SECURITY: Your IDENTIFICATION may have been compromised (153 million people's info stolen from idscan.net)!

Number of people's names compromised. 

Image from KrebsOnSecurity.com1.

BACKGROUND

In the beginning of September, sources alerted Brian Krebs, from KrebsOnSecurity.com, that 153 million (drivers') identities from the United States and Canada were stolen from idscan.net, a prominent identity verification company based in Louisiana, and that the FBI was launching an investigation of the breach2. The compromised information includes but is not limited to ID, medical cards, and travel documents. Records of Brian Krebs including U.S. Defense Secretary Pete Hegseth and other high ranking U.S. government officials whose drivers licenses were also found and available for sale on the dark web on a platform called Nexus--taken down shortly after KrebsOnSecurity.com's reporting on the incident1.

Brian Krebs validated that people's information was compromised by searching through Nexus's platform before it was taken down, something that he confirmed with me directly, since I investigated my own information as well. As of this writing, I have not yet validated whether my information was found on the dark web in regards to the idscan.net breach.

Considering the sensitivity of the information, it is recommended to take necessary actions to better secure your ID information. All of this depends on your risk tolerance.

The blog post includes an introduction of what the dark web is and recommendations. Be safe.

CAUTION & DISCLAIMER

  • The Dark Web or darknet that can also be referred to as the Tor network (short for The Onion Router) can best be referred to as an internet network within the existing internet infrastructure. The Tor network cannot be interacted with directly despite using existing internet infrastructure, but instead requires tools like the Tor browser to traverse within it. Common uses for Tor is to further anonymize oneself on the internet as well as host services within the Tor network. Other common uses are to circumvent areas that have internet censorship. Usage of the Tor network is not inherently malicious. With that being said, there is an abundance of nefarious content that can be found on the Tor network because of the very same reason of anonymity and the ability to host services through existing internet infrastructure3.
  • This is neither an endorsement or disapproval of the Dark Web but suggests that if you decide that you want to enter the space, take considerable caution to do so. The information provided in this blog post DOES NOT go into detail about how to use Tor and only provides a primer to better describe the topic of the blog post.
  • If you are concerned about your identification be stolen, consult professional help, and this blog post provides common actions that you can take to protect yourself.
  • Engaging in and entering the Tor network is at your own risk.
  • This post is provided as is.

I would recommend taking a look at the references section for more insights about some of the topics.

ENVIRONMENT

People's compromised identification was made available on the Dark Web. As of Brian Kreb's reporting the incident, the Nexus website selling the compromised ID, has been taken offline.

OBSERVATIONS

Pete Hegseth Image from KrebsOnSecurity.com1.

A list of unknown and known information based on observing the images:

UNKNOWNS

  • When specifically were people's ID information compromised? The breach occurred over the course of the year.
  • Where did the compromise happen? Did it happen on the machine that scanned the documents? Was the data compromised during the transmission from device to servers or in the other direction?
  • What device(s) or app(s) that could have compromised the data?
  • Did the compromise happen within the infrastructure of Idscan.net or 3rd party infrastructure?
  • How was the data captured, man-in-the-middle (mitm), social engineering, etc?
  • How many people were involved? Are people involved in other cyber crime also involved with this breach?
  • Who were the people who conducted the breach?

KNOWN

Brian Kreb

Image from KrebsOnSecurity.com1.

  • Brian Krebs validated that ID information has been compromised regardless of who the person is.
  • Images do not appear to be the "raw" profile image, rather they appear to be scans, that include the different image layers4.
  • Metadata and timestamps are included with for sale profile5.
    The timestamps traces suggestions of where the compromise happened. 
  • The images from Krebs shows that they are not the digital "original" images but a "scanned" image of the hard copy id rather than the digital image itself.
  • The date formatting is not synonymous with the USA. The US typically formats dates with Month, Year, Date where the displayed dates on the Nexus website are Year first, with the assumption that Month and Date follow6.
  • The design of the webpage is retro, "Windows xp" style7.
  • The scanned images' names do not have spaces8...
  • Considering that the breach is for people within Canada and the USA, this suggests it was domestic.

AUDIENCES

Anyone concerned about their IDs being compromised.

PURPOSE

Provide awareness and recommended actions to help secure your ID information.

PROBLEM

Determining if your ID has been compromised and to what extent. Provide helpful actions to take.

TOOLS

  • Burner Device
  • Containerized operating system
  • Different network from your main network
  • Tor Browser
  • Contacts/Representatives to help secure your accounts

ACTION_ITEMS

Exact URL or potential pertinent information have been purposely redacted for security purposes. No links are provided to Dark web content.

ACTIONS I TOOK

  1. Entered the dark web and searched using the web crawler Ahmia.
  2. Located services with the prefix nexus[a-zA-Z0-9]*.onion that requires authentication.
  3. Contacted Brian Krebs, acquired the Tor url (nexus[a-zA-Z0-9]*.onion) where he validated the compromised IDs of people.
  4. Compared urls to determine if there were correlations TBD. The design differs suggesting, no immediate correlation. Url naming are not the same.
  5. Suggested potential areas where the compromised occurred: Did the exploit happen on the device that scanned the licenses or was it the database itself? Did the exploit occur during transmission to the database?

ACTIONS YOU CAN TAKE

The list of what you can do is obviously incomplete but does offer suggestions to decrease the potential attack vectors and vulnerabilities.

  • During the time of acquiring your ID or driver's license, you may have been given the option to have a separate unique number instead of your social security number printed on your ID as a safe guard against these types of scenarios. Confirm this and you might be a little more self-assured.
  • Review your online accounts, check security settings.
  • Review financial activity includes but not limited to credit card and bank statements.
  • As a follow up to the previous bullet, freeze your credit cards (and credit info)9 and deal with the headaches that come with that.
  • Suggest using a VPN9. This is still debatable.
  • Use strong passwords9.
  • Be careful with your stuff.
  • Use Linux.
  • Familiarize yourself with standardized practices for privacy, like HIPAA.
  • Keep a record of interactions with people who have access to some sensitive information about you.
  • Keep a record of when you install new applications on your devices.
  • Limit people from accessing your devices.
  • If visiting website, make sure they are using https instead of http if you are filling out forms. This alone does not determine whether a website is safe but only determines that information being transmitted from your device to the server is encrypted during transit and garbles up the data for prying eyes.
  • Avoid suspect phone calls, emails, links, and websites. It is a lot easier to inspect links on a computer because you can copy and paste a link to a text document and see what the url is. For example, a weekly newsletter I send every week contains a link to my website https://www.avrstory.net?utm_source=participant_button&utm_medium=email&utm_campaign=emailer&utm_id=avrs_email_link. The first section https://www.avrstory.net is the website. The ?utm_source=participant_button&utm_medium=email&utm_campaign=emailer&utm_id=avrs_email_link is the extension for Google Analytics to categorize and track when someone clicks on the link. In itself, is not inherently unsafe however does provide me analytics about site visits :). 
  • With your device, avoid connecting to accounts if connected to a public network.
  • Assume that people and companies, for that matter, can be or have scumbags.
  • Call IDScan directly at 1-833-516-2980 (Monday-Friday: 8AM-8PM)9.
  • Subscribe and read A VR STORY BLOG.
  • Live in complete isolation away from technology, internet, and people. Consider taking on a new identity.(Joking, but am I?)

VERSIONS

2026v.0.1.4:revise (27Sept26): Fixed wording, included links to krebonsecurity.com, fixed broken reference link10

2026v.0.1.0:init10

REFERENCES

  1. KrebsOnSecurity Blog ↩ ↩2 ↩3 ↩4

  2. FBI Probes Possible Dark Web Sale of Over 153 Million Driver's License Scans. How Can You Protect Info? ↩

  3. The Onion Router: The Tor Project ↩

  4. Different databases can contain different versions and stages of particular data. The image looking like more like a scan indicates to me that wherever the images of people's faces are stored were not compromised. Determining what and where the stage of the breach from idscan.net hardware and software is unknown. ↩

  5. Timestamps do not really tell all that much IMO because the timestamps could be for just about anything, on top of being altered later in processing data. The timestamps could very well just indicate of when the profile was uploaded. ↩

  6. Date formatting itself is not an indication of fully determining the origins of where the attackers are from, however, does suggest that the attack may have originated from somewhere else, or is not from the USA. In some regards, this could also be a detail that could lead an investigation astray. ↩

  7. A classical web design suggests to me that the creators may have take some precautions hosting their dark web ecommerce site to minimize detection. You are probably wondering, why would this be important? Well... There are two obvious areas that could provide a window of where the servers are... One being the fonts and two the javascript libraries could be areas that could be further looked at. Obviously if the website on the darkweb is offline, the likelihood of gathering information about it would be slim to none. However, if they are pulling fonts and javascript externally there is a slight window there to peer through. Using system stored javascript and system fonts prevents calls to these assets outside their own system(s). With that being said, more than likely, they are going to attach the payment system through cryptocurrency and at some point, we are going to encounter a scenario where those transactions are going to appear on the public ledgers. ↩

  8. On Linux/Unix platforms having spaces included in naming a file is highly discouraged. One it makes it difficult to query because it often requires having an 'escape' character, \, a down slash to substitute for the space. A space is usually used for separating values from each other, in very much the same way standard writing uses commas , and semicolons ;. Most Windows and possibly Mac (even though Mac is Unix based) users, not delving into the technical side of the operating system, will most likely add spaces to name their files. This observation probably doesn't pose any remarkable context but it still is a fun little tidbit. ↩

  9. CNET "Over 153 Million Driver's Licenses Were Stolen by Hackers. Here's What to Know" ↩ ↩2 ↩3 ↩4

  10. blog.avrstory.net's development release page. ↩

Comments

Popular Posts