Skip to main content
Promotional banner for the pentest readiness checklist
153M IDs Exposed in Year-Long ExfiltrationPrivacy and Security
4 min readFor GRC Leaders

153M IDs Exposed in Year-Long Exfiltration

More than 153 million driver's licenses and identification documents surfaced on a Russian cybercrime forum last month, complete with front, back, infrared, and ultraviolet scans. Journalist Brian Krebs first reported the breach, noting that the service, dubbed "Nexus," includes U.S. and Canadian licenses, over 10 million identification cards, three million travel documents, and at least 579,000 medical cards. The FBI is investigating.

This breach is particularly damaging because the data includes enough detail to pass most identity verification checks. The database has been growing for over a year, adding roughly 400,000 records during that time.

What the Data Shows

The scale is alarming. A blank search in the compromised database returns about 11.5 million pages of results at 15 records per page. Most entries are Americans, with Canadian records making up about 1.1 million.

The real issue isn't just the volume. It's the retention model that created this target. IDScan, the identity verification vendor at the center of this breach, defaults to "Collect all" and retains all records, as per its documentation. The Basic plan requires collecting everything with no deletion option. This isn't about attackers breaching sophisticated defenses; it's about a business model treating identity verification as data accumulation.

This breach follows a pattern. Texas Parks & Wildlife lost 3 million records. AssuranceAmerica exposed nearly 7 million. An analysis documented 88 identity verification breaches since 2011, with 42% occurring in the last two and a half years. As more businesses outsource identity checks under pressure from age verification laws and know-your-customer mandates, data concentrates, increasing the impact of each breach.

Key Findings

Persistent access over perimeter security. If an attacker gains access as an authorized user, database encryption won't protect you. The year-long exfiltration suggests compromised credentials or outdated multi-factor authentication, not a quick attack.

Document scans enable long-term fraud. Unlike compromised passwords, which you can reset quickly, a compromised driver's license requires an in-person DMV visit, proof of fraud, and significant paperwork. The scans in this breach include enough biometric and document security features to pass most current checks.

Data retention creates liability. The verification transaction may take seconds, but the data persists indefinitely. When a vendor retains full document scans for marketing and analysis instead of just the verification result, they're creating a permanent target, with consequences.

No infrastructure for license compromise. You can freeze your credit in minutes, but not your driver's license number across states. There's no standardized alert for a compromised license. The burden falls on victims to place manual flags, state by state.

Concentration risk is accelerating. Companies like Hertz, Target, Caesars, FedEx, and over a thousand marijuana dispensaries outsource identity checks to the same vendors. One breach exposes every customer of every client. This consolidation is driven by compliance requirements, but security hasn't kept pace.

What This Means for Your Team

If your organization collects government-issued IDs for verification, you're handling regulated data, whether you've classified it that way or not. The absence of a comprehensive federal framework doesn't eliminate risk; it just means you're in a gap that will eventually close, likely after the next major incident.

Your vendor contracts probably lack data minimization obligations. Most agreements focus on uptime and accuracy, not retention limits or deletion schedules. If you can't answer how long your vendor keeps scans post-verification, you lack adequate visibility into third-party risk.

Your Incident Response Structure likely doesn't account for identity document compromise. You have playbooks for payment card breaches and personal data exposure, but driver's license compromise requires different notification procedures and remediation steps.

Action Items by Priority

Immediate: Audit your identity verification vendors. Request documentation of their data retention policies, deletion schedules, and whether they monetize verification data. If they default to "Collect all" with no deletion option, that's a red flag needing executive attention.

Within 30 days: Implement data minimization requirements. Revise vendor contracts to require deletion of full document scans after verification. If retention is necessary, define specific periods and deletion triggers. Verification results should suffice for most cases; if keeping the document, document the justification.

Within 60 days: Strengthen access controls for identity data. Require biometric authentication on dedicated hardware for systems accessing large volumes of identity documents. Eliminate or continuously monitor service accounts with standing access to these databases.

Within 90 days: Develop identity compromise response procedures. Create a playbook for notification requirements, coordination with state DMV systems, and support for affected individuals. This isn't a standard breach notification scenario.

Ongoing: Treat identity documents like payment card data. Apply security controls equivalent to PCI DSS requirements. This means encryption at rest and in transit, access logging, regular penetration testing, and vendor security assessments. The lack of explicit regulation doesn't mean the risk is lower.

The breach highlights a fundamental tension: compliance mandates drive more identity verification, leading to data concentration and creating bigger targets. Until regulatory frameworks catch up, it's up to individual organizations to implement controls matching the data's sensitivity, not just the minimum required by law.

PCI DSS requirements

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like