Scans of driver’s licenses and other identity documents, such as passports, are one of the most commonly traded commodities among cyber criminal forums, and often feature heavily in some of the more damaging datasets exposed by ransomware incidents.
But a pair of recent breaches have seen tens of millions of license scans compromised in job lots, putting their owners at risk of identity theft, scams, and other cyber-criminal activity.
On September 1, superstar cyber security reporter Brian Krebs outlined the details of an identity theft service advertised on a Russian hacking forum, called Nexus. According to Krebs, the operator of that service was selling access to more than 170 million scanned identity documents, including 153 million Canadian and US driver’s licenses.
Krebs' own license was part of the dataset, alongside licenses belonging to senior government officials, such as Secretary of Defence Pete Hegseth.
“Curiously, the identity records include not only driver's licenses but also marijuana dispensary cards. Some of the records list their ‘source’ as ‘CDL,’ presumably short for ‘commercial driver's license.’ Other records carry the source notation of ‘CAC,’ which may refer to Common Access Cards, government-issued identity cards that grant physical access to government buildings and secure rooms,” Krebs said in a blog post.
“The people behind Nexus claim the license images are coming from an active breach at ‘a major identity verification company’ whose customers include multiple Fortune 500 companies.”
The operators behind Nexus pulled the service down soon after, with the FBI eventually getting onto the case, and identity verification firm idscan.net eventually disclosing that “certain data” may have been accessed without authorisation.
Then, only a week later, cyber extortionist group ShinyHunters claimed it had stolen more than 200,000 license scans from the US state of Florida’s Driver and Vehicle Information Database. To prove the claim was real, the hackers shared a screenshot of disgraced financier Jeffrey Epstein’s entry in the system.
ShinyHunters told BleepingComputer that it would announce further DMV-related breaches “over the coming weeks”. Driver’s licenses are, clearly, a prime target and big business for actors such as ShinyHunters.
“Together, these incidents expose vulnerabilities at both ends of the identity ecosystem. One allegedly targeted a government database containing detailed driver records, while the other appears connected to license scans collected during routine commercial transactions,” Danny Jenkin’s, founder and CEO of endpoint protection firm ThreatLocker, explained.
“Consumers have been conditioned to view a driver’s license as a safe and trusted way to prove their identity, but every scan creates another permanent copy of a credential that cannot simply be reset after a breach.
“A driver’s license has effectively become a master key to a consumer’s identity. A complete scan gives criminals much more than an identification number – it can reveal a person’s photograph, signature, address, date of birth and other information contained in a legitimate government credential. Criminals could potentially use this data to open fraudulent accounts, conduct targeted phishing and password-reset attacks, commit insurance, medical, tax or government-benefit fraud, or create convincing synthetic identities. The danger grows when license information is combined with Social Security numbers, passwords and other personal data exposed in previous breaches.”
According to Jenkins, another immediate concern is how documents such as licenses can enable phishing attacks by making them more convincing.
“For example, a cybercriminal could send what appears to be a legitimate DMV renewal notice that includes the recipient’s actual driver’s license number,” Jenkins said.
“Personal details like that give fraudulent messages a veneer of legitimacy, increasing the likelihood that someone will click a malicious link, surrender additional information or download malware.”
The real concern, Jenkins believes, is the permanence of this information. Credit cards or passwords can be replaced, but faces, birth dates, signatures or identity histories are another matter entirely.
“Even when a state issues a new license, much of the information displayed on it remains unchanged. This gives criminals opportunities to exploit stolen data for years after the original breach,” Jenkins said.
“The good news is that consumers can take immediate steps to reduce their risk. They should freeze their credit with all three credit bureaus, regularly review their credit reports, obtain an IRS Identity Protection PIN and secure their email and financial accounts with unique passwords and phishing-resistant authentication methods, such as passkeys or authenticator apps. Consumers should also enable alerts for new transactions, login attempts, password resets and changes to contact information, and report any suspected identity misuse immediately.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.