Global

150 Million Driver’s Licenses Are Now Searchable on a Russian Cybercrime Forum

5 min read

The company millions of people trusted to scan their driver’s license so a bar, a rental-car counter, or a cannabis dispensary could verify their identity just confirmed that the license itself — front, back, and the photo on it — is now for sale on a Russian cybercrime forum.

IDScan.net, a Louisiana-based identity verification provider, formally confirmed on September 10 that hackers stole more than 150 million driver’s license records from its cloud infrastructure. The company processes over 21 million identity verifications a month across more than 20,000 locations worldwide, with a client list that includes Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment, plus more than 1,000 marijuana dispensaries across 19 US states that rely on it for age verification.

How It Came to Light

Security journalist Brian Krebs first surfaced the breach on September 1, after discovering a searchable dark-web platform called Nexus, advertised on the Russian-language cybercrime forum Exploit. A blank search on the site returned roughly 11.5 million result pages at around 15 entries per page — evidence of scale rather than a proof-of-concept leak. Krebs verified the data was real by finding and confirming his own driver’s license record inside it, complete with six separate image files per document: front and back photo pairs, a basic scan, and both infrared and ultraviolet versions — the exact image formats a real identity-verification system would capture and store, not a crude photocopy.

The database wasn’t static. Records grew by nearly 400,000 within a single 24-hour window while researchers were watching, meaning the breach was still actively harvesting fresh data even after it had already been publicly discovered — a detail that suggests whoever compromised IDScan’s systems either still had live access or had already exfiltrated a continuously updating pipeline of new verifications. Among the records confirmed inside the database: US Secretary of Defense Pete Hegseth’s own driver’s license.

A Verification System That Became a Fraud Tool

The FBI’s New Orleans field office opened a formal investigation on September 1, and by the time IDScan issued its own public confirmation nine days later, the company had begun offering credit-monitoring protection to affected individuals — a standard breach response, but one that does little to address the specific risk this particular data creates. A stolen credit card number can be canceled. A stolen driver’s license photo, paired with a real name and government ID number, doesn’t expire and can’t be reissued the way a card can; it becomes a permanent, reusable tool for identity fraud, account takeover, and — given how many businesses use exactly this kind of document to verify a customer is who they claim to be — a way to defeat the very systems built to catch impersonation.

Security researcher Corrado Paolini framed the underlying design problem plainly: “Any system that stores identity as an image… is one breach away from becoming the very fraud tool it was built to stop.” That’s the real structural lesson here, independent of whatever specific vulnerability let hackers into IDScan’s cloud in the first place. Identity verification as an industry has scaled enormously over the past several years — driven by age-verification laws, KYC requirements, and fraud-prevention mandates across dozens of industries — without a corresponding scale-up in how seriously the underlying document images are secured once collected. IDScan is one vendor; it is not remotely the only company holding a database shaped exactly like this one.

Whether IDScan faces the ransom demand Krebs’ reporting implies — the company itself has declined to clarify whether attackers sought payment to suppress the data — the practical damage is already done the moment 150 million real government ID images sit searchable on a criminal marketplace. Full access reportedly required payment on the dark-web platform itself, meaning the breach has already generated direct criminal revenue independent of whatever IDScan does or doesn’t pay.

What This Means for Philippine Founders

Any Philippine fintech, e-wallet, lending platform, or marketplace that outsources KYC and identity verification to a third-party vendor should treat this as a direct prompt to ask that vendor a specific, concrete question: how is our customers’ scanned ID data stored, and is it encrypted at rest in a way that survives exactly this kind of cloud breach? Many local platforms integrate international identity-verification APIs precisely because building this infrastructure in-house is expensive and specialized — but that same specialization means a single vendor compromise can expose customer data across dozens of unrelated companies at once, in a jurisdiction (the Philippines) where BSP and Data Privacy Act obligations still make the originating business, not the vendor, primarily accountable for the breach’s fallout.

There’s also a product-design lesson worth internalizing directly: any startup currently designing its own KYC flow should treat “store the raw ID image indefinitely” as a real liability decision, not a default setting. Extracting and storing only the verified data fields a business actually needs — rather than retaining the full document image long after verification is complete — meaningfully shrinks what a future breach could expose, even if it adds friction to the verification flow itself. IDScan’s breach is the concrete argument for why that tradeoff is usually worth making.

Brian Krebs cybersecurity data breach identity verification IDScan KYC

Share this article

Share on X Share on LinkedIn Share on Facebook

Related Articles

Newsletter

By subscribing, you agree to our Privacy Policy.