Dark‑Web Vendors Offer Over 150 Million North American Driver’s License Scans
Cybercriminals have posted a massive trove of more than 153 million digital images of U.S. and Canadian driver’s licences for sale on underground forums, according to a report first published by SecurityWeek.
The collection is believed to originate from a breach of IDScan.net, a service that processes licence scans for identity verification purposes. While the exact method of exfiltration has not been confirmed, investigators suspect that the platform’s database was compromised, allowing attackers to harvest the high‑resolution images that businesses routinely use to confirm customer identities.
Each licence image contains a wealth of personally identifiable information, including full name, date of birth, address, licence number and a photo. When paired with other data sources, such details can enable a range of fraudulent activities, from opening bank accounts and credit cards to creating synthetic identities that evade traditional detection tools.
The scale of the leak places it among the larger data‑theft incidents targeting government‑issued IDs. While previous breaches have focused on credit‑card numbers or social‑security numbers, the sheer volume of licence scans introduces a new vector for identity fraud, prompting security experts to warn that criminals can now bypass many of the checks that rely on visual verification of a physical ID.
Law‑enforcement agencies and cybersecurity firms are monitoring the listings, but the decentralized nature of dark‑web marketplaces makes rapid takedown difficult. Officials have advised individuals to remain vigilant for unexpected credit inquiries or account openings, and to consider placing fraud alerts on their credit files if they suspect their licence data may have been exposed.
The incident underscores the growing need for stronger safeguards around biometric and document‑verification services. As more businesses adopt digital ID checks, experts say that robust encryption, strict access controls and regular security audits will be essential to prevent similar large‑scale exposures in the future.
Comments (0)
Be the first to comment.
Join the discussion