A major data leak exposed millions of documents and raises concerns about potential impacts on Brazil. Often, when using platforms or services that require identity verification, the submitted data, such as scanned documents or selfies, is forwarded to third-party companies responsible for authentication.
The company IDScan, one of these service providers, was allegedly the victim of a major data breach, as reported by cybersecurity journalist Brian Krebs in an article published on his website on Tuesday, the 1st. The vast collection of this company's documents was reportedly exposed.
Although the leaked documents are known to belong to countries such as the United States and Canada, IDScan also provides authentication services for Brazilian documents and lists support for these types of documents.
The origin of the leak was identified on a dark web site called Nexus, which began disclosing access to a massive database. The criminals claimed to possess photos of over 153 million driver's licenses issued in the United States and Canada, in addition to about ten million identity documents, three million passports and travel documents, health cards, and access badges for government buildings.
To validate the authenticity of the material, the site presented samples, including documents belonging to Krebs and American authorities, such as US Secretary of Defense Pete Hegseth, and an assistant director of the FBI.
The connection between the leak and IDScan was established during the analysis of the exposed images. Each photo contained a date and time record. By comparing this data with his personal history, Krebs noted that the times coincided with moments when he had presented documents at locations equipped with IDScan readers.
The leak included versions of documents both front and back, as well as captures made under infrared and ultraviolet light, spectra used by validation equipment to check security elements invisible to the naked eye. Furthermore, the data extraction appeared to occur in real-time, with approximately 400,000 records entering the Nexus database in just 24 hours, while the criminals claimed to have collected data from the company over the course of a year.
After the publication of the report and confirmation that the FBI office in New Orleans initiated an investigation into IDScan, the Nexus site was taken offline.
Implications of the leak for security
Natalian Silva, spokesperson for IAM Brasil and cybersecurity expert, classified the incident as serious, given that technologies like those offered by IDScan are employed in processes considered critical. According to the expert, the leak goes beyond the simple exposure of documents, as it can generate inputs for fraud in financial, digital, and in-person services.
Silva detailed that previously captured and validated documents are particularly valuable to criminals, as they can be used in attempts to open accounts, apply for credit, improperly recover access, modify registration data, conduct social engineering, and create synthetic identities.
The expert made two important observations. Firstly, she stressed that such a leak does not imply that all processes using the documents are automatically compromised. She argued that robust validation must go beyond the mere presentation of the document image, needing to integrate signals such as proof of life, biometric comparison, device reputation, transaction context, behavior, and risk analysis. However, the incident considerably diminishes confidence in the document as isolated proof.
The spokesperson for IAM Brasil also pointed out an aggravating factor: although a password can be changed after a leak, personal characteristics such as face, date of birth, signature, and history cannot simply be replaced, which can lead to consequences for victims for many years.
Natalian Silva's second caveat was that the platform supporting Brazilian documents does not prove that Brazilian citizens' documents were actually leaked; this needs to be confirmed by the investigation. The technical processing capability indicates potential exposure but does not confirm the inclusion of Brazilian data in the incident.
Natalian Silva advised that companies using IDScan technology take immediate measures to verify which integrations and data are active with the partner platform, in addition to changing digital access keys (APIs), credentials, and passwords. She also recommended demanding clarification from the provider regarding the scope of the leak and, in the absence of security guarantees, temporarily suspending the submission of new information.
The expert concluded that this case reinforces the principle that outsourcing identity verification does not mean transferring responsibility. The contracting organization remains responsible for understanding the data flow, limiting its retention, assessing international transfer, monitoring security controls, and maintaining contingency plans for when a critical point in the chain of trust fails.
