153 Million Driver’s License Scans Found for Sale Online | Sync Up

267

When a business scans your driver’s license, the card comes back to you, but the digital copy may stick around. This week, we’re looking at an FBI investigation into a service claiming access to more than 153 million driver’s license records and what it could mean for how scanned IDs are stored and protected as we sit down and sync up with Rocket IT’s weekly technology update.

In this episode, you’ll learn more about:

  • How more than 153 million driver’s license records ended up for sale online.
  • What researchers found when they checked whether the scanned IDs were real.
  • Why scanned IDs can remain sensitive long after the physical card is returned.
  • What individuals should consider before allowing a business to scan their ID.
  • How businesses can reduce risk when collecting or storing identity information.
  • Why third-party vendors still matter when sensitive customer data is involved.

Video Transcript

Earlier this month, cybersecurity journalist Brian Krebs discovered a new identity theft service called Nexus being advertised on a Russian cybercrime forum. The service claimed to have digital scans of more than 153 million driver’s licenses from people in the United States and Canada, along with millions of other identity documents.

That number hasn’t been independently confirmed as 153 million unique people, but Krebs found strong evidence that at least part of the collection is real. His own driver’s license was being offered as a sample, and when he searched for licenses belonging to friends and family who gave him permission, several of them appeared too.

Some of those records included images of both sides of the license, along with timestamps showing when the documents had apparently been scanned. Those timestamps became an important clue.

For several people, they lined up with times when they had handed their licenses over during real-world transactions. Krebs and other researchers traced examples back to places like rental car counters, where IDs had been scanned as part of normal business.

That investigation eventually pointed toward IDScan.net, a company whose technology businesses use to verify identity documents. IDScan says its technology performs more than 21 million identity verifications every month across more than 20,000 locations worldwide.

At this point, though, it’s important not to get ahead of what’s been confirmed. IDScan.net said it was investigating whether unauthorized access occurred, and the company hasn’t publicly confirmed that it was the source of all of the records Nexus claimed to have. The FBI’s New Orleans field office has also opened an investigation.

What makes this story important goes beyond figuring out exactly where these records came from.

Think about how often you hand over an ID without giving the process much thought. You might rent a car, check into a hotel, verify your age, open an account, or complete some other transaction. Once that ID gets scanned, information that started on a card in your wallet can become data moving through another company’s systems.

And a driver’s license contains information you can’t simply replace the way you would a compromised password. There’s your name, photo, address, date of birth, license number, and other information that can help prove who you are.

For individuals, that means it’s worth being more thoughtful when someone asks to scan an ID. Sometimes there’s a legitimate reason for it, but you can still ask why the scan is needed, what information is being stored, and how long the business plans to keep it.

For businesses, the bigger question is what happens after you collect that information.

If your company scans IDs or relies on another provider to verify customers, employees, or visitors, that outside service becomes part of your data-security picture. It’s worth understanding what information the vendor collects, where it’s stored, who can access it, and how long it’s retained.

And the same principle applies beyond driver’s licenses. Businesses hand sensitive information to payroll providers, CRMs, cloud platforms, payment processors, HR systems, and countless other outside services every day.

Using a third party can make a process easier, but it doesn’t make the responsibility for that information disappear.

So whether or not the investigation ultimately confirms where all 153 million records originated, there’s already a useful lesson here. Before collecting sensitive information, know why you need it. Keep only what serves a real purpose. And when another company is handling that data for you, make sure you understand what happens to it after it leaves your hands.

For help, contact Rocket IT using the link in this video’s description. And to stay up to date on trending technology news, hit that subscribe button and the bell to catch us on next week’s episode of Sync Up with Rocket IT.

Related Posts

Subscribe to Rocket IT's Newsletter

Stay up to date on trending technology news and important updates.

CTA2

Find out if Rocket IT is the right partner for your team

Claim a free consultation with a technology expert.

Fed up with IT support that falls short?

Claim a free 30-minute consultation and explore three key practices to evaluate the maturity of your help desk.