AssuranceAmerica Managing General Agency, LLC
Incident posture
Linked entities
- Victim
- AssuranceAmerica Managing General Agency, LLC
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A dark web group called NEXUS offered for sale full scans of more than 153 million U.S. and Canadian driver’s licenses, along with more than 10 million other identity, travel, and medical cards. The compromised material included front-and-back images, facial photos, barcodes, and anti-counterfeiting features. The incident involved AssuranceAmerica Managing General Agency, LLC and IDScan.net, an identity-verification platform whose cloud-stored customer information was accessed or copied by an unauthorized third party. The exposed records created significant identity-theft risk because they contained high-quality government ID images and verification data. The FBI was investigating the breach.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Driver’s license information from AssuranceAmerica Managing General Agency, LLC, referred to in the broadcast as Assurance America, had been stolen in July, according to James Lee of the Identity Theft Resource Center. The issue became widely discussed after independent security reporter Brian Krebs reported unusual activity on a Russian cybercrime forum called Exploit, where someone was attempting to sell a large volume of North American identity documents. Krebs’s report showed that the listing was not limited to extracted license data, but included actual scans of identity documents. A dark web group or service called NEXUS offered full scans of more than 153 million driver’s licenses from the United States and Canada, along with more than 10 million ID cards, travel documents, and medical cards. The listing claimed to include front and back images of driver’s licenses, including security features such as barcodes and anti-counterfeiting details.
The scope of the listing meant that more than half of licensed drivers in the United States were represented in the stolen material. Krebs reported finding his own driver’s license in the database, as well as his mother’s license and licenses belonging to friends. The broadcast also stated that Defense Secretary Pete Hegseth’s license was listed for sale for $100, and that some licenses apparently belonged to FBI agents. NEXUS went dark after Krebs’s initial post, but the material had already been exposed on the dark web.
The broader incident centered on IDScan.net, a Louisiana-based identity verification company that provides age and identity verification services, mobile ID scanners, and ID fraud prevention tools. The broadcast described IDScan.net as serving about 20,000 locations and processing 21 million verifications per month. Public statements from IDScan.net said an unauthorized third party may have accessed and/or copied certain customer information stored within accounts on the IDScan.net cloud. At the time of the broadcast, IDScan.net had not publicly explained how the unauthorized access occurred. The FBI was reported to be conducting an official investigation, and IDScan.net was also conducting its own internal investigation.
The exposed scans created risks beyond ordinary exposure of names or account details because they included high-quality images of government-issued documents. The broadcast described the images as including Real ID-compatible facial images and forensic-level document details. IDScan.net documentation showed that its systems scanned documents using visual, infrared, and ultraviolet light, which could capture anti-counterfeiting technology. The stated impacts included the ability to create convincing replicas of government IDs, fool people or machines during identity checks, and support online identity verification fraud. Reported fraud scenarios included attempts to access state and local benefits, apply for small business loans, apply for unemployment benefits, and commit new account fraud. The breach also raised risks for vulnerable people, including domestic abuse survivors, people in witness protection, and military undercover personnel, because the leaked documents included face images tied to identity records.
As part of its response, IDScan.net offered credit protection services to affected individuals. The broadcast noted that Louisiana’s breach notification framework allowed large breaches involving more than 100,000 individuals, or cases where individual notification would cost more than $100,000, to be handled through a website notice and a news release to media in the state rather than individual notification. James Lee said many individuals whose driver’s licenses had been scanned did not know IDScan.net existed. The incident exposed how identity data collected by third-party verification vendors could become a large-scale breach source when stored in centralized cloud accounts.
Sources
Sources available to members: 1 source.