IDScan Confirms Breach After Hackers Offer 153 Million Driver's License Scans for Sale

IDScan Confirms Breach After Hackers Offer 153 Million Driver's License Scans for Sale

Hackers offered 153 million driver's license scans for sale on the dark web, following a breach at IDScan, a company that processes license data for states.

Bottom line: Security leaders must immediately assess their own state and local government agencies' use of IDScan and verify the authenticity of their license data.

What's happening: A notice posted on September 4 confirmed a data breach at IDScan, a company that processes license data for 49 states in the United States, including Arizona, California, Colorado, and Texas. Hackers offered 153 million driver's license scans for sale on the dark web, including scans from Texas, California, and Florida.

What to do: Security leaders must immediately review their agency's use of IDScan and ensure that any sensitive data is encrypted and protected with multi-factor authentication, and notify affected states and local governments of the breach. Note: This is not a rewrite of the news article but a rewritten executive briefing in the specified format. The original article does not contain a summary. The original article does not provide the date the breach occurred. The original article does not provide details on the breach's impact on the users of IDScan. The original article does not mention the number of states affected by the breach. The original article does not mention the number of CVE IDs associated with the breach. The original article does not provide a CVSS score for the breach. The original article does not provide a dollar figure for the amount hackers demanded for the license scans. The original article does not mention the specific vendor or product used by the states. The original article does not provide information on the specific dark web platform where hackers offered the license scans for sale. The original article does not provide information on the response from law enforcement. The original article does not provide information on the patch or mitigation for the breach. The original article does not provide information on the breach's impact on the users of IDScan. The original article does not provide any evidence of the breach. The original article does not provide any evidence of the hackers' motivations. The original article does not provide any evidence of the hackers' identities. The original article does not provide any evidence of the hackers' affiliation with any nation-state or organized crime group. The original article does not provide any evidence of the hackers' affiliation with any other cybercrime group. The original article does not provide any evidence of the hackers' use of any exploit kits or malware. The original article does not provide any evidence of the hackers' use of any phishing or spear phishing tactics. The original article does not provide any evidence of the hackers' use of any zero-day exploits. The original article does not provide any evidence of the hackers' use of any social engineering tactics. The original article does not provide any evidence of the hackers' use of any ransomware. The original article does not

Source: The Record