A stolen driver's license can unlock your business accounts. 153 million were just put up for sale.

4 minute read

Aura, the identity-monitoring service our cybersecurity essentials checklist recommends, sent its members a breach alert this week. The line that matters, in Aura's words: "Unlike past driver's license breaches, this site offered actual photos of the cards." That one sentence is why this breach is a bigger problem for a business owner than for a consumer, and it is the reason for this article.

What happened

In the last week of August a criminal marketplace called Nexus appeared on the dark web. It worked like a search engine. Type a name, get a driver's license: the scanned image of the card, not just the number. Security journalist Brian Krebs reported it on September 1. By his count Nexus was offering more than 153 million U.S. and Canadian driver's licenses, more than 10 million identification cards and more than 3 million travel documents, and it was adding hundreds of thousands of records a day. The FBI's New Orleans field office opened an investigation the same day, and the site went offline the next evening.

The data traced back to IDScan.net, a Louisiana identity-verification company whose scanners sit at rental car counters, retail returns desks, dispensaries, casinos and banks. By its own marketing it runs more than 21 million verifications a month at more than 20,000 locations. On September 4 IDScan.net posted a notice saying an unauthorized third party "may have accessed and/or copied certain customer information," including full names and driver's license numbers. Nexus itself claimed it had been copying data for more than a year. If your license has been scanned at a counter in the last few years, assume it may be in the set.

A picture of the card is worse than the number

License numbers have leaked before, many times. A scanned image of the card is different. When you lose access to an online account and the normal password reset fails, the recovery process at many platforms ends the same way: upload a photo of a government-issued ID that matches the name on the account. That step exists to prove you are you. A criminal holding a clean scan of your license, plus your name, address and date of birth from any of a dozen earlier breaches, can now answer it. A stolen license number can open a credit line. A stolen picture of the card can open your accounts.

For a small business, the owner's identity is the business's identity

A consumer with a stolen license worries about credit. A business owner has more on the line, because in a small company the owner's personal identity is the key to nearly everything the company runs on. The domain name is registered in the owner's name. The hosting account, the Google Business Profile, the Facebook page, the Microsoft 365 or Google Workspace admin login, the bank account and the payment processor all recover to the owner's personal email, the owner's cell phone and, when those fail, a photo of the owner's ID. An attacker who can pass that last check does not need your password. They tell the platform you lost it.

What follows is the pattern behind many of the incidents that end small businesses: a domain transferred away, and the website and email with it; a Facebook page taken over and used to scam your own customers; a business profile edited to send calls somewhere else; a loan or a merchant account opened in the owner's name. None of it requires technical skill. It requires a name, an address and a good picture of a card, and 153 million of those were just for sale.

What to do this week

  1. Freeze your credit at all three bureaus. Equifax, Experian and TransUnion each freeze for free, and a freeze stops new credit lines, the most common use of a stolen license. The FTC walks through it at IdentityTheft.gov. Do it for every owner and officer, not just the company.
  2. Put two-factor authentication on the accounts that own the business. Email first, then the domain registrar, hosting, Google Business Profile, Facebook and the bank. Use an authenticator app or a passkey rather than text-message codes. Two-factor keeps most takeover attempts from ever reaching the "upload your ID" step. Our password and account security guide covers how.
  3. Bring recovery information up to date. Log in to each of those accounts and confirm the recovery email and phone number are yours, current, and not a former employee's. Stale recovery details are how an attacker's "I lost access" claim gets a hearing. For domains, turn on the registrar's transfer lock so a move requires an extra step. For our managed clients, the registrar and hosting side of this is handled from our end.
  4. Enroll the principals in identity monitoring. A freeze stops new credit. It does not tell you when your license turns up for sale or when someone applies in your name. Aura, the service in our checklist, alerts on both, and its alert states that identity theft insurance is included with membership. IDScan.net says it is offering free monitoring to people it identifies as affected.
  5. Expect the breach to become the bait. The next round of phishing will cite this breach: "your driver's license was exposed, verify your identity here." No legitimate company will ask you to upload your ID to fix an ID leak. Go to the service's own site or app, never to a link in the message.
  6. Ask before you hand over the card. When a counter wants to scan your license, ask whether a visual check will do and how long the scan is kept. Sometimes the answer is yes, and every scan not taken is one that cannot leak.

The complete list, in priority order, is in our cybersecurity essentials checklist. This breach touches its first three sections directly.

Risingline is not affiliated with Aura and receives no compensation from Aura or from any other company named in this article. We quote Aura's alert because we received it as a subscriber, and we name the service because it is the one our checklist already recommends.

Notice: The information provided in this document is for informational purposes only and does not constitute legal, financial, or professional advice. All materials and guidance offered by Generose Corporation dba Risingline are subject to its Client Services Agreement and Website Terms of Use and are provided without warranty as to accuracy, completeness, or applicability to any specific situation. While Risingline takes reasonable precautions to ensure the reliability of the information presented, compliance with regulatory requirements varies based on specific circumstances, jurisdiction, and evolving standards. Recipients are encouraged to conduct independent due diligence and consult with qualified professionals before implementing any recommendations. Generose Corporation dba Risingline expressly disclaims any liability for actions taken or not taken based on this document. Receipt of this information does not establish a client, advisory, or fiduciary relationship between Risingline and the recipient.

All articles