Feds Investigating ~153 Million Leaked Drivers Licenses 4 hours ago
#1
An estimated 153 million drivers licenses were leaked on Exploit. With all of the new KYC and ID requirements, it is not surprising they are being poorly handled or leaked.
Whether it's crypto, adult content, or identity verification - your ID is being stored improperly somewhere. Stay safe and avoid KYC/ID requirements where possible.
Read More: https://www.tomshardware.com/tech-indust...e-provider
Whether it's crypto, adult content, or identity verification - your ID is being stored improperly somewhere. Stay safe and avoid KYC/ID requirements where possible.
Quote:More than 153 million US and Canadian driverās licenses, as well as other identity documents, have reportedly become available for purchase on the dark web for a limited time. According to cybersecurity journalist Brian Krebs, the service was called Nexus, and although itās no longer available at the time of writing, it claimed to have possessed 153 million driverās licenses, 10 million ID cards, 1.9 million travel documents, 1.3 million international driverās licenses, 579k medical cards, 429k common access cards, 91k residence cards, 77k employment authorization records, and 5 million other documents, allegedly sourced from an ID-authentication service based in Louisiana.
The service was advertised on the Russian cybercrime forum Exploit, where whoever was promoting it posted the driverās license of Krebs as a free sample, which caught the journalistās attention. He was also able to see a preview of U.S. Secretary of Defense Pete Hegsethās information on the database ā a concerning breach of security for someone with such a sensitive position in the government. After further investigation, they concluded that the service seemed to have possessed legitimate data, especially after searching for the data of several of his friends and family members with their consent. One thing that all the people he found in the database had in common was that they all used Hertz to rent a vehicle.
Krebs also talked with security and privacy researcher Zach Edwards, who said that their information was also found on Nexus. Edwards said that they did not rent a car recently but used their ID at a Planet13 marijuana dispensary. The time stamps found on the scanned images of the driverās licenses and other identity documents coincide with the time that the victims used their IDs at the said companies, confirming that they were the sources of the leaks. However, Planet13 and Hertz do not do their own authentication; instead, they contract a service provider for the service. Now, it turns out that both Planet13 and Hertz used the company for identity verification and ID-authentication ā IDScan.
Based on the evidence gathered by Krebs, it seems that the leak is centered around the company. He has already contacted the company about the issue, and they said they were investigating the matter. āAt this point Iām not able to share any additional information, but the updates you have provided have been welcome, and helpful to our teamās investigation,ā Jillian Kossman, a marketing and operations leader at idscan.net, told the journalist. The FBI has also started looking into the leak, with its New Orleans field office opening an official investigation into the breach.
The massive amount of data that was briefly available on the dark web is certainly concerning. A similar data breach hit Discord after its third-party service provider was hit and resulted in the exposure of 70,000 government IDs. Incidents like these have got privacy experts concerned with the push for online age verification requirements, which is why the EFF is asking the California governor to veto the law requiring this.
Read More: https://www.tomshardware.com/tech-indust...e-provider












![[Image: 7ajmN5P.jpg]](https://i.imgur.com/7ajmN5P.jpg)
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)








![[Image: e91-1.png]](https://i.ibb.co/VHj0yMD/e91-1.png)