{"id":9308,"date":"2026-09-04T13:47:47","date_gmt":"2026-09-04T13:47:47","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9308"},"modified":"2026-09-04T13:47:47","modified_gmt":"2026-09-04T13:47:47","slug":"fbi-investigates-breach-of-153-million-driving-license-records-at-idscan-net","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9308","title":{"rendered":"FBI investigates breach of 153 million driving license records at IDscan.net"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers\u2019 licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth \u2013 and investigative reporter Brian Krebs, who has dug deep into the data breach on his blog <a href=\"https:\/\/krebsonsecurity.com\/2026\/09\/fbi-probes-service-selling-153m-drivers-licenses\/\" target=\"_blank\" rel=\"noopener\">KrebsOnSecurity<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The driving license details were offered for sale by a user of the Russian cybercrime forum Exploit, KrebsOnSecurity said. In addition to the 153 million driving licenses, the user also offered details ofmore than 10 million identification cards; more than three million travel documents or international IDs; and at least 579,000 medical cards through a site called Nexus. That site has now been taken down \u2013 although, of course, all the acquired data could always pop up on another site.<\/p>\n<p class=\"wp-block-paragraph\">KrebsOnSecurity traced the leak to IDscan.net, an identity verification service used by car rental company Hertz. IDscan The company has a long list of clients, including Target, FedEx, Motorola Solutions, the financial services giant Jack Henry, and Caesars Entertainment.<\/p>\n<p class=\"wp-block-paragraph\">IDscan has not yet issued an official statement about the breach, but Jillian Kossman, a marketing and operations leader at IDscan.net told KrebsOnSecurity, \u201cI\u2019m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team\u2019s investigation.\u201d The investigation into the leak has gathered pace, with an official enquiry from the FBI into the source of the images.<\/p>\n<p class=\"wp-block-paragraph\">However, the breach has revealed a vulnerability at the heart of enterprises\u2019 use of ID verification systems: No matter how secure businesses\u2019 IT systems and processes are, they are also dependent on the security of their suppliers.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers\u2019 licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth \u2013 and investigative reporter Brian Krebs, who has dug deep into the data breach on his blog [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9309,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9308","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9308"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9308"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9308\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9309"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}