AI Security AI安全 5h ago Updated 2h ago 更新于 2小时前 43

153 Million Driver License Images Offered on Dark Web 1.53亿张驾照图片在黑市出售

A threat actor listed over 153 million US and Canadian driver's licenses, along with millions of other identity documents, on a dark web identity theft service called Nexus The breach is believed to have originated from IDScan.net, a Louisiana-based identity verification firm serving Fortune 500 companies across multiple industries Investigative journalist Brian Krebs verified the authenticity of the stolen data by finding his own and others' driver's licenses on the platform The FBI has launche 暗网身份盗窃平台Nexus泄露超过1.53亿份美国驾照及1000万份其他身份证件,数据疑似从身份验证平台IDScan.net窃取 IDScan.net服务多家财富500强企业,每月处理2100万次身份验证,覆盖汽车、银行、游戏、教育等十几个行业 FBI已启动正式调查,部分泄露驾照属于FBI探员,泄露平台在调查报道发布后被关闭 安全专家建议组织假设身份证据最终可能被泄露,需建立数据清单并监控异常批量访问行为

72
Hot 热度
55
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • A threat actor listed over 153 million US and Canadian driver's licenses, along with millions of other identity documents, on a dark web identity theft service called Nexus
  • The breach is believed to have originated from IDScan.net, a Louisiana-based identity verification firm serving Fortune 500 companies across multiple industries
  • Investigative journalist Brian Krebs verified the authenticity of the stolen data by finding his own and others' driver's licenses on the platform
  • The FBI has launched an official investigation after learning some exfiltrated licenses belong to FBI agents; Nexus was shut down shortly after Krebs published his findings
  • Experts urge organizations to assume identity evidence will eventually be compromised and to implement stronger data governance, monitoring, and contractual safeguards with identity providers

Why It Matters

This breach highlights the systemic risk of centralized identity verification ecosystems, where a single compromised vendor can expose hundreds of millions of sensitive personal records. For AI and security practitioners, it underscores the urgency of designing identity systems that do not rely solely on document-based verification, which can be rendered obsolete when underlying data is exfiltrated. The incident also demonstrates how dark web marketplaces are becoming increasingly sophisticated platforms for trading stolen identity data at scale.

Technical Details

  • The Nexus platform listed over 153 million driver's licenses, 10+ million identification cards, 3+ million travel documents and international IDs, and approximately 580,000 medical cards, with only about 1.1 million licenses originating from Canada
  • IDScan.net performs over 21 million verifications monthly across 20,000+ locations and serves clients in automotive, banking, fintech, gaming, education, transportation, hospitality, law enforcement, retail, and security
  • The breach appears to have been an active exfiltration rather than a one-time leak, with the threat actor claiming direct access to the identity verification firm's systems
  • Krebs independently verified the breach's legitimacy by locating his own driver's license and those of other individuals on the Nexus platform
  • NCC Group's Tim Rawlins recommended monitoring for abnormal bulk access patterns, unusual activity involving service accounts, APIs, and administrative accounts, and establishing contractual requirements for logging, data segregation, retention, and incident notification

Industry Insight

  • Organizations relying on third-party identity verification providers must treat vendor risk as a critical security concern; due diligence should include assessing data retention practices, access controls, and breach notification capabilities before contracting
  • The era of static document-based identity proofing is ending—industries should accelerate adoption of multi-factor, behavioral, and cryptographic identity verification methods that do not depend solely on scanned government IDs
  • Individuals should minimize the distribution of driver's license copies and actively question whether physical inspection alone suffices during verification interactions, reducing the attack surface for future breaches

TL;DR

  • 暗网身份盗窃平台Nexus泄露超过1.53亿份美国驾照及1000万份其他身份证件,数据疑似从身份验证平台IDScan.net窃取
  • IDScan.net服务多家财富500强企业,每月处理2100万次身份验证,覆盖汽车、银行、游戏、教育等十几个行业
  • FBI已启动正式调查,部分泄露驾照属于FBI探员,泄露平台在调查报道发布后被关闭
  • 安全专家建议组织假设身份证据最终可能被泄露,需建立数据清单并监控异常批量访问行为

为什么值得看

这是近年来规模最大的身份数据泄露事件之一,直接影响身份验证行业的安全实践和信任体系。对于AI从业者而言,此类事件凸显了身份验证系统在隐私保护、数据治理和异常检测方面的关键挑战。

技术解析

  • 泄露数据规模:1.53亿份驾照、1000万份身份证件、300万份旅行证件和国际ID、58万份医疗卡,其中仅约110万份来自加拿大
  • 数据源平台IDScan.net位于路易斯安那州,提供ID欺诈预防、访问管理、年龄验证服务,以及ID激活门锁和移动ID扫描仪
  • 泄露渠道通过暗网平台Nexus和俄罗斯网络犯罪论坛推广,调查记者Brian Krebs验证了自己的驾照信息确实在平台上
  • 事件响应:平台在报道发布后迅速关闭,但FBI已介入调查,部分泄露数据涉及FBI探员身份

行业启示

  • 身份验证系统应假设身份证据最终可能被泄露,真实文档不能无限期作为唯一身份证明,需建立多层验证机制
  • 组织需对身份数据进行完整盘点,明确收集目的、流转路径和删除时机,并在与身份提供商的合同中明确日志、隔离、保留和事件通知要求
  • 应建立异常批量访问监控机制,重点关注服务账户、API和 administrative 账户的异常活动,防范数据外泄

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全