← Back to Daily Briefing (#idscan.net)

An identity verification (IDV) supply chain compromise allegedly targeting idscan.net has exposed between 153 million and 170 million driver's license records from the United States and Canada. Exfiltrated data consists of high-resolution digital scans of government-issued IDs and associated PII, including full names, dates of birth, and residential addresses. Technical investigations are currently targeting API endpoint exploitation, unauthorized third-party access tokens, or cloud storage misconfigurations as the primary breach vectors. This compromise creates systemic risk by undermining the KYC/AML integrity of downstream financial services, enabling high-fidelity synthetic identity fraud and sophisticated account takeover (ATO) attacks.

  • Incident Scope: Mass Identity Exfiltration

    • Estimated Volume: Between 153,000,000 and 170,000,000+ individual driver's license records.
    • Geographic Reach: Extensive datasets impacting highly populated regions across the United States and Canada.
    • Data Composition: High-fidelity digital scans of government-issued identification paired with comprehensive PII.
  • Technical Artifacts: Data & Vectors

    • Primary Payload: High-resolution image files of IDs, potentially containing embedded EXIF metadata, timestamps, and device identifiers.
    • PII Components: Datasets including full names, dates of birth, residential addresses, and license numbers.
    • Suspected Attack Vectors: Investigation is focused on API endpoint exploitation, unauthorized third-party access tokens, or cloud infrastructure misconfigurations.
  • Threat Intelligence: Dark Web Activity

    • Marketplace Activity: Threat actors are actively marketing sample datasets on dark web forums as proof-of-concept for illicit listings.
    • Data Utility: The sale of high-fidelity scans increases the utility of the data for bypassing automated identity verification systems.
    • Investigative Status: The FBI is currently investigating the provenance and the organized sale of these specific identity records.
  • Impact Analysis: Systemic & Regulatory Risk

    • Operational Risk: Facilitates high-success synthetic identity fraud and sophisticated account takeover (ATO) campaigns.
    • Supply Chain Fallout: Compromises the KYC/AML integrity of downstream integrated services, including FinTech, Neobanks, and crypto exchanges.
    • Regulatory Exposure: Significant liability for affected organizations under CCPA (US) and PIPEDA (Canada) privacy frameworks.
  • Defense & Mitigation: Strengthening Identity Orchestration

    • Immediate Response: Conduct rapid audits of third-party IDV integrations and perform a mandatory rotation of all associated API credentials and tokens.
    • Enhanced Monitoring: Implement behavioral analytics to detect anomalous, high-volume, or geographically inconsistent identity verification requests.
    • Supply Chain Resilience: Diversify identity verification providers to mitigate single-point-of-failure risks inherent in the IDV SaaS model.

Related posts

  1. hackernews.com — Hackers Had a Live Feed of Every ID Verification Company Scanned for over a Year
  2. techjacksolutions.com — Dark Web 'Nexus' Service Sells 153M+ Driver's License Scans; FBI Opens Inquiry as KrebsOnSecurity Investigation Points to Identity Verification Firm
  3. esecurityplanet.com — FBI Investigates Dark Web Trove of 153 Million Driver’s Licenses
  4. Securitymagazine
  5. Kucoin
  6. Saasrise
  7. Scworld
  8. Biometricupdate
  9. Nccgroup
  10. Cybersecuritydive
  11. Facebook

LINK COPIED TO CLIPBOARD