<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Data Breach - PhishFort | AI-Powered Brand Protection</title><link>https://phishfort.com/resources/blog/tag/data-breach/</link><description>PhishFort delivers agentic brand protection: detecting and eliminating phishing sites, fake apps, and impersonations across every digital channel.</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Tue, 06 Oct 2026 07:35:51 +0000</lastBuildDate><atom:link href="https://phishfort.com/resources/blog/tag/data-breach/index.xml" rel="self" type="application/rss+xml"/><item><title>DriveWealth Breach: What Revolut Users Need to Know</title><link>https://phishfort.com/revolut-drivewealth-third-party-breach/</link><pubDate>Tue, 06 Oct 2026 00:00:00 +0000</pubDate><dc:creator>PhishFort Team</dc:creator><guid>https://phishfort.com/revolut-drivewealth-third-party-breach/</guid><description><![CDATA[<p>In September 2026, Revolut notified customers that unauthorized parties had accessed historical personal data on systems belonging to DriveWealth, the US broker that runs Revolut&rsquo;s US stock trading. Revolut&rsquo;s own systems were not the source. The incident mainly affects customers who traded US stocks through Revolut before December 2023, and it shows that a fintech&rsquo;s exposure includes every partner that holds its customers&rsquo; data.</p>
<p><strong>Summary</strong></p>
<ul>
<li>DriveWealth, a US brokerage infrastructure provider and Revolut&rsquo;s stock trading partner, reported unauthorized access to historical personal data.</li>
<li>Revolut emailed potentially affected customers and confirmed that a separate email from DriveWealth LLC was genuine.</li>
<li>The affected data relates to customers who traded US stocks through Revolut before December 2023, which means some records were kept since 2022.</li>
<li>The case raises questions about cross-border jurisdiction and about data minimization under the EU General Data Protection Regulation (GDPR).</li>
<li>Breach notification emails are a common template for follow-up phishing, so customers should verify any security updates through the official app.</li>
</ul>
<h2 id="what-happened-in-the-drivewealth-security-incident">What happened in the DriveWealth security incident?</h2>
<p>DriveWealth confirmed unauthorized access to historical personal data stored on its systems, and Revolut notified customers who may be affected. The incident came weeks after Revolut handled a separate attack in which a fake government request led to the release of customer passports.</p>]]></description><content:encoded><![CDATA[<p>In September 2026, Revolut notified customers that unauthorized parties had accessed historical personal data on systems belonging to DriveWealth, the US broker that runs Revolut&rsquo;s US stock trading. Revolut&rsquo;s own systems were not the source. The incident mainly affects customers who traded US stocks through Revolut before December 2023, and it shows that a fintech&rsquo;s exposure includes every partner that holds its customers&rsquo; data.</p>
<p><strong>Summary</strong></p>
<ul>
<li>DriveWealth, a US brokerage infrastructure provider and Revolut&rsquo;s stock trading partner, reported unauthorized access to historical personal data.</li>
<li>Revolut emailed potentially affected customers and confirmed that a separate email from DriveWealth LLC was genuine.</li>
<li>The affected data relates to customers who traded US stocks through Revolut before December 2023, which means some records were kept since 2022.</li>
<li>The case raises questions about cross-border jurisdiction and about data minimization under the EU General Data Protection Regulation (GDPR).</li>
<li>Breach notification emails are a common template for follow-up phishing, so customers should verify any security updates through the official app.</li>
</ul>
<h2 id="what-happened-in-the-drivewealth-security-incident">What happened in the DriveWealth security incident?</h2>
<p>DriveWealth confirmed unauthorized access to historical personal data stored on its systems, and Revolut notified customers who may be affected. The incident came weeks after Revolut handled a separate attack in which a fake government request led to the release of customer passports.</p>
<p>PhishFort reviewed a notification Revolut sent to a potentially affected user. Titled &ldquo;DriveWealth security incident update&rdquo;, it states that unauthorized access to historical personal data occurred on DriveWealth&rsquo;s systems and that Revolut is working directly with DriveWealth to determine the scope.</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791212015942-pasted-image_hu_de2c8df02076880a.webp 480w, /img/1791212015942-pasted-image_hu_14cd8288c5aa051c.webp 768w, /img/1791212015942-pasted-image_hu_c5ef6bd749c04629.webp 1200w, /img/1791212015942-pasted-image_hu_8ceca1d5d8aec617.webp 1600w, /img/1791212015942-pasted-image_hu_d5717046944656dc.webp 1690w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791212015942-pasted-image.png"
          srcset="/img/1791212015942-pasted-image_hu_692ee5ad9d7e2c1c.png 480w, /img/1791212015942-pasted-image_hu_edad47e89fba125c.png 768w, /img/1791212015942-pasted-image_hu_cd9b31899265bcc5.png 1200w, /img/1791212015942-pasted-image_hu_57b2a9298aa06832.png 1600w, /img/1791212015942-pasted-image.png 1690w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1690" height="939"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p>The notice tells the user they were identified as being potentially affected and adds: &ldquo;You recently received an email from DriveWealth LLC&hellip; That email is genuine and you should read it carefully alongside this one.&rdquo;</p>
<p>This is the DriveWealth email the notice refers to:</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791212019267-pasted-image_hu_dfe39d90cc7b02e3.webp 480w, /img/1791212019267-pasted-image_hu_bb7efa8d45687310.webp 768w, /img/1791212019267-pasted-image_hu_6608c2c24a8ae3db.webp 1200w, /img/1791212019267-pasted-image_hu_87c4e05180012652.webp 1472w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791212019267-pasted-image.png"
          srcset="/img/1791212019267-pasted-image_hu_56bfe3f81722fde9.png 480w, /img/1791212019267-pasted-image_hu_28287edf11fa728.png 768w, /img/1791212019267-pasted-image_hu_112151973fa54a38.png 1200w, /img/1791212019267-pasted-image.png 1472w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="1472" height="1531"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<h2 id="who-is-affected-by-the-drivewealth-breach">Who is affected by the DriveWealth breach?</h2>
<p>The affected group is Revolut customers who traded US stocks before December 2023, according to the information shared with customers. Revolut has not published the total number of affected users. Customers who received both the Revolut and the DriveWealth emails should treat themselves as affected.</p>
<h2 id="how-did-revolut-and-drivewealth-communicate-the-incident">How did Revolut and DriveWealth communicate the incident?</h2>
<p>Both companies contacted affected customers directly by email. Revolut also placed a visible alert on its website and published a help page about the incident.</p>
<p>DriveWealth published a standalone cyber response page on a subdomain (<a href="http://legal.drivewealth.com" target="_blank" rel="noopener noreferrer nofollow">legal.drivewealth.com</a>). At the time of PhishFort&rsquo;s review, the page was not linked from DriveWealth&rsquo;s main navigation, which makes it harder for customers to confirm the notice is real.</p>
<h2 id="why-does-a-partners-breach-expose-a-fintechs-customers">Why does a partner&rsquo;s breach expose a fintech&rsquo;s customers?</h2>
<p>A fintech&rsquo;s customers are exposed wherever their data is stored, including at brokers, payment processors and identity verification vendors. A US broker that executes trades for a European digital bank holds names, addresses and account details of the bank&rsquo;s customers, so a breach at the broker reaches them directly.</p>
<p>This is a common pattern. The Verizon 2026 Data Breach Investigations Report (DBIR) found third-party involvement in 48% of breaches.</p>
<h2 id="what-are-the-jurisdiction-and-gdpr-questions">What are the jurisdiction and GDPR questions?</h2>
<p>The incident raises an open question about which rules apply: Lithuanian and EU law, where Revolut holds its European banking license, or US frameworks that govern DriveWealth. The answer affects notification deadlines, regulator involvement and customer remedies.</p>
<p>Retention is the second question. If records from as early as 2022 were still held, the case tests the GDPR principle of data minimization, which limits how long personal data can be kept. Financial institutions often cite legal and regulatory duties to retain records, but those duties do not cover every field indefinitely.</p>
<h2 id="how-do-attackers-exploit-breach-notification-emails">How do attackers exploit breach notification emails?</h2>
<p>Attackers copy real breach notices because customers expect them and act on them. After a public incident, fake &ldquo;security update&rdquo; emails, SMS messages and support accounts often reuse the real subject line, logo and wording, then point to a lookalike domain that asks for login details or identity documents.</p>
<p>Revolut&rsquo;s notice confirmed that the DriveWealth email was genuine, which helps. A copy of either message can still target a customer. Warning signs include:</p>
<ul>
<li>A link that asks you to log in, &ldquo;verify&rdquo; your identity or reset your account from the email itself.</li>
<li>A sender domain that is similar to, but not exactly, <a href="http://revolut.com" target="_blank" rel="noopener noreferrer nofollow">revolut.com</a> or <a href="http://drivewealth.com" target="_blank" rel="noopener noreferrer nofollow">drivewealth.com</a>.</li>
<li>Requests for passwords, one-time codes, card details or ID photos.</li>
<li>Unsolicited calls or chat messages that reference the incident.</li>
</ul>
<p>Customers should open the Revolut app directly to check any security notice.</p>
<h2 id="what-should-fintechs-do-about-third-party-risk">What should fintechs do about third-party risk?</h2>
<p>Fintechs can reduce partner risk by limiting what partners hold and planning the customer response before an incident. Practical steps:</p>
<ol>
<li>Map which partners store customer data, which fields and for how long.</li>
<li>Set contractual retention limits and deletion obligations that match GDPR data minimization.</li>
<li>Agree breach notification timelines and a joint communication plan with each partner.</li>
<li>Publish incident pages on the main domain and link them from the homepage, so customers can verify notices.</li>
<li>Monitor for lookalike domains and fake support accounts that use the incident as a lure.</li>
</ol>
<h2 id="how-phishfort-helps-after-a-third-party-incident">How PhishFort helps after a third-party incident</h2>
<p>When a partner is breached, attackers impersonate both brands. <a href="https://phishfort.com/product/brand-protection/" target="_blank" rel="noopener"><u>PhishFort Brand Protection</u></a> detects lookalike domains, fake support accounts and fake apps that use the incident as a lure, and takes them down with registrars, hosts and platforms.</p>
<h2 id="frequently-asked-questions">Frequently asked questions</h2>
<h3 id="was-revolut-hacked-in-the-drivewealth-incident">Was Revolut hacked in the DriveWealth incident?</h3>
<p>No. The unauthorized access happened on the systems of DriveWealth, Revolut&rsquo;s US stock trading partner. Revolut notified potentially affected customers and said it is working with DriveWealth to determine the scope.</p>
<h3 id="who-is-affected-by-the-drivewealth-breach-1">Who is affected by the DriveWealth breach?</h3>
<p>According to information shared with customers, the incident affects Revolut users who traded US stocks before December 2023. Revolut has not published the total number of affected users.</p>
<h3 id="is-the-drivewealth-breach-email-real">Is the DriveWealth breach email real?</h3>
<p>Revolut told customers that the email from DriveWealth LLC is genuine. Copies of breach notices are a common phishing lure, so check any security notice inside the Revolut app rather than through email links.</p>
<h3 id="what-is-third-party-risk-in-fintech">What is third-party risk in fintech?</h3>
<p>Third-party risk is the exposure a fintech takes on when partners such as brokers, processors or verification vendors store or process its customers&rsquo; data. A breach at the partner affects the fintech&rsquo;s customers even if the fintech&rsquo;s own systems are secure.</p>
<h2 id="sources">Sources</h2>
<ul>
<li><a href="https://legal.drivewealth.com/cyber-response" target="_blank" rel="noopener noreferrer nofollow">DriveWealth cyber response page</a></li>
<li><a href="https://help.revolut.com/en-US/help/security-logging-in/drivewealth-security-incident/question-drivewealth-data-incident/" target="_blank" rel="noopener noreferrer nofollow">Revolut Help Center: DriveWealth data incident</a></li>
<li>Revolut customer notification &ldquo;DriveWealth security incident update&rdquo;, reviewed by PhishFort, September 2026.</li>
<li>Verizon 2026 Data Breach Investigations Report (DBIR).</li>
</ul>
]]></content:encoded><category>Financial Services</category><category>phishing</category><category>security</category><category>DriveWealth</category><category>Revolut</category><category>third-party risk</category><category>supply chain security</category><category>data breach</category><category>GDPR</category><category>fintech</category><category>breach notification phishing</category></item><item><title>153M Driver's Licenses for Sale: The IDScan.net Nexus Leak</title><link>https://phishfort.com/idscan-nexus-153-million-drivers-licenses-breach/</link><pubDate>Sun, 06 Sep 2026 14:00:00 +0000</pubDate><dc:creator>PhishFort Team</dc:creator><guid>https://phishfort.com/idscan-nexus-153-million-drivers-licenses-breach/</guid><description><![CDATA[<p>In September 2026, a dark web identity theft service called Nexus offered searchable access to more than 153 million US and Canadian driver&rsquo;s license scans, plus millions of other ID documents. KrebsOnSecurity traced the likely source to IDScan.net, an identity verification provider used by rental counters and dispensaries, and the FBI&rsquo;s New Orleans field office opened an inquiry. Because ID scans cannot be changed like passwords, the data can fuel account opening fraud, account recovery attacks and targeted phishing for years.</p>]]></description><content:encoded><![CDATA[<p>In September 2026, a dark web identity theft service called Nexus offered searchable access to more than 153 million US and Canadian driver&rsquo;s license scans, plus millions of other ID documents. KrebsOnSecurity traced the likely source to IDScan.net, an identity verification provider used by rental counters and dispensaries, and the FBI&rsquo;s New Orleans field office opened an inquiry. Because ID scans cannot be changed like passwords, the data can fuel account opening fraud, account recovery attacks and targeted phishing for years.</p>
<p><strong>Summary</strong></p>
<ul>
<li>Nexus, advertised on the Russian-language cybercrime forum Exploit, claimed documents for more than 170 million people in North America.</li>
<li>The listing included more than 153 million driver&rsquo;s licenses, 10 million ID cards, 3 million travel documents and about 579,000 medical cards.</li>
<li>Some records included front and back images plus infrared (IR) and ultraviolet (UV) scans, the imagery ID verification systems use to validate physical documents.</li>
<li>Timestamps on stolen images matched ID scans at Hertz rental counters and a Planet13 dispensary, pointing to <a href="http://IDScan.net" target="_blank" rel="noopener noreferrer nofollow">IDScan.net</a> as the likely source.</li>
<li>Nexus went offline after the report, but the data is likely to resurface. Organizations that rely on ID documents should expect more convincing fraud and phishing.</li>
</ul>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1791211107306-pasted-image_hu_65034a716cd3e83f.webp 480w, /img/1791211107306-pasted-image_hu_9e065d773a2dc90e.webp 768w, /img/1791211107306-pasted-image_hu_ada14aab462c0bca.webp 1200w, /img/1791211107306-pasted-image_hu_437b21abc90c0852.webp 1600w, /img/1791211107306-pasted-image_hu_7618cd08d116eada.webp 2000w, /img/1791211107306-pasted-image_hu_faef77045f781e6e.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791211107306-pasted-image.png"
          srcset="/img/1791211107306-pasted-image_hu_cd896abeae1b27cf.png 480w, /img/1791211107306-pasted-image_hu_efa0f058a8d815b.png 768w, /img/1791211107306-pasted-image_hu_8132c9b841717d8c.png 1200w, /img/1791211107306-pasted-image_hu_e55ec87e2c9a6b19.png 1600w, /img/1791211107306-pasted-image_hu_b08856baacd6bac2.png 2000w, /img/1791211107306-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt=""
          
          width="2048" height="1117"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<h2 id="what-happened-in-the-idscannet-and-nexus-leak">What happened in the IDScan.net and Nexus leak?</h2>
<p>Nexus, a new identity theft service on the Exploit forum, sold searchable access to identity documents and claimed it had been continuously exfiltrating new data for more than a year. Security journalist Brian Krebs reported that the number of listed licenses grew by nearly 400,000 in 24 hours, which suggests an ongoing compromise rather than a one-time leak.</p>
<p>Krebs began investigating after a source told him his own Virginia driver&rsquo;s license was being offered as a free sample. By matching image timestamps with the dates and times people had their IDs scanned at Hertz counters and a Planet13 dispensary, he traced the apparent source to IDScan.net, a Louisiana-based identity verification company. TechCrunch also reported that the evidence pointed to a breach of a major ID verification service.</p>
<p>The listing claimed:</p>
<ul>
<li>
<p>More than 153 million driver&rsquo;s licenses.</p>
</li>
<li>
<p>More than 10 million ID cards.</p>
</li>
<li>
<p>More than 3 million travel or international identity documents.</p>
</li>
<li>
<p>About 579,000 medical cards.</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
      
      

      <picture>
        <source srcset="/img/1791211173192-pasted-image_hu_6f305e5d7be5d632.webp 480w, /img/1791211173192-pasted-image_hu_4b8a2c2e6cf1f78c.webp 768w, /img/1791211173192-pasted-image_hu_808d206fcbe6483c.webp 1200w, /img/1791211173192-pasted-image_hu_d2bb9de0394c889e.webp 1600w, /img/1791211173192-pasted-image_hu_42ce88f62bf01b3.webp 2000w, /img/1791211173192-pasted-image_hu_a326a2fabf74e31b.webp 2048w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791211173192-pasted-image.png"
          srcset="/img/1791211173192-pasted-image_hu_9aacee02c88e658.png 480w, /img/1791211173192-pasted-image_hu_4bcb93bc9a7bda5e.png 768w, /img/1791211173192-pasted-image_hu_784f2f9a7c98a55a.png 1200w, /img/1791211173192-pasted-image_hu_321d5a1be2cacf50.png 1600w, /img/1791211173192-pasted-image_hu_4684d61cce144ed.png 2000w, /img/1791211173192-pasted-image.png 2048w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt="Leaked data breakdown"
          
          width="2048" height="1827"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
</li>
</ul>
<p style="text-align: center;"><em>Leaked data breakdown</em></p>
<p>Shortly after the KrebsOnSecurity report, Nexus replaced its login page with the message &ldquo;This service is no longer available.&rdquo;</p>
<h2 id="who-is-investigating-and-what-are-the-lawsuits-about">Who is investigating, and what are the lawsuits about?</h2>
<p>The FBI&rsquo;s New Orleans field office opened an inquiry into the incident. Krebs reported that records of high-ranking US government officials, reportedly including Defense Secretary Pete Hegseth, appeared in the dataset.</p>
<p>Consumers in California, Florida, Georgia and Louisiana filed lawsuits alleging that <a href="http://IDScan.net" target="_blank" rel="noopener noreferrer nofollow">IDScan.net</a> failed to protect sensitive data and likely violated Federal Trade Commission (FTC) data security guidelines. The plaintiffs seek damages and court-ordered security improvements.</p>
<h2 id="why-are-identity-verification-vendors-such-attractive-targets">Why are identity verification vendors such attractive targets?</h2>
<p>An identity verification vendor processes ID checks for thousands of businesses, so one compromise exposes all their customers. Attackers do not need to breach every rental counter, hotel or dispensary. They only need the shared service behind them.</p>
<p>
















  
  
  
    
    
    

    
    

    
      
      
      
      
      
        
          
          
          
          
        
      
        
          
          
          
          
        
      
        
      
        
      
        
      
      
      

      <picture>
        <source srcset="/img/1791211146434-pasted-image_hu_7c2a32d51f015a39.webp 480w, /img/1791211146434-pasted-image_hu_16c7fb0cab8763b9.webp 768w, /img/1791211146434-pasted-image_hu_44181ac47020b03a.webp 1060w"
                sizes="(max-width: 768px) 100vw, 700px" type="image/webp">
        <img src="/img/1791211146434-pasted-image.png"
          srcset="/img/1791211146434-pasted-image_hu_47391e6886fd848b.png 480w, /img/1791211146434-pasted-image_hu_46f0c46504625ba4.png 768w, /img/1791211146434-pasted-image.png 1060w"
          sizes="(max-width: 768px) 100vw, 700px"
          alt="Partners of ID Scan"
          
          width="1060" height="418"
          
          
          loading="lazy"
          >
      </picture>
    
  



</p>
<p style="text-align: center;"><em>Partners of ID Scan</em></p>
<p>ID scanning is now routine in car rentals, hotels, dispensaries, financial services, age-restricted platforms, travel and marketplace onboarding. Each use reduces fraud at the counter but adds to a central store of sensitive data. The more trust and scale a provider accumulates, the more valuable a compromise becomes.</p>
<h2 id="why-is-a-leaked-drivers-license-worse-than-a-leaked-password">Why is a leaked driver&rsquo;s license worse than a leaked password?</h2>
<p>A password can be reset, but a driver&rsquo;s license bundles a legal name, date of birth, address, photo, document number and issuing authority that a person cannot easily change. Many organizations still treat it as strong proof of identity.</p>
<p>Replacing the license changes the document number, but the exposed image and personal details can still be abused. That is why the impact of an ID document leak lasts much longer than a credential leak.</p>
<h2 id="what-can-attackers-do-with-stolen-id-scans">What can attackers do with stolen ID scans?</h2>
<p>Stolen ID scans give attackers verified personal details they can use to pass weak checks and make impersonation believable:</p>
<ol>
<li><strong>Account opening fraud:</strong> submitting stolen document images to open accounts or apply for credit.</li>
<li><strong>Account recovery attacks:</strong> sending a matching ID image to a support team to take over a victim&rsquo;s account.</li>
<li><strong>Targeted phishing:</strong> using real names, addresses and license details to make messages look legitimate, especially when combined with other breach data.</li>
<li><strong>Executive and public figure targeting:</strong> using exposed IDs of executives and officials for impersonation, doxxing or physical security threats.</li>
<li><strong>Bypassing weak KYC (Know Your Customer) checks:</strong> reusing images where verification only checks that a document looks valid, without liveness, device or behavior signals.</li>
</ol>
<h2 id="what-should-organizations-that-collect-id-documents-do-now">What should organizations that collect ID documents do now?</h2>
<p>Organizations that collect or rely on ID documents should reduce what they store and assume the leaked data will be used against their customers. In order of priority:</p>
<ol>
<li><strong>Review what you collect.</strong> If the business only needs a verification result, do not keep the document image.</li>
<li><strong>Minimize retention.</strong> Set clear retention windows and delete raw images once legal, compliance or fraud review needs end.</li>
<li><strong>Reassess vendor exposure.</strong> Ask verification providers what they store, for how long, whether they keep raw images, whether they support deletion or tokenized verification, and how they log and monitor access.</li>
<li><strong>Strengthen account recovery.</strong> Do not accept a government ID alone. Combine known-device checks, recent activity, step-up authentication and manual review for high-risk cases.</li>
<li><strong>Monitor for impersonation.</strong> Watch for lookalike domains, fake support portals, executive impersonation, fraudulent onboarding attempts, social media impersonation and credential harvesting pages that use breached personal data.</li>
<li><strong>Prepare customer guidance.</strong> Explain what happened, what data may be at risk and what people can realistically do.</li>
</ol>
<h2 id="what-should-individuals-do-if-their-id-may-be-exposed">What should individuals do if their ID may be exposed?</h2>
<p>People who think their license may be in the dataset should focus on blocking new-account fraud and spotting targeted phishing:</p>
<ul>
<li>Place a credit freeze with the major credit bureaus.</li>
<li>Monitor bank accounts and credit reports.</li>
<li>Be skeptical of messages that contain accurate personal details.</li>
<li>Watch for account recovery notices you did not request.</li>
<li>Use unique passwords and multi-factor authentication (MFA) on important accounts.</li>
<li>Report suspected identity theft at <a href="http://IdentityTheft.gov" target="_blank" rel="noopener noreferrer nofollow"><u>IdentityTheft.gov</u></a> in the US or through the <a href="https://www.priv.gc.ca/en/privacy-topics/identities/identity-theft/guide_idt/" target="_blank" rel="noopener noreferrer nofollow"><u>Office of the Privacy Commissioner of Canada</u></a>.</li>
</ul>
<h2 id="how-phishfort-helps-after-an-identity-data-leak">How PhishFort helps after an identity data leak</h2>
<p>Leaked identity data makes brand and executive impersonation more convincing. <a href="https://phishfort.com/product/executive-protection/" target="_blank" rel="noopener noreferrer nofollow"><u>PhishFort Executive Protection</u></a> detects and removes fake profiles and doxxing that target executives, and PhishFort Dark Web Monitoring watches underground sources for credential and identity data tied to your brand.</p>
<h2 id="frequently-asked-questions">Frequently asked questions</h2>
<h3 id="was-idscannet-hacked">Was IDScan.net hacked?</h3>
<p>KrebsOnSecurity traced the Nexus data to IDScan.net by matching image timestamps with real ID scans at Hertz and a Planet13 dispensary. The FBI&rsquo;s New Orleans field office opened an inquiry, and consumer lawsuits allege the company failed to protect the data.</p>
<h3 id="how-many-drivers-licenses-were-exposed-in-the-nexus-leak">How many driver&rsquo;s licenses were exposed in the Nexus leak?</h3>
<p>Nexus claimed more than 153 million US and Canadian driver&rsquo;s licenses, plus more than 10 million ID cards, 3 million travel documents and about 579,000 medical cards, covering more than 170 million people.</p>
<h3 id="what-can-criminals-do-with-a-scanned-drivers-license">What can criminals do with a scanned driver&rsquo;s license?</h3>
<p>Criminals can use stolen license scans to open accounts, pass weak KYC checks, take over accounts through support teams and make phishing messages more believable. Executives and officials face added impersonation and physical security risks.</p>
<h3 id="does-getting-a-new-drivers-license-protect-me">Does getting a new driver&rsquo;s license protect me?</h3>
<p>Only partly. A new license changes the document number, but the leaked image, name, address and date of birth can still be used for fraud, so credit freezes and monitoring remain important.</p>
<h2 id="sources">Sources</h2>
<ul>
<li><a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/" target="_blank" rel="noopener noreferrer nofollow">KrebsOnSecurity: FBI probes service selling 153M driver&rsquo;s licenses</a></li>
<li><a href="https://techcrunch.com/2026/09/02/it-sure-looks-like-hackers-breached-a-major-id-card-verification-service/" target="_blank" rel="noopener noreferrer nofollow">TechCrunch: It sure looks like hackers breached a major ID card verification service (September 2, 2026)</a></li>
<li><a href="http://USA.gov" target="_blank" rel="noopener noreferrer nofollow">USA.gov: Identity theft</a></li>
<li><a href="https://www.priv.gc.ca/en/privacy-topics/identities/identity-theft/guide_idt/" target="_blank" rel="noopener noreferrer nofollow">Office of the Privacy Commissioner of Canada: Identity theft guide</a></li>
</ul>
]]></content:encoded><category>News</category><category>phishing</category><category>security</category><category>IDScan.net</category><category>Nexus</category><category>driver's licenses</category><category>identity verification</category><category>data breach</category><category>dark web</category><category>identity theft</category><category>KYC</category><category>executive impersonation</category></item></channel></rss>