HomeRisk ManagementsMultiple Class Action Lawsuits Filed Against IDScan

Multiple Class Action Lawsuits Filed Against IDScan

Published on

spot_img

Law firms are now mobilizing in response to alarming reports regarding a potential massive breach of driver’s license information that surfaced last week. This breach centers on IDScan.net, a company specializing in ID verification and fraud prevention services, which has recently found itself under scrutiny.

At least four class-action lawsuits have been filed in the U.S. District Court for the Eastern District of Louisiana against IDScan.net. These lawsuits emerge from the distress among the affected individuals, who are now seeking damages. Furthermore, these plaintiffs are demanding that the company enhance its internal security measures to prevent future incidents.

The Federal Bureau of Investigation (FBI) also announced last week that it is actively investigating the breach. This development followed the initial report by journalist Brian Krebs, who played a crucial role in bringing the issue to public attention. Krebs’ findings suggest that the breach could potentially involve sensitive data from millions of individuals, thereby intensifying the urgency of the investigations.

Two law firms, Hall Attorneys and Markovits, Stock & DeMarco, are joining the fray by investigating claims from potential victims. On the website of Markovits, Stock & DeMarco, a note states, “If you rented a vehicle, visited a cannabis dispensary, or otherwise had your driver’s license or other identification document scanned or verified through IDScan.net’s systems, you may be entitled to compensation and other legal remedies.” This outreach aims to inform individuals about their rights and the potential for recompense due to this significant data breach.

### Drivers in the Crosshairs

Adding to the seriousness of the situation, a service known as “Nexus” on a Russian cybercrime forum has claimed to possess over 153 million driver’s licenses, primarily from American and Canadian drivers. Nexus also reported having over 10 million additional ID cards, travel documents, and medical cards, among other sensitive items. Following Krebs’ exposition, the Nexus service was taken down swiftly, but Krebs continued to track the activity and correlated it with the operations of IDScan.net based in New Orleans.

IDScan.net provides business-to-business ID verification services for a slew of well-known enterprises, including car rental giant Hertz, delivery service FedEx, and numerous cannabis dispensaries across the U.S. The reach of IDScan.net indicates a diverse clientele and significant trust placed in its systems—making the implications of this data breach even more consequential.

John Strand, owner of Black Hills Information Security, commented on the magnitude of data collection by brokers like IDScan.net. He stated, “When you look at data brokers and the sheer amount of information they collect, purchase, acquire, aggregate, and store over time, it’s absolutely staggering. This particular breach appears to be staggering in its own right.” Strand called for more stringent protective measures for such sensitive data, suggesting that personal information might need similar protections to those afforded under HIPAA, the Health Insurance Portability and Accountability Act. He proposed establishing a regulatory framework that treats large collections of personal data with the seriousness they warrant.

In light of this situation, Hall Attorneys have made recommendations for individuals who suspect their data may have been compromised in the breach. Their guidance includes several steps to follow:

1. Identify the business that scanned or uploaded the individual’s ID, noting the location, approximate date, and purpose of the scan.
2. Inquire whether the business employed IDScan.net, VeriScan, DIVE, or another ID verification provider.
3. Ask if any front-and-back images, infrared or ultraviolet captures, selfies, or parsed ID fields were retained and whether the individual’s record is included in any incident review.
4. Retain all correspondence and responses, being cautious not to disclose unredacted ID images, Social Security numbers, or any account passwords in initial inquiries.
5. Treat unsolicited links for breach checks with suspicion to avoid phishing attacks.

IDScan.net has responded to the situation by stating that it is actively investigating the incident. However, the atmosphere remains charged with apprehension and concern as the full scope of the breach becomes clearer. Individuals who may have been affected are encouraged to seek legal counsel and remain vigilant regarding their personal information. As investigations unfold, lawyers, victims, and cybersecurity experts will continue to analyze the ramifications of this substantial breach on personal data privacy and security.

Source link

Latest articles

Tengu Mirai-Style Linux Bot Disguises Itself as Kernel Worker to Execute DDoS and Proxy Attacks

Analysis of Tengu: A New Threat in Linux Malware In the evolving landscape of cybersecurity,...

OpenAI Invests $1 Billion in Daybreak AI Cyber Tools to Safeguard Critical Infrastructure

OpenAI has announced a groundbreaking initiative with a commitment of $1 billion to enhance...

North Korea’s Lazarus Group Functions Across Six Unique Cyber Clusters

In a recent analysis, cybersecurity firms Sekoia and Kudelski Security revealed that North Korea’s...

Global Phishing Campaign Exploits Google Infrastructure to Bypass Security and Steal Credentials

Large-Scale Phishing Operation Exploiting Google Services A sophisticated phishing campaign has emerged, leveraging trusted Google...

More like this

Tengu Mirai-Style Linux Bot Disguises Itself as Kernel Worker to Execute DDoS and Proxy Attacks

Analysis of Tengu: A New Threat in Linux Malware In the evolving landscape of cybersecurity,...

OpenAI Invests $1 Billion in Daybreak AI Cyber Tools to Safeguard Critical Infrastructure

OpenAI has announced a groundbreaking initiative with a commitment of $1 billion to enhance...

North Korea’s Lazarus Group Functions Across Six Unique Cyber Clusters

In a recent analysis, cybersecurity firms Sekoia and Kudelski Security revealed that North Korea’s...