Massive Data Breach Involving More Than 160M Driver’s Licenses, Other PII Being Investigated

WASHINGTON — The FBI is investigating a possible massive data breach involving scans of more than 160 million North American driver’s licenses and other identification documents, an exposure that could pose new risks to credit unions’ digital account-opening and identity-verification processes, according to Bloomberg News.

An FBI spokesperson confirmed to Bloomberg that the bureau is investigating the incident but declined to provide additional details because the investigation is ongoing.

Bloomberg reported that criminals are advertising access to more than 160 million driver’s licenses through a service called Nexus. An advertisement posted on Exploit, a Russian-language cybercrime forum, described the database as containing “160M+ USA DL/ID Scans + data.”

More Than 10-Million Documents Claimed

The sellers also claim to possess more than 10 million additional documents, including residency cards, medical cards and international identity documents, Bloomberg reported.

It remains unclear where the information originated or whether the sellers’ claims about the size of the database have been independently verified.

Potentially Major Fraud Implications

If confirmed, the breach could have significant implications for financial institutions because driver’s licenses and other government-issued identification are commonly used to verify identities when consumers open accounts, apply for loans or conduct other financial transactions.

Access to large numbers of legitimate identification documents could potentially give fraudsters another tool for impersonating consumers and attempting to defeat identity verification and know-your-customer controls.

‘Persistent Access’

As credit unions are well aware, the incident comes as financial institutions increasingly rely on digital identity verification companies to authenticate customers/members remotely.

According to Bloomberg, the advertisement for the stolen information claimed the sellers have continuing access to an identity verification provider and its customers.

“We have persistent access to a major identity verification company and its customers, which includes multiple Fortune-500 companies,” the advertisement said, according to Bloomberg.

The identity verification company allegedly involved has not been publicly identified, and Bloomberg reported the source of the data remains unclear.

Researcher Says Breach May Be Ongoing

Cyberthreat researcher Zach Edwards, whose own identification reportedly appeared in the cache, told Bloomberg that if the claims are confirmed, the incident could rank among the largest known exposures of U.S. government identity documents.

Edwards, who works for cybersecurity company Infoblox, said evidence suggests the compromise may be ongoing, with new identification documents continuing to be submitted and stolen.

That possibility could make the incident particularly significant because it would suggest attackers have access not simply to a previously stolen database, but potentially to an active flow of documents being submitted for identity verification.

Edwards also told Bloomberg that the exposure could create national security concerns if identification documents belonging to government officials or other high-profile individuals are included.

Documents Confirmed With License Holders

Independent cybersecurity journalist Brian Krebs first reported the apparent breach and contacted nine people whose driver’s licenses appeared among the documents being offered for sale, according to Bloomberg. Those individuals confirmed the documents were authentic.

The Nexus service reportedly went offline shortly after news emerged that the FBI was investigating.

The potential breach also underscores a growing security challenge surrounding the collection and storage of identity documents. Financial institutions and their technology providers routinely depend on government-issued identification to distinguish legitimate customers from fraudsters.

The FBI told Bloomberg it is looking into the incident but declined further comment.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.