Reports that a dark web service is offering access to more than 153 million driver's licence scans have prompted an FBI inquiry and raised fresh concerns about how sensitive identity data is collected, stored and retained. The records have been linked to identity verification provider IDScan.net, which says it is investigating the claims.
Tim Rawlins, Senior Advisor and Director at NCC Group, comments
"Organizations should identify where driver’s license images are collected, retained, shared, or accepted. They should apply enhanced checks to high-risk onboarding and account recovery processes. Customer-facing employees should be briefed on likely impersonation techniques and escalation procedures without disclosing sensitive control details.
Organizations should also avoid asking potential victims to upload additional identity documents unless doing so is strictly necessary and the documents can be managed securely. A less obvious risk is exclusion. Stronger anti-fraud controls could wrongly prevent genuine customers or victims from accessing services unless organizations provide effective review, appeal, and recovery processes.
Individuals who may be affected should use official channels to determine their status, monitor their accounts and credit reports, and remain alert to suspicious communications. They should check bank, credit, and online accounts for unexpected activity and consider placing a fraud alert or credit freeze where available. People at heightened personal risk may require tailored protective security support in addition to credit monitoring. Nobody should use links or telephone numbers contained in unsolicited breach notifications.
A narrow focus on the provider identified in the reporting could overlook weaknesses affecting customers, resellers, devices, application programming interfaces, or downstream processors. The incident highlights the concentration risk created when many businesses send high-value identity evidence to a small number of verification providers. It also exposes a structural conflict: organizations collect more personal data to prevent fraud, but the resulting data stores can enable further fraud if they are compromised.
The policy question is how organizations can provide strong identity assurance while retaining fewer reusable documents in centralized systems. Retention policies must also be enforced in practice, rather than existing only as written requirements.
The first lesson is that organizations should design identity systems on the assumption that identity evidence may eventually be compromised. A genuine-looking document cannot remain sufficient proof of identity indefinitely. Organizations should inventory identity data and establish who collects it, why it is needed, where it flows, and when it is deleted.
Contracts with identity providers should establish requirements for logging, data segregation, retention, incident notification, access to evidence, and independent assurance. Organizations should also monitor for abnormal bulk access and potential data exfiltration, including unusual activity involving service accounts, application programming interfaces, and administrative accounts."
Tim Rawlins biography
Tim is a Director and Senior Adviser at NCC Group with a long career in senior security, risk and resilience roles across the public and private sectors. His experience includes serving as an Operations Director in industry and as Chief Security Officer (CSO) for a global bank as well as twice holding the role of NCC Group’s own CSO.
Tim specialises in executive level briefings, crisis management and resilience. He leads NCC Group’s crisis training for senior leaders, regularly delivering Gold Team exercises and supporting organisations through real incidents. Working closely with our Digital Forensics and Incident Response (DFIR) team, he helps clients navigate major cyber events, ensuring they can stabilise, respond effectively and recover with confidence.
Drawing on deep strategic, stakeholder and communication expertise, Tim advises board members, senior executives and leadership teams across NCC Group’s global client base. He is also an experienced public speaker and frequently contributes to NCC Group’s public affairs and media activity, briefing analysts, journalists and senior officials on emerging threats, resilience and cyber strategy.
Contact
NCC Group Press Office
All media enquires relating to NCC Group plc.