Privacy News FBI probes report of data breach exposing millions of drivers' licenses in US, Canada

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,119
6,100
2,168
Germany
WASHINGTON, Sept 2 (Reuters) - The FBI said on Wednesday it was investigating a report that tens of millions of drivers' licenses belonging to people in the United States and Canada were being sold on the dark web.
On Tuesday, the ‌independent journalist Brian Krebs said he had discovered a dark web site, opens new tab selling digital scans of millions of drivers' licenses from people in the U.S. and Canada. He said he confirmed the authenticity of the data being sold with nine people.
In a brief statement on Wednesday, the bureau said it was “looking into the incident” but could not comment “due to the ⁠ongoing nature of the investigation.”
The breach, if confirmed, could be one of the largest-ever exposures of government-issued identity documents in North America, creating risks of identity theft and fraud for tens of millions of people.
Krebs said he was alerted to the site after it was advertised on a Russian cybercrime forum, with his own driver's license being offered as a free sample. Krebs said the service, dubbed Nexus, claimed to have tens of millions of licenses for people in the U.S. and Canada, as well as millions of other identification cards and travel documents and hundreds of ‌thousands ⁠of medical records. Krebs said that the site appeared to be updating its database of stolen data in real time, indicating that it was being fed by a live breach.
Zach Edwards, a threat researcher at the cybersecurity company Infoblox, said the incident was unprecedented in terms of its sweep.
"There's never been a breach ⁠of driver's licenses at this scale," said Edwards, who added that his own license was available for sale on the site. Edwards said that the ongoing nature of the breach "means that this attack created legitimate national ⁠security risks for high-profile individuals."
Reuters could not establish the source of the stolen data. Krebs quoted a representative of New Orleans-based identity verification provider IDScan.net as saying that it was investigating the matter. IDScan.net, ⁠which describes itself as providing "ID fraud prevention at scale," did not return repeated messages from Reuters.
Krebs said the dark web site offering the driver's license data vanished shortly after he published his report.
 
What the report establishes

Based on the quoted Reuters report, the FBI had acknowledged that it was investigating claims that large numbers of U.S. and Canadian driver’s licenses were being offered on a dark-web site. However, the source, total number, and authenticity of the complete dataset had not been independently established.

The report also indicates that:

  • Some individuals reportedly verified that their licenses appeared in the samples.
  • The alleged source of the data was unknown.
  • The site disappeared after public reporting.
  • The claims involved driver’s licenses as well as other identity and medical records, but those broader claims were also not confirmed.

What affected individuals should do

If someone believes their license information may be exposed, sensible precautions include:

  • Monitor bank, credit-card, and other financial accounts for unfamiliar activity.
  • Review credit reports through the official source for the relevant country.
  • Consider placing a fraud alert or credit freeze where available.
  • Be cautious of phishing calls, emails, or messages that use accurate personal details.
  • Contact the issuing motor-vehicle authority for guidance, especially if there are signs of identity fraud.
  • Report suspected identity theft to the appropriate government authority and affected financial institution.

A driver’s-license exposure does not by itself prove that an individual’s accounts have been compromised, but the information can make impersonation and targeted phishing more convincing. The key point is that the reported dataset’s full scope and origin were not confirmed in the quoted material, so people should take reasonable protective steps without assuming that every license was exposed.