FBI Probes IDScan Breach Exposing 153 Million Driver's Licenses
A leak at a Louisiana-based verification service compromised millions of identity documents, including that of U.S. Secretary of Defense Pete Hegseth.
The FBI has launched an investigation into a massive cybersecurity breach involving IDScan, a Louisiana-based identity verification service. The leak has potentially exposed the personal data of over 153 million people across the United States and Canada.
The FBI's New Orleans field office opened the official probe after hackers advertised a vast database of identity documents on 'Exploit,' a Russian cybercrime forum. The data was offered via a service known as 'Nexus,' with the attackers claiming to possess scans of approximately 153 million driver's licenses. Among the compromised records is the driver's license of U.S. Secretary of Defense Pete Hegseth, elevating the breach from a commercial failure to a matter of national security.
Discovery and Scope
The breach first came to light through cybersecurity journalist Brian Krebs, who discovered the leak after hackers posted a scan of his own driver's license as a free sample on the Exploit forum. Subsequent analysis indicated that the breach is linked to IDScan (idscan.net), a service used by various businesses to authenticate customer identities.
Evidence suggests the compromised data includes individuals who used their identification at companies that contract IDScan for verification services. Specifically, customers of the car rental agency Hertz and Planet13 dispensaries are among those affected. Jillian Kossman, a marketing and operations leader at idscan.net, stated that while she could not share additional details, updates regarding the breach have been "welcome, and helpful" to the company's internal investigation.
Industry Implications
This breach highlights a critical vulnerability in the identity verification pipeline. Driver's license scans are prized by cybercriminals because they provide the foundational data required to commit sophisticated identity theft, such as opening fraudulent bank accounts or securing unauthorized lines of credit. When a centralized verification provider is compromised, the risk extends beyond a single company to every business that relies on that provider's infrastructure.
National Security Concerns
The inclusion of high-ranking government officials in the leak transforms the incident into a significant security risk. The exposure of Secretary Hegseth's personal identification documents provides malicious actors with verified data that could be used for targeted phishing, social engineering, or more complex espionage efforts against U.S. leadership.
Current Status of Investigation
While the scale of the driver's license leak is established, investigators are still working to determine the full extent of other compromised documents. The FBI continues to analyze the origin of the attack and the specific methods used to exfiltrate the data from IDScan's systems. It remains unclear whether the hackers have already sold the database or if the 'Nexus' service is still actively distributing the records.