not respond to requests for comment. Jillain Kossman, the company’s Chief Operating Officer, told Krebs that the company is investigating the matter.
The FBI has intervened in the investigation.
The report also stated that the FBI’s New Orleans field office has become involved in the investigation. The FBI did not respond to TechCrunch’s request for comment. A U.S. Department of Defense spokesperson also did not immediately comment on the report.
This incident occurs as governments in multiple regions are advancing age verification regulations that require adults to upload identification documents to prove their eligibility to access certain websites or apps. Security researchers and privacy advocates have long warned that centrally storing vast amounts of identification documents significantly increases the risk of theft. Shortly after the report was published, Nexus was taken offline, but the actual extent of the leaked data's spread remains unclear.
