Russian hackers managed to get their hands on a lot of American and Canadian driver’s licenses. That could prove very dangerous for some.
Someone on a Russian cybercrime forum recently posted a massive database packed with stolen identification records.
More than 153 million driver’s licenses belonging to American and Canadian citizens were listed for access.
One of them was the driver’s license of the Defense Secretary in the United States.
Hegseth as proof
According to American journalist and cybersecurity expert Brian Krebs, Nexus, a dark web identity theft service, was created this week and offered stolen driver’s licenses, passports, medical files, and even cannabis dispensary cards to anyone willing to buy.
To prove the breach was authentic, the a source showed Krebs a copy of US Secretary of Defense Pete Hegseth’s driver’s license.
Federal law enforcement authorities then quickly intervened. The page went offline shortly after the FBI opened an investigation.
Krebs found his own documents
Hackers claimed they managed to steal it because they were able to hack into a top IT identification service used by the richest companies in the world.
The investigation by Brian Krebs took an interesting turn when he searched his own name and found that a couple of the leaked documents belonged to him and his mother.
Those documents included personal information about them from the car rental company Hertz. The documents were uploaded the same day they rented a vehicle from the company.
Widespread identity risk
Security researcher Zach Edwards also spotted his own driver’s license in the leak after visiting Planet 13, a cannabis dispensary. That vendor relies on IDScan, a software provider based in New Orleans.
IDScan works with major brands like Hertz, Target, and FedEx. IDScan confirmed that an internal investigation is currently underway.
Larry Baldwin, a specialist in cybersecurity, says this leak presents multiple privacy threats to citizens who do not want to be found, such as people who are in a witness protection program.
“Just when it seems like we’re making some headway in improving authentication controls through driver’s license verification systems, this happens and the very thing those improvements are dependent on is compromised,” Baldwin said.