Infosecurity
FBI Investigates Possible Breach of 153 Million Driver’s Licenses
Published
50 minutes agoon

What We Know So Far
The FBI is reportedly looking into what could be one of the largest identity data breaches in recent memory. Investigative journalist Brian Krebs first exposed the issue, revealing a service called “Nexus” on the Exploit Russian cybercrime forum.
Nexus claimed to hold digital scans of over 153 million driver’s licenses — mostly from the U.S. and Canada. The trove also included ID cards, travel documents, and medical cards. That’s not just a few records. We’re talking about a significant chunk of the North American adult population.
The operators said the data came from an active breach at “a major identity verification company.” Shortly after Krebs published his findings, Nexus went dark. But Krebs had already tracked activity linking the data to IDScan.net, a New Orleans-based identity verification provider. The company says it’s investigating.
Why Driver’s License Data Is So Dangerous
A driver’s license isn’t just a plastic card. It carries your date of birth, home address, physical descriptors, and a government-issued ID number. Seemant Sehgal, CEO of BreachLock, put it bluntly: that’s enough to pass identity checks at most financial institutions and government agencies.
Here’s the kicker — unlike a password, you can’t change your face or your birth date. Sehgal notes that every person in this dataset carries the exposure for life. A compromised credit card gets replaced in 24 hours. A compromised driver’s license? You’re stuck with it.
The Growing Threat of Identity Verification Breaches
This isn’t an isolated incident. Identity verification companies hold massive amounts of sensitive data, making them prime targets for cybercriminals. When one gets hit, the ripple effects can touch millions.
Denis Calderone, CTO at Suzu Labs, argues that businesses relying on these vendors need to ask harder questions. How long are scans retained after verification? Are there contractual data minimization obligations? Can you audit the vendor?
What Can You Do to Protect Yourself
Right now, there’s no equivalent of a credit freeze for your driver’s license number. Calderone stressed that every organization collecting government-issued IDs needs to treat that data with the same security as payment card data — if not higher.
For individuals, the options are limited but not zero. Here are a few practical steps:
- Monitor your credit reports regularly for unfamiliar activity.
- Place a fraud alert or credit freeze with the major credit bureaus.
- Be cautious when asked to upload your ID online — verify the request is legitimate.
- Use identity theft protection services if you suspect you’re affected.
The Bigger Picture on Data Breaches
This potential breach comes amid a record year for data compromises. US data breaches hit an all-time high recently, though the number of victims per incident declined. That trend doesn’t make this case any less concerning — the sheer volume of identity documents involved is staggering.
Calderone summed it up well: “You can get a new credit card number in 24 hours. You can’t get a new face.” That’s the uncomfortable reality of this situation.
For more context on how these incidents unfold, check out our coverage on identity data breaches and cybersecurity best practices.
You may like
Infosecurity
Two Decades of Malice: How an International Takedown Finally Struck at the Sality P2P Botnet
Published
5 minutes agoon
September 4, 2026
Operation Strikes at a 20-Year-Old Menace
For more than two decades, the Sality P2P botnet has been a quiet, persistent threat. On August 31, that all changed. A US-led law enforcement operation, with help from Bulgaria, Hungary, Romania, and Europol, dealt a significant blow to this sprawling network.
The private sector played a key role too. CrowdStrike and the Shadowserver Foundation lent their technical muscle to the effort. Their goal? To sever the botnet’s decentralized communication lines and finally start cleaning up the mess.
Why Sinkholing Is the Go-To Tactic
Disrupting a P2P botnet isn’t like taking down a traditional one. There’s no single command-and-control server to seize. Instead, infected machines talk directly to each other. That’s what makes them so resilient.
The operation’s core strategy was sinkholing. This technique redirects traffic from infected machines away from the botnet’s real infrastructure. It’s a clever way to isolate the network and observe its behavior without letting it function normally.
Europol noted this wasn’t a spur-of-the-moment decision. They’ve been tracking Sality-related infrastructure since 2017. In the weeks before the takedown, coordination intensified with weekly operational calls among all partners.
The Role of ISPs and CSIRTs
While authorities seized domains linked to Sality, the Shadowserver Foundation worked behind the scenes. They coordinated with internet service providers and Computer Security Incident Response Teams (CSIRTs) to identify infections and notify victims. The US Justice Department emphasized this victim-notification effort as a critical part of the overall strategy.
The Scale of the Sality Botnet
Sality isn’t just old; it’s massive. Europol reports that at its peak, the botnet boasted over one million infected machines. These were unwitting participants in crypto-theft and other malicious schemes.
Over the years, more than 11 million unique IP addresses have been linked to Sality’s infrastructure. That’s a staggering footprint for any cybercriminal enterprise.
CrowdStrike’s analysis paints an even more detailed picture. They claim the botnet operator distributed malicious payloads to over 15,000 machines. These payloads included credential theft tools, spam distribution software, proxy services, and DDoS attack mechanisms.
Exploiting Sality’s Trust Flaw
Here’s the interesting part: the takedown worked by turning Sality’s own design against it. CrowdStrike explained that every Sality bot maintains a list of known super peers. These are publicly reachable infected machines that form the backbone of the network.
Every 40 minutes, each bot checks whether its stored peers are still online. Peers that respond gain reputation. Those that don’t lose it and are eventually purged from the list. This verification process was the weak link.
The disruption team exploited this by:
- Removing legitimate peers through protocol-level manipulation during the verification phase.
- Inserting sinkhole entries into the emptied peer lists. This allowed them to track progress and notify victims effectively.
The result? A botnet that once seemed untouchable is now struggling to maintain its grip on infected machines worldwide.
What This Means for the Future of Botnet Disruption
This operation proves that even the most resilient P2P networks have vulnerabilities. It also highlights the importance of international cooperation. No single country could have pulled this off alone.
For anyone concerned about P2P botnet threats, this is a positive sign. It shows that law enforcement and private security firms can work together effectively against even the most entrenched cybercriminal infrastructure.
Still, experts caution that Sality isn’t completely dead. The sinkholing has disrupted operations, but the underlying malware remains on infected machines. Continued vigilance from ISPs and individual users will be essential to fully eradicate this decades-old threat.
Infosecurity
Russian national faces 20 years for malware campaign that infected 80,000 freelancers
Published
21 hours agoon
September 3, 2026
Malware campaign targeted freelancers with poisoned Excel files
A Russian national is staring down a potential 20-year prison sentence after being indicted for a malware campaign that infected more than 80,000 freelancers back in 2016.
Searzhudin Tamirlanovich Aktulaev made his first appearance in a San Francisco federal court on Monday. He was arrested in Cyprus in May 2025 and extradited to the U.S. last week, according to the Justice Department.
The indictment, originally filed in 2021, accuses Aktulaev of deploying a variant of the TVRAT malware — also known as TVSPY or TeamSpy — through the messaging platform of a freelance employment tech company. Between June 2016 and November 2017, he allegedly spread the malware to roughly 80,000 of the site’s users.
Prosecutors say Aktulaev sent messages from 255 fake user accounts, each carrying malicious Microsoft Excel attachments. When victims opened those files, they were prompted to take actions that secretly downloaded the malware onto their devices.
The indictment remains sealed as of Wednesday, and the DOJ has not named the freelance company that was hit.
How the malware worked
TVRAT is a nasty piece of code that exploits a vulnerability in TeamViewer, a popular remote access tool. Once installed, it gives attackers full control over a victim’s device.
Aktulaev also used a second strain of malware called DarkVNC, which did the same thing but targeted a bug in VNC Viewer, another remote administration tool.
With that level of access, Aktulaev allegedly stole data and committed fraud. He kept command-and-control domains active after the initial infection, allowing him to return to compromised devices whenever he wanted.
Victims concentrated in California
About half of the victims were based in the U.S., with a heavy concentration in California. Prosecutors say Aktulaev maintained a document containing stolen e-commerce login credentials and personal information for hundreds of victims.
That document alone paints a picture of a long-running operation — not a one-off hack. The scale of it, 80,000 infected freelancers, makes it one of the more significant malware campaigns aimed at remote workers in recent memory.
Charges and potential sentence
Aktulaev faces multiple charges, including:
- Conspiracy
- Aggravated identity theft
- Transmission of a program, information, code, and command to cause damage to a protected computer
If convicted on all counts, the maximum sentence is 20 years in federal prison.
He is currently in federal custody, with his next hearing scheduled for October 5.
Why this matters for freelancers
This case is a stark reminder that freelancers are prime targets for cybercriminals. They often work from personal devices, handle sensitive client data, and communicate through platforms that may not have enterprise-grade security.
The attack vector here — malicious Excel attachments sent through a legitimate messaging system — is still one of the most common ways malware spreads. A 2016 campaign like this one would have been cutting-edge then, but the techniques remain relevant today.
For anyone working remotely, the lesson is simple: be wary of unexpected attachments, even from people you think you know. And if a file asks you to enable macros or take other unusual steps, stop and think before clicking.
This case also highlights how international cybercrime prosecutions work. Aktulaev was arrested in Cyprus, extradited to the U.S., and is now facing justice in San Francisco. It’s a slow process, but it shows that law enforcement agencies are willing to chase suspects across borders.
The freelance platform targeted here hasn’t been named, but the impact on its users was clearly massive. For those 80,000 victims, the malware may have compromised everything from bank accounts to client contracts.
As the case moves forward, more details are likely to emerge. For now, Aktulaev sits in federal custody, awaiting his next court date. The outcome could set a precedent for how similar cross-border cybercrime cases are handled in the future.
Infosecurity
FulcrumSec Drops 550GB of Manchester Airports Group Data — and It’s Almost All Out There
Published
1 day agoon
September 3, 2026
The Short Version: A Massive Dump, Almost Fully Public
A threat actor going by the name FulcrumSec says it has now published nearly all of the 550GB of data it stole from Manchester Airports Group (MAG), the UK’s largest airport operator. The group claims the leaked archive contains around 549GB of uncompressed customer information, which it describes as “pure PII.”
That’s a staggering volume of personal data. And if FulcrumSec’s claims check out, it dramatically expands what we know about an incident that MAG has said very little about since it first acknowledged a cyber incident back in late August.
How Did They Get In? Blame the Frontend JavaScript
FulcrumSec says the initial access wasn’t some sophisticated zero-day exploit. Instead, the group claims it found admin keys for Iterable, a customer engagement platform, sitting in the frontend JavaScript of all three MAG-owned airport websites: Manchester, Stansted, and East Midlands.
“These keys were not found on some obscure subdomain, as was the case with the credentials that led to our breaches of Arup Group and Novo Nordisk. All three of these were on the sites’ root domain,” the group’s leak note reads.
In other words, anyone who visited the sites could have hit “inspect element” and seen the keys. No subdomain enumeration. No URL crawling. Just plain sight.
What Exactly Was Stolen? A Lot More Than MAG Admitted
MAG’s initial disclosure was thin on details. FulcrumSec’s post paints a much broader picture of the exfiltration. The group claims to have taken:
- Nearly 8.7 million customer profiles, including names, emails, mobile numbers, home towns, postcodes, and residential IP addresses.
- Around 1.2 billion marketing events (sends, opens, clicks).
- Almost 2.5 million purchase records — essentially every booking ever made for parking, Fast Track, and lounge services.
- Over 461,000 SMS messages containing passenger booking dates, car park details, and vehicle registrations in plain text.
- 108,000 unique vehicle registration plates.
- Platform configuration data.
That’s a treasure trove for phishing campaigns. With residential IP addresses and mobile numbers in hand, attackers can craft highly convincing, targeted scams that are hard to spot.
The Physical Danger for Travellers
Perhaps the most alarming claim involves data on nearly 191,000 future bookings. FulcrumSec says this includes travel schedules, PII, and vehicle information that could allow criminals to target holidaymakers’ homes while they’re away.
The group even suggests that some of these individuals may be public figures, politicians, or military personnel, based on the email addresses tied to the bookings.
“Sadly MAG declined to pay the necessary fee to protect their passengers’ data, leaving us to remove the most sensitive parts … from the leak prior to publication,” FulcrumSec added.
That last line is worth pausing on. It implies the group edited the dump before release — which raises questions about what was left out, and why.
What MAG Has Said (and Not Said)
Manchester Airports Group has not issued an update since its original statement on August 27. Its initial post confirmed a cyber incident but offered little in the way of specifics. FulcrumSec’s claims remain unverified by independent researchers, and it’s possible the data is incomplete, repackaged, or partially fabricated.
That said, the group has a track record. It previously claimed breaches of Arup Group and Novo Nordisk, and its leak site is active. The MAG incident, if confirmed, would be one of the largest airport-related data breaches in UK history.
What Should Affected Passengers Do Now?
If you’ve used Manchester, Stansted, or East Midlands airports for parking, Fast Track, or lounge bookings, the risk is real. Here’s a practical checklist:
- Change your passwords — especially if you reuse them across sites. Use a password manager to generate unique ones.
- Enable two-factor authentication on your email and banking accounts immediately.
- Watch for phishing emails and SMS that reference your airport bookings. Be suspicious of any message asking you to click a link or confirm details.
- Monitor your credit reports for unusual activity over the coming months.
- Be cautious with travel plans — if you have an upcoming booking, consider whether you need to share additional personal details.
For more on how to protect yourself after a data breach, check out our guide on responding to a personal data leak. You might also want to read about how phishing attacks use stolen PII to understand the tactics criminals employ.
The Bottom Line
This is a developing story, and verification is pending. But the scale of the alleged leak — 550GB, millions of profiles, and a heap of sensitive travel data — is a stark reminder that exposed API keys can have catastrophic consequences.
MAG’s silence is deafening. Passengers deserve to know exactly what was taken, and what the group is doing about it. Until then, assume your data is out there and act accordingly.

Two Decades of Malice: How an International Takedown Finally Struck at the Sality P2P Botnet

FBI Investigates Possible Breach of 153 Million Driver’s Licenses

How to Fix Start Menu & Taskbar Not Working in Windows 10 & 11 – Step-by-Step Guide
Trending
CyberSecurity6 months agoLeakBase Data Breach Forum Seized in Major Europol Operation
How To5 months agoThe Truth About Fast Charging Apps for Android: Can They Speed Up Your Battery?
CyberSecurity6 months agoZero-Day Attacks Hit Record High as Enterprise Software Becomes Prime Target
CyberSecurity6 months agoRussian Hackers Target WhatsApp and Signal in Global Espionage Campaign
Social Media6 months agoYouTube Live Streaming API: A Developer’s Guide to Managing Live Broadcasts
Video4 months agoSamsung One UI 8.5 Official Update Is Here: Release Timeline, Eligible Devices & Key Features
Infosecurity6 months agoCybersecurity Communication: Why Fear-Based Messaging Fails and What Works
CyberSecurity6 months agoContextCrush Vulnerability: How a Trusted AI Tool Became an Attack Vector


