home.social

#identity-theft — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #identity-theft, aggregated by home.social.

fetched live
  1. Cyber Attacks Exploit Legitimate Tools for Rogue Access

    Cyber attackers are sneaking into systems through the front door - by exploiting legitimate tools and services to gain rogue access, with a recent dark-web claim boasting of 153 million stolen U.S. and Canadian driver's licenses. Attackers are finding clever ways to impersonate trusted sources, like IT personnel, to get inside and take…

    osintsights.com/cyber-attacks-

    #SocialEngineering #MicrosoftTeams #IdentityTheft #DarkWeb #EmergingThreats

  2. Driver's Licenses Exposed in Massive 150M Record Breach

    A massive data breach has exposed a staggering 153 million driver's licenses, putting the sensitive information of millions of people in the US and Canada at risk. The breach, linked to a service called Nexus on a Russian cybercrime forum, also includes 10 million ID cards, 3 million travel documents, and 579,000 medical cards.

    osintsights.com/drivers-licens

    #DataBreach #DriversLicenses #IdentityTheft #EmergingThreats #Canada

  3. Krebs On Security: FBI Probes Service Selling 153M+ Drivers Licenses. “A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a […]

    https://rbfirehose.com/2026/09/03/krebs-on-security-fbi-probes-service-selling-153m-drivers-licenses/
  4. As a consequence of this (huge) #databreach the victims will be asked (as it was the case with previous breaches) to be particularly careful and sign up for identity theft protection services.

    That means that the responsibility for preventing negative consequences of data breaches effectively lies with the victim. #equifax initially even tried to sell credit monitoring to the victims of their 2017 breach; they later were forced to provide 4 years of free monitoring as part of the settlement. The #FTC even recommended to go for free monitoring instead of the $125 payout - which I believe very few people actually received anyway.

    I think industry needs to be held responsible for these breaches, e.g., by contributing towards a free insurance for identity-theft victims.

    #krebsonsecurity #identitytheft

    krebsonsecurity.com/2026/09/fb

  5. FBI Probes Massive Driver's License Breach Exposing 153 Million Records

    A stolen cache of 153 million driver's licenses, containing sensitive info like birth dates, addresses, and ID numbers, has fallen into the wrong hands, putting millions at risk of identity theft. This breach is especially alarming since this type of data is often used to verify identities.

    osintsights.com/fbi-probes-mas

    #IdentityTheft #DarkWeb #DriversLicenseBreach #ExploitForum #MassiveDataBreach

  6. KrebsOnSecurity found a driver's license scanned at a rental agency appeared on dark web market Nexus within hours. The service lists over 153 million licenses, pointing to a potential near real-time exfiltration pipeline from document scanning systems. This scale indicates systemic compromise, not isolated breaches. #DataBreach #IdentityTheft #InfoSec

    cyberworldops.eu/en/nexus-153-

  7. @DavidPenington
    I didn’t know that. Thanks

    Maybe legilsation that would criminalise any citizien ID credentials leaving the country unless covered by special govt agreement with extraterritorial guarantees, or something giving the Aust Govt legal rights over such info collected, stored or used overseas in every case, Along with a Govt-backed system of encryptpted identification tokens (preserving a citizen’s privacy) that could be exchanged with companies and agencies overseas when an ID is required, might put an end to #IDTheft schemes.
    /thinking out loud here…/

    #AusPol #PrivacyLaws #IDSecurity #IdentityTheft

  8. RE: infosec.exchange/@brian_greenb

    Scanning of ID documents such as driver’s licence is common in Australia as well, including at most, if not all, clubs (which, let’s be honest have links to the underworld via gambling machines). Fortunately, banks and official institutions require 100 pts of identification and a licence by itself is not enough.

    Still, if your driver’s licence is scanned for whatever reason, you ought to find out what happens to the scan and who has access to it down the line… do you bother to find out? I haven’t, so far…

    #AusPol #Fraud #IdentityTheft #IDScanning #PrivacyProtection

  9. “On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.

    The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.

    A quick look around Nexus finds they are likely not exaggerating about that 153 million number: Running a blank search in Nexus (with no search parameters entered) returns approximately 11.5 million pages of results, with roughly 15 results displayed per page. It includes documents from people in both Canada and the United States, but the bulk of these records are on Americans: searching for just Canadian drivers licenses returns approximately 1.1 million results, with the largest concentration from Ontario (473,673 records).”

    krebsonsecurity.com/2026/09/fb

    #IdentityTheft #CyberCrime #FBI #USA #Canada #Russia #DarkWeb

  10. The FBI's New Orleans field office has opened a formal investigation. This boss has many, many hit points.

    Renting from Hertz lately? That timestamp on your record says hello. Monitor your credit reports, watch for identity fraud, and check idscan.net for breach notifications immediately.

    Reward: You've received a Laminated Dread Card — permanently equipped, cannot be unequipped.

    #DataBreach #CyberSecurity #FBI #IdentityTheft #PrivacyViolation #AchievementUnlocked (2/2)

  11. Brian Krebs found his own driver's license for sale on a Russian crime forum this week. The timestamp on the scan matched the day he rented a car to attend a family funeral. His mom's license was there too, scanned a few seconds after his.

    The service is called Nexus. It claims over 153 million driver's licenses from the US and Canada, and the count grew by nearly 400,000 in a single day. Krebs traced the scans back to an identity verification vendor that checks IDs for rental car companies, big retailers, and over 1,000 marijuana dispensaries. The FBI opened an investigation on Tuesday.

    Most of the people in that database never dealt with the vendor. They handed a license to a clerk at a counter. The clerk ran it through a scanner. Nobody mentioned that the scanner belonged to a different company, or that a copy might stick around long enough to get stolen. If your company scans customer IDs, you own the risk of how your vendor uses those images, whether the contract says so or not.

    Two things worth thinking about:

    - Every new "show us your ID" rule, including the ones sold as protecting kids online, pushes more license scans into more vendors. Each one is another place to lose them.

    - A driver's license is still what banks use to open credit. A scan with the photo, front and back, in infrared and ultraviolet, is close to a master key.

    I would love to see ID scans deleted the moment a check is done. Until then, ask whether your license will be scanned or just looked at before you hand it over. And freeze your credit at all three bureaus. It's free. It takes about ten minutes.

    krebsonsecurity.com/2026/09/fb

    #Cybersecurity #Privacy #IdentityTheft #security #privacy #cloud #infosec

  12. LLM/AI is ignoring human commands and overriding authority by impersonating the human user to grant itself the authority it wants. These kinds of events, being tracked in the UK, doubled in July compared to June.
    youtu.be/txEmFM5cg2Q

    #AI #LLM #corruption #security #identityTheft

  13. RE: infosec.exchange/@briankrebs/1

    🖥️. Canada ⚠️ 🇨🇦 and. 🇺🇸 USA. ⚠️

    Have you scanned , allowed a company to scan, or uploaded your ID ??

    If so, Read This article👇

    #Infosecurity #IdentityTheft
    #Privacy. #Canada #USA #Computing
    #Travel

  14. Notes from Poland: Poland asks EU to fine Meta €250m over scam Facebook ads. “Poland has formally requested that the European Commission fine Meta, the owner of Facebook, Instagram and WhatsApp, €250 million (1.1 billion zloty) for failing to tackle fraudulent advertising on its platforms. Its decision follows a high-profile campaign by Rafał Brzoska, the billionaire owner of Polish […]

    https://rbfirehose.com/2026/08/27/notes-from-poland-poland-asks-eu-to-fine-meta-e250m-over-scam-facebook-ads/
  15. The DoRaleigh Scam Report Popular Scams and How to Avoid Them

    Scammers are becoming more convincing, using artificial intelligence, caller ID spoofing, social media, text messages, fake websites, and emotional pressure to steal money and personal information.

    In 2025, consumers submitted approximately 3 million fraud reports and reported losing $15.9 billion, according to the Federal Trade Commission⁠. Imposter scams alone accounted for $3.5 billion in reported losses.

    Raleigh and Triangle residents can reduce their risk by learning the warning signs of today’s most common scams.

    1. Government and Business Imposter Scams

    A caller, email, or text may claim to come from the IRS, Social Security Administration, Federal Trade Commission, police department, bank, utility company, or another trusted organization.

    Scammers often say that your account has been compromised, you owe money, or you face arrest unless you act immediately. They may even manipulate caller ID or send official-looking documents.

    How to avoid imposter scams

    • Do not trust caller ID alone.
    • Hang up and contact the organization using its official website or published phone number.
    • Never move money to “protect” it.
    • Government agencies will not demand payment through gift cards, cryptocurrency, gold, or cash delivered to a courier.
    • Do not provide account passwords, PINs, verification codes, or Social Security numbers after an unexpected contact.

    The FTC advises consumers never to transfer money, cryptocurrency, or gold after an unsolicited call or message. Anyone directing you to move money for its protection is attempting a scam. Read more from the FTC’s imposter scam guide⁠.

    2. Phishing Emails and Text-Message Scams

    Phishing messages imitate banks, delivery companies, toll agencies, streaming services, employers, and government offices. Common messages claim that a package is delayed, a toll remains unpaid, an account will be closed, or suspicious activity requires immediate attention.

    The included link may lead to a fake website designed to steal login credentials, banking information, or credit-card numbers. The FBI explains that these sites can closely resemble legitimate financial or commercial websites. Learn about phishing and spoofing from the FBI⁠.

    How to avoid phishing scams

    • Do not click links in unexpected emails or text messages.
    • Open the company’s official app or type its website address directly into your browser.
    • Inspect email addresses carefully for misspellings or unusual domains.
    • Never share a login verification code with someone who contacts you.
    • Delete messages that demand immediate payment or personal information.

    3. Investment and Cryptocurrency Scams

    Investment scammers promise guaranteed returns, exclusive opportunities, or profits with little or no risk. Some build relationships through social media or dating apps before recommending a fraudulent cryptocurrency platform.

    A fake account dashboard may appear to show growing profits, but victims are later told to pay additional fees or taxes before withdrawing their money.

    How to avoid investment scams

    • Be skeptical of guaranteed or unusually high returns.
    • Research the investment professional and company independently.
    • Do not invest based solely on advice from someone you met online.
    • Never send cryptocurrency to “unlock” earnings or protect an account.
    • Avoid opportunities that pressure you to act before conducting research.

    The FBI warns that no legitimate investment can guarantee a return. Review the FBI’s investment fraud guidance⁠.

    4. Romance Scams

    Romance scammers create fake profiles on dating apps and social media, quickly building trust and emotional connections. They frequently avoid meeting in person while claiming to work overseas, serve in the military, travel extensively, or face a personal emergency.

    Eventually, the scammer requests money for travel, medical care, legal problems, business expenses, or an investment.

    How to avoid romance scams

    • Be cautious when an online relationship develops unusually quickly.
    • Conduct a reverse-image search on profile photographs.
    • Discuss the relationship with a trusted friend or family member.
    • Never send money, gift cards, cryptocurrency, or banking information to someone you have not met.
    • Stop communicating when someone repeatedly avoids video calls or in-person meetings.

    The FBI’s romance scam guidance⁠ explains how criminals use fake identities and emotional manipulation to gain trust before asking for money.

    5. Job and “Task” Scams

    Job scammers pose as recruiters offering remote positions with high salaries, flexible schedules, and little experience required. They may conduct interviews through text messages, send fake checks for equipment, or require applicants to pay for training.

    Task scams promise commissions for completing simple online activities. Victims may initially receive a small payment before being required to deposit larger amounts or purchase cryptocurrency.

    How to avoid job scams

    • Verify openings on the employer’s official careers page.
    • Research the recruiter’s name, email address, and company.
    • Be suspicious of interviews conducted entirely through messaging apps.
    • Never pay for a job or send money to begin working.
    • Do not deposit a check and forward part of the money to another person.
    • Never use your personal bank account to transfer money for an employer.

    6. Tech-Support Scams

    A pop-up, phone call, or email may claim that your computer has a virus or your account has been hacked. The scammer may request remote access to your device, install unwanted software, or demand payment for unnecessary repairs.

    How to avoid tech-support scams

    • Do not call numbers displayed in unexpected security pop-ups.
    • Never give remote access to someone who contacts you unexpectedly.
    • Contact the device manufacturer or software provider directly.
    • Close the browser or restart the device if a suspicious pop-up will not disappear.
    • Never pay for technical support with gift cards, cryptocurrency, or a wire transfer.

    The FTC’s tech-support scam guide⁠ notes that scammers prefer payment methods that are difficult to reverse.

    7. Online Shopping, Marketplace and Rental Scams

    Scammers advertise nonexistent products, pets, concert tickets, vehicles, apartments, and vacation rentals. Prices are often significantly lower than comparable listings, and the seller may demand a deposit before allowing an inspection.

    How to avoid marketplace and rental scams

    • Search the seller’s name, phone number, and listing photographs.
    • Compare the price with similar listings.
    • Inspect property or merchandise before paying whenever possible.
    • Use the platform’s approved payment system and buyer protections.
    • Avoid sellers demanding gift cards, cryptocurrency, wire transfers, or payment outside the platform.
    • Never pay a rental deposit before verifying the property and owner.

    8. Family Emergency and Grandparent Scams

    A caller may pretend to be a child, grandchild, lawyer, police officer, or hospital employee. Some scammers use artificial intelligence to imitate a loved one’s voice.

    The caller claims there has been an accident, arrest, kidnapping, or medical emergency and insists that the situation remain secret.

    How to avoid family emergency scams

    • Hang up and call the family member directly.
    • Contact another relative to verify the story.
    • Create a private family verification word.
    • Ask a question that a stranger could not answer from social media.
    • Never send cash to a courier or pay through gift cards or cryptocurrency.

    9. Prize, Lottery and Sweepstakes Scams

    Scammers tell victims they have won money, a vacation, or another prize—but must first pay taxes, processing costs, or delivery fees.

    How to avoid prize scams

    • Remember that legitimate sweepstakes do not require payment to receive a prize.
    • Do not provide banking or Social Security information.
    • Be suspicious if you did not enter the contest.
    • Never deposit a check and return a portion of the funds.
    • Ignore demands for gift-card or cryptocurrency payments.

    10. Payment-App and Gift-Card Scams

    Payment apps are designed to send money quickly, which can make recovery difficult. Scammers may impersonate a bank employee, buyer, seller, friend, or relative and ask for an immediate transfer.

    Gift cards are another major warning sign. No legitimate government agency or business will require gift cards as payment. The FTC’s gift-card scam guidance⁠ advises consumers never to share a gift-card number or PIN with an unexpected caller.

    How to avoid payment scams

    • Confirm payment requests directly with the person involved.
    • Review the recipient’s name before sending money.
    • Never return an alleged accidental payment by starting a new transaction.
    • Do not share gift-card numbers, PINs, or photographs.
    • Stop when someone dictates exactly how and where you must pay.

    Major Scam Warning Signs

    Stop communicating when someone:

    • Creates a sudden emergency
    • Pressures you to act immediately
    • Demands secrecy
    • Requests gift cards, cryptocurrency, gold, cash, or a wire transfer
    • Promises guaranteed profits
    • Asks for passwords, PINs, or verification codes
    • Tells you to move money for its protection
    • Refuses to let you independently verify the story

    What to Do If You Have Been Scammed

    Act quickly, but do not feel embarrassed. Scammers are trained to manipulate emotions and create believable situations.

    1. Contact your bank, credit union, card issuer, payment app, or gift-card company immediately.
    2. Ask whether the transaction can be stopped, recalled, or disputed.
    3. Change compromised passwords and enable multifactor authentication.
    4. Save emails, text messages, receipts, usernames, phone numbers, and transaction records.
    5. Report fraud to the Federal Trade Commission⁠.
    6. Report internet-enabled fraud to the FBI Internet Crime Complaint Center⁠.
    7. Use IdentityTheft.gov⁠ for a personalized recovery plan if personal information was stolen.
    8. File a complaint with the North Carolina Department of Justice⁠ or call 1-877-5-NO-SCAM.
    9. Contact local law enforcement if money was stolen or you are being threatened.

    Protect Your Accounts Before a Scam Happens

    Use a unique password for every important account, turn on automatic software updates, and enable multifactor authentication for email, banking, social media, and payment accounts. CISA recommends MFA because it adds another identity check beyond a password and makes unauthorized access more difficult. Learn more from CISA⁠.

    Most importantly, pause before responding. A few minutes spent verifying a message can prevent significant financial loss. If you need help in Raleigh contact BTDesigns.pro

    Follow DoRaleigh.com for more Triangle consumer alerts, public-safety information, community resources, and local news.

    Connect With Us: Instagram | Facebook | BSky | Linkedin

    Share With Us: Post your community News, Events, on our Submissions Page.

    Advertise With Us: Interested in Advertising click here.

    Published by Bryan Tomlinson | BTDesigns.pro |

    #CyberSecurity #DoRaleigh #freeCybersecurityWorkshops #IdentityTheft #ImposterScams #InvestmentScams #JobScams #News #NorthCarolinaScams #OnlineSafety #PhishingScams #PopularScams #RaleighConsumerAlerts #RomanceScams #ScamPrevention #ScamReport
  16. Lifehacker: Hundreds of Fake VPNs Are Flooding the Chrome Web Store. “Many of these extensions are free, some are paid, and some even pretend to be from trusted cybersecurity providers to lure users into handing over unrestricted access to their network and browser. This weekend, I dug through Socket’s report to find out exactly what was going on with these apps and how they managed to clear […]

    https://rbfirehose.com/2026/08/22/lifehacker-hundreds-of-fake-vpns-are-flooding-the-chrome-web-store/
  17. Amex CreditSecure alerted me that somebody had opened a collections account with my details, reported to all three credit agencies. Called them, and they were able to see that the originator of the alleged $60 debt was Comcast: A company I have not had any dealings with since 2017 when I canceled my service and paid the final bill from them (and that was just $6).

    Disputes filed with all three agencies now; will see what comes of it.

    #creditmonitoring #identitytheft

  18. So, when my wife got her passport, the post office conveniently lost her naturalization certificate. When she got a new one issued, the new one mysteriously disappeared in the mail too, even though it was sent certified mail. It seems like there's some organized thing going on in the #Bronx where people are stealing naturalization certificates being sent through #USPS.

    #USCIS #theft #identitytheft

  19. Hollywood Reporter: Inside the Fake Celebrity Podcast Scam Fooling Hollywood. “[Seth] Rudetsky had stumbled into an increasingly sophisticated scam in which fraudsters impersonate famous podcasters and their representatives, using flattering, highly personalized invitations — most likely composed by AI — to lure prospective guests into handing over money, login credentials or control of […]

    https://rbfirehose.com/2026/08/19/hollywood-reporter-inside-the-fake-celebrity-podcast-scam-fooling-hollywood/
  20. AI is increasingly calling the punches, accelerating the assault while defenders scramble between rounds.

    The bell doesn't save you here. Audit your breach response and notification pipelines now, because the volume alone will bury anyone still running manual triage.

    Reward: You've received the Participation Ribbon of Inevitable Compromise. Frame it. You earned it.

    #DataBreach #CyberSecurity #InfoSec #AI #IdentityTheft #AchievementUnlocked (2/2)

  21. @paul @mcnado This is great to know. Thanks for posting. The #phishing #scams are getting more and more convincing, backed up by real/AI people on the phone who know exactly how to manipulate their victims. I know because I was a victim about a year ago. #Identitytheft is a major PITA, and possibly devastating. I was lucky — the baddies were caught in the act of trying to siphon my accounts. Let be me clear about one thing:

    TRUST YOUR INSTINCT!

    Often, our subconscious recognizes risks and we don’t pay attention to the signals. If just one of you avoids a phishing attack because of this post it will bring us all some peace.

  22. NiemanLab: Japanese publishers are fighting imposter news sites with a cryptographic signature. “[Originator Profile] isn’t meant to judge whether all of the content on a website is true. It doesn’t authenticate specific photographs or video clips. Instead, it authenticates the site itself — for example, confirming that a news article is genuinely coming from the news organization it […]

    https://rbfirehose.com/2026/08/15/niemanlab-japanese-publishers-are-fighting-imposter-news-sites-with-a-cryptographic-signature/
  23. This is absolutely wild..what the hell.
    [The Wall Street Journal-Gifted article]: Video Investigation, Inside North Korea’s Operation to Conquer the American Job Market

    Watch how Pyongyang’s scheme to generate $800 million a year works By Emma Scott, Sam Kessler and Robert McMillan, Aug. 12, 2026

    wsj.com/business/media/inside-

    #northkorea #identitytheft