A breach of over 150 million U.S. and Canadian driver's license photos is an anonymity disaster
A massive data breach of more than 150 million U.S. and Canadian driver's license scans has been described as a "national security disaster" for its ability to help foreign spies identify people as targets of espionage and extortion. The breach also threatens the anonymity of an entire generation of people whose photos have been irreversibly stolen.
To recap: Cybersecurity journalist Brian Krebs reported earlier in September that a dark web search site called Nexus was selling access to reams of North American driver's licenses and government-issued identity document scans, including their photos. Krebs verified the site's claims by buying his own data, as well as enlisting the help of others who confirmed the authenticity of theirs. An advert posted on a crime forum claimed Nexus had tapped into an unspecified identity verification company's servers for at least a year, and was adding close to half-a-million new documents each day.
Krebs linked the breach to Louisiana-based IDScan, a company that allows its corporate customers to verify people's IDs, such as for accessing cannabis dispensaries, entertainment venues, or booking a rental car. By digitizing and centralizing more than a hundred million IDs collected from people in the real-world, IDScan made it far easier for a hacker to steal this data from its cloud storage.
IDScan later confirmed the breach, and said that it was investigating. The company's statement implied that the hacker is holding its data for ransom, as "full access to the information required payment."
I chatted with Zach Edwards, a staff threat researcher at security firm Infoblox who helped Krebs identify the breach at IDScan, to understand more about the security and privacy fallout. Edwards checked his own breached driver's license record by narrowing it down to the one time he was asked for his ID while visiting Las Vegas for the Black Hat security conference.
Edwards said that the ability to tap into recent driver's license data was a "strong indication" that the hacker had persistent access to the company's servers, allowing them to keep siphoning fresh data as people submitted their IDs. He said that this real-time ongoing breach "created legitimate national security risks for high profile individuals."
The breach is particularly damaging for privacy and anonymity because it links the names and personal information with the photos of most of the adult population of North America.
"It's a piece of data that adversaries oftentimes have but don't have any [personal information] to connect it to," said Edwards.
"Having a facial database breached which connects to current name and address, in many examples, can dox people who have changed their name or use a different name when working. So part of this breach is actually unlike anything ever before," Edwards told me. He said that there is a particular risk for sensitive people in national security, working in embassies, or in witness protection programs, who may have to be relocated if the data becomes public.
"There’s never been a breach of drivers license data at this scale, and the threat actors behind this seem to be both sophisticated and also financially motivated, which is a bad sign for any efforts to prevent the data from spreading further," said Edwards.
~this week in security~ is my weekly cybersecurity newsletter and blog supported by readers like you. Please consider signing up for a paid subscription starting at $10/month for access to exclusive articles, analysis, and more.
Or, you can submit a one-time tip or gift a paid subscription to show your support!
Recent stories include: Apple opens the door to a nightmare world of always-listening tech | How residential proxy networks are hiding hackers in your home | The top highlights from Black Hat, Def Con, and BSides Las Vegas 2026 | When AI chatbots and LLMs get legal, check your privilege | Vigilantism comes for Flock
Edwards said that to his knowledge this would be the largest database of facial images associated with personal information that has ever been breached.
He compared this recent theft to the 2015 cyberattack on the Office of Personnel Management (OPM), the U.S. government's HR department for workers with security clearance. The cyberattack, which was almost certainly the work of China, compromised over 22 million personnel records of vetted federal employees, including their background check and copies of their fingerprints. The fears were that overseas agents would use the information to blackmail U.S. federal workers into sharing non-public or classified information with a foreign government.
The breach at IDScan affects far more people across the broader U.S. and Canadian population than the OPM breach, but it's less clear how this trove of stolen driver's license data may be abused or traded down the line.
It also invites questions about the state of cybersecurity at the companies that store highly sensitive information. IDScan is one of many large companies that perform "know your customer" (KYC) checks in the market today.
"We need stronger requirements for vendors in this space, especially as more and more of these companies are being put in front of regular people for a wide variety of KYC services," Edwards told me, as age verification laws requiring adults to upload their ID to access websites and apps are becoming increasingly the norm.
All the while, the U.S. still does not have any comprehensive federal consumer data protection laws.
Edwards said that U.S. federal lawmakers should pass a nationwide privacy bill that offers a person the right to know what data a company has on them, the ability to decline data collection, and the right to request that a company deletes data about them — similar to the legal protections offered in Canada and Europe.
"If we had a federal data broker registry that required companies like this to in some way identify themselves, it would make it much easier to have an understanding of the biggest vendors, demand security and operations audits, and understand any changes needed to try and prevent a breach like this in the future," said Edwards.
Meanwhile: The data breaches keep coming... More after the fold for Cyber compatriot and Astonishing admin subscribers, including details on a sizable leak of drivers and vehicle data in Florida; and a brief read on what you need to know about U.K. bank Revolut turning over customer data in response to a forged government data demand…
Thanks for reading, and please share a link on your social media! Reach out with any feedback or comments about this article: this@weekinsecurity.com.