Dark Web Platform Sells 153 M+ Driver’s Licenses After IDScan.net Breach
What Happened — A newly discovered dark‑web marketplace, Nexus, is offering more than 153 million driver’s‑license scans, 10 million ID cards, 3 million travel documents, and hundreds of thousands of medical cards. The data appears to have been exfiltrated from identity‑verification provider IDScan.net, which confirmed it is investigating the incident.
Why It Matters for Trust & Control Assurance
- Highlights the risk of relying on a single third‑party for high‑value identity data; continuous vendor‑risk monitoring is essential to detect and remediate such gaps.
- Demonstrates the need for documented controls around data‑handling contracts, encryption, and breach‑response procedures that can be presented as audit evidence.
- Aligns with Verisq’s Vendor Risk Management capability, which supplies real‑time assurance artifacts for third‑party oversight.
Who Is Affected – SaaS identity‑verification services, their downstream clients (e‑commerce, travel, cannabis dispensaries), and any organization that collects government‑issued IDs from customers.
Recommended Actions
- Review and tighten contracts with ID‑verification vendors: require recent SOC 2/ISO 27001 reports, breach‑notification clauses, and data‑encryption commitments.
- Deploy continuous third‑party risk monitoring to collect evidence of vendor controls and detect deviations promptly.
- Implement tokenization or on‑premise encryption for stored ID images to limit exposure if a provider is compromised.
Technical Notes – The breach was uncovered by KrebsOnSecurity, which captured front‑and‑back, infrared, and ultraviolet scans of driver’s licenses. The FBI’s New Orleans field office has opened an investigation. No specific vulnerability (CVE) was disclosed; the incident appears to stem from a supply‑chain compromise of IDScan.net’s data‑collection pipeline. Source: Malwarebytes Labs