Massive Personal Data Breach Raises Concerns, Vietnam's Direct Impact Appears Limited
Technology
2026年9月11日
6
Nhan Dan
Relations
🇻🇳Vietnam🇺🇸United States

General articles are free for 24 hours after publish.

Massive Personal Data Breach Raises Concerns, Vietnam's Direct Impact Appears Limited

Share
AI Summary

A massive personal data breach under FBI investigation has revealed the illicit sale of identity information of US and Canadian citizens. While direct impact on Vietnam appears limited currently, the incident underscores the critical importance of personal data protection.

The U.S. Federal Bureau of Investigation (FBI) is investigating a case involving the theft and online sale of hundreds of millions of personal identification documents belonging to U.S. and Canadian citizens. This incident has raised concerns about identity fraud and other unpredictable consequences. According to a report by cybersecurity journalist Brian Krebs in early September, a cybercrime service named Nexus advertised on a Russian cybercrime forum that it possessed copies of identity documents for over 170 million people in North America and was offering these data for sale on the internet. U.S. authorities have stated that the data trove includes approximately 160 million driver's licenses and identification cards from the U.S. and Canada, along with over 10 million resident permits, travel documents, and international medical cards. Notably, the data posted on the cybercrime forum reportedly included images of driver's licenses bearing the name of U.S. Secretary of the Army Pete Hegseth. The hacker group operating Nexus claims to have maintained access to the systems of a major identity verification company for over a year. They stated that the system is connected to numerous corporate clients, including companies on the "Fortune 500" list, and that they continuously extracted about 500,000 new documents daily. However, these claims have not yet been fully verified, and the true origin of the data remains unclear. James E. Lee, President of the Identity Theft Resource Center, commented that if Nexus's claims are accurate, this could be one of the largest driver's license data leaks ever recorded, warning that the data could be exploited by cybercriminals for years. Professor Edgar Whitley from the London School of Economics warned that the exposure of identity document images is significantly more dangerous than the loss of ordinary personal information. It facilitates identity theft, opening credit accounts, or combining with data from previous leaks to conduct targeted fraud. Furthermore, identification images could be used to create fake products with artificial intelligence (AI). Unlike passwords, biometric features like faces are nearly impossible to change. The incident questions how businesses are collecting and storing personal data. In recent years, identity and age verification have become increasingly common in business activities, leading to a concentration of personal information within companies and external service providers. Lee emphasized that businesses must consider data protection a mandatory requirement in identity verification operations. As the volume of collected information grows, ensuring its security becomes an indispensable requirement for each business. In fact, similar data leakage incidents have occurred multiple times in recent years. Experts suggest that individuals find it difficult to fully protect themselves from such incidents, as their data has already been entrusted to organizations for identity verification. Brian Krebs advised individuals to minimize allowing scans and storage of their identification documents unless absolutely necessary. In cases of suspected data leaks, individuals can proactively lock their credit files to prevent identity theft. Meanwhile, the U.S. National Institute of Standards and Technology (NIST) recommends that identity verification service providers collect only the information necessary for a transaction and limit the retention period of personal data. Users should also be clearly informed about how their data is collected, used, and stored. Analysts believe this incident once again highlights that identity data is becoming a particularly attractive target for cybercriminals, underscoring the urgent need for businesses, organizations, and regulatory bodies to tighten the protection of personal information from the point of collection and storage. Source: Nhan Dan

0

Original source

Nhan Dan

原文を読む