IDScan, a company that provides technology to scan and authenticate government-issued identification documents, disclosed the incident in a September 4 security notice. The company said it learned on or around September 1 that certain data may have been accessed without authorization, and immediately took steps to secure its systems and engaged third-party specialists.
“Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident,” IDScan said in a statement.
The company says its investigation remains ongoing but has determined that an unauthorized third party “may” have accessed or copied customer information stored in IDScan.net cloud accounts. Exposed information may include customers’ full names and driver’s license or other government-issued identification numbers. While not mentioned in the notification, the breach reportedly also allowed threat actors to steal scans of driver’s licenses.
The incident first came to light after security journalist Brian Krebs reported on September 1 that a dark-web platform called “Nexus” was advertising access to more than 153 million U.S. and Canadian driver’s license scans. The service also allegedly contained 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs verified samples from the database by searching for records belonging to himself and others, and traced the exposed information back to IDScan.
Multiple lawsuits have been filed against IDScan after hackers allegedly breached the company and offered access to the database. At the time, IDScan had not publicly acknowledged the incident or responded to requests for comment.
The company said that although full access to the exposed information required payment, it is notifying potentially impacted individuals “in an abundance of caution” and providing free credit monitoring and identity protection services.
After news of the Nexus service spread, the platform was taken offline, though the cybercriminals likely still have access to the database. Since then, multiple threat actors have claimed to be selling the entire database, though these sales have not been confirmed.