🚨 IDSCAN.NET OFFICIALLY CONFIRMS DATA BREACH — GOVERNMENT ID INFORMATION POTENTIALLY EXPOSED
IDScan.net has officially confirmed a cybersecurity incident involving unauthorized access to information stored in its cloud environment.
The identity verification company says it received information around September 1 indicating that certain data may have been accessed without authorization.
IDScan subsequently launched an investigation and engaged third-party cybersecurity specialists.
The company has now determined that an unauthorized third party may have accessed and/or COPIED customer information stored within customer accounts on the IDScan.net cloud.
Potentially affected information includes:
* Full names
* Driver's license numbers
* Other government-issued identification numbers
IDScan says it has taken steps to secure its systems and currently has no evidence of ongoing unauthorized access.
Potentially affected records are those that entered its systems BEFORE September 1, 2026.
The company is reviewing the affected information to identify impacted individuals and says it will provide notifications and free credit-monitoring services where appropriate.
🚨 WHAT ABOUT THE REPORTED 153 MILLION DRIVER'S LICENSES?
This is an important distinction.
Earlier reporting linked IDScan.net to a massive dark-web dataset advertised through the Nexus marketplace, reportedly containing approximately 153 million driver's-license records and millions of other identity documents.
IDScan's new disclosure confirms unauthorized access to its cloud environment and potential copying of government-ID information.
However, IDScan has NOT confirmed that 153 million figure as the number of people or records affected.
The full scope of the incident remains under investigation.
⚠️ Analyst Note:
This is an unusually sensitive category of breach.
Passwords can be changed.
Payment cards can be replaced.
Government-issued identity information is substantially more difficult to remediate once compromised.
And identity-verification providers inherently represent high-value aggregation points because their platforms may process identity documents on behalf of many different organizations.
For defenders, this incident raises a broader supply-chain question:
How long should identity-verification providers retain the documents and identity attributes they process after verification is complete?
Data that no longer needs to exist cannot later become breach inventory.
Official source — IDScan.net:
idscan.net/press-release/…#DDW#IDScan#DataBreach#IdentityTheft#CyberSecurity
AI is moving beyond chatbots.
The next wave is agentic: AI agents that can take action on behalf of users through trusted delegation. But scaling that innovation across the enterprise requires more than excitement—it requires control, security and visibility.
Jeetu Patel and DJ Sampath explore the shift from chatbots to agents and how Cisco Cloud Control is helping enterprises manage AI innovation with confidence.
Watch their full conversation: cs.co/6010B17ZYO
China-based AI companies are illicitly distilling U.S. frontier AI capabilities. Read NSA’s new report, co-sealed with @FBI, @CISAgov, highlighting AI knowledge distillation, TTPs used, and recommended mitigations: media.defense.gov/2026/Sep/08/20…
Several major AI services experienced outages yesterday, with disruptions affecting users across multiple regions.
ChatGPT, Claude, Grok, Gemini, Cursor and others all saw spikes in reports on Downdetector. ChatGPT received more than 340,000 reports globally, marking its largest outage by Downdetector report volume in more than a year.
ATF is aware of claims concerning the possible publication of data allegedly obtained during the previously disclosed cybersecurity incident involving a standalone system used in connection with CALEA. We are working with @TheJusticeDept and other federal partners to assess these claims and take appropriate actions. As stated previously, the affected system was separate from ATF’s enterprise network. ATF has not confirmed the authenticity, nature, or scope of the materials at issue.
More at atf.gov/news/press-rel….
Today, the @FBI and @TheJusticeDept announced the disruption of a global botnet used by Chinese state-sponsored group known as QTFY to target U.S. critical infrastructure.
Our investigation attributes QTFY to the Nanjing Xinjiuwei Network Technology Company, which sells stolen data and hacking services to Chinese military and intelligence agencies. Their services include a scanning platform that scours the internet for vulnerable smart devices—like home routers and security cameras—infects thousands of them, and feeds them into a botnet, or a network of machines secretly controlled by the adversary.
These platforms hide the origin of PRC-linked cyberattacks. Thanks to the work of @FBISanDiego, FBI Cyber Division, and partners at DOJ—we shut those platforms down 🔗justice.gov/opa/pr/justice…
🚨🇨🇳 FBI knocks China-linked QScan and QTRouter hacking infrastructure offline
The DOJ and FBI seized domains powering two hacking platforms operated by QTFY, a Chinese state-sponsored group tied to Nanjing Xinjiuwei Network Technology Company.
U.S. officials say QTFY has compromised or targeted sensitive networks including NASA, the Federal Reserve, Department of Energy, DOJ, HHS, NIH, and the U.S. Senate.
QScan automatically scans for and infects thousands of IoT devices worldwide.
Those compromised devices are then incorporated into QTRouter, an obfuscation network combining hacked IoT devices, commercial proxies, and leased VPS infrastructure to hide the China-based origin of intrusion activity.
Court documents say QTFY sells hacking services to paying customers including China's Ministry of State Security and People's Liberation Army.
Because the seized domains were hard-coded into QScan and QTRouter for authentication and communications, the FBI says the operation rendered both platforms inoperable.
The infrastructure has been linked to malicious activity dating back to at least 2018.
Seized: qtproxy[.]xyz
Source: justice.gov/opa/pr/justice…
🚨We are seeing increased targeting of PLCs in the Water and Wastewater Systems Sector. Owners, operators, & integrators should disconnect PLCs & internet-exposed OT assets ASAP to reduce risk of disruptions, configuration changes, & physical damage. 🔗 go.dhs.gov/5sC
🚨 🏛️ 🇺🇸 CYBER INTELLIGENCE ALERT / ALLEGED DATABASE COMPROMISE — GOVERNMENT AND PUBLIC SAFETY SECTOR (USA)
[STATUS: ALLEGED DATA LEAK / UNCONFIRMED / SOURCE: CLANDESTINE CHANNEL (MIRROR OF DARKNESS) / DATE: JULY 10, 2026]
THE "NEMORISHACKING" ACTOR CLAIMS DATA EXFILTRATION FROM YELLOWSTONE COUNTY, MONTANA, BY SPREADING FILES LINKED TO THE JUVENILE SERVICES CENTER
Through technical monitoring of criminal dissemination channels and data leak forums, a post has been intercepted that allegedly compromises the confidentiality of local computer systems in North America. The threat actor using the alias NemorisHacking, operating within the clandestine channel "Espejo De La Oscuridad" (Mirror of Darkness), has announced the alleged exfiltration of databases belonging to the government infrastructure of Yellowstone County, Montana (yellowstonecountymt.gov).
As a proof of concept (PoC), the attacker has published two structured .json files that directly reference the Yellowstone Youth Service Center.
🏢 Allegedly Affected Entity: Yellowstone County Government, Montana, United States (including, indirectly, portals indexed to the local Sheriff's Office).
👤 Threat Actor: NemorisHacking.
⚔️ Volume and Files Compromised According to the Announcement: Two logical extracts named Yellowstone_Youth_Service_Center_-_MT.json and Yellowstone_Youth_Service_Center_-_2MT.json, each with a size of 242.4 KB.
🔍 Verification Status: UNCONFIRMED BY US LOCAL OR FEDERAL AUTHORITIES. As of July 10, 2026, the Yellowstone County Administration, the Sheriff's Office, or CISA have not issued any official statements acknowledging an intrusion into their servers or a loss of control over their databases. This event should be handled under the strict status of SUSPECTED COMPROMISE.
🛡️ PREVENTIVE TECHNICAL RECOMMENDATIONS FOR CONTAINMENT (SOC / PERIMETER DEFENSE)
Information security officers for local government portals are urged to implement immediate hardening controls:
🛑 Database and API Endpoint Query Audit: Conduct a forensic investigation of database server and management system logs at the Youth Service Center to detect anomalous spikes in data exports or massive queries that match the size of JSON files published in the last week.
🔑 Repository and Backup Configuration Review: Verify that institutional API endpoints or cloud storage buckets are not publicly exposed without authentication, and immediately revoke outdated passwords and API keys.
📊 MONITORING AND EVALUATION OF GOVERNMENT INFRASTRUCTURE
Intelligence System: analyzer.vecert.io
Monitoring Console: monitor.vecert.io#CyberSecurity#USA#Montana#YellowstoneCounty#DataLeak#YouthServiceCenter#JSONExposure#GovBreach#SheriffOffice#NemorisHacking#ThreatIntelligence#CyberAlert#VECERT#Infosec#UnverifiedIncident
Xbox CEO Asha Sharma is now an official advisor for the U.S. Federal Reserve.
She's leading a task force to address employment and productivity in the U.S. and will directly influence government decisions.
33K Followers 385 FollowingResearch and development arm of the Department of Homeland Security. Likes, retweets, etc. ≠ endorsement. Comment Policy: https://t.co/HQr5xUZMhy
21K Followers 2K FollowingDelivering the latest in #cybersecurity news, trends, insights, and top #infosec blogs for the cybersecurity community. Stay informed, stay secure!
4K Followers 1K FollowingISMG is a global leader in cybersecurity education, intelligence and research with 38 media properties focused on #cybersecurity news.
28K Followers 201 FollowingSecurity magazine is designed and written for business-minded executives who manage enterprise risk and security. https://t.co/oa59C5wGbc
423K Followers 49 FollowingTypeScript is a language for application-scale JavaScript development. It's a typed superset of JavaScript that compiles to plain JavaScript.
14K Followers 240 FollowingA random infosec/science enthusiast guy...
This account is personal and only reflects my opinions, not those of my employer...and if it hurts your feelings🖕
48K Followers 0 FollowingDarkFeed: Cyber Threat Intelligence Platform, Putting things at order in the ransomware crazy world
#OSINT | #Ransomware | #Cyberattacks | #Hacktivism
33K Followers 1K FollowingSharing the latest tech news, tips and in-depth insights, covering AI, cloud, cybersecurity, DevOps and more from the Editorial team at @InformaTTGT!
11K Followers 573 FollowingShadow Chaser Group is a sub-group of the GcowSec team which consists of college students who love it.Shadow Chaser Group focused on APT hunt and analysis
62K Followers 1K FollowingSecurity information portal, testing and certification body.
Organisers of the annual Virus Bulletin conference. @[email protected]
170K Followers 192 FollowingLinux and Open Source Web Portal 🐧
Follow us to
- Get the latest Linux and Open Source news 📰
- Learn Linux tips and tutorials 💡
- Enjoy Linux memes 🤣
6K Followers 309 FollowingThe JFrog Security Research Team empowers developers and companies to excel by identifying, prioritizing, and mitigating software risks.
187K Followers 1K FollowingThe National Cybersecurity Alliance is a nonprofit that empowers people to use technology safely & securely. Co-leads Cybersecurity Awareness Month
343K Followers 3K FollowingHackerOne makes security continuous.
We unite AI and human insight through a unified platform to expose risk and eliminate it.
72K Followers 401 FollowingProving that cybersecurity is everyone's business. We research what others skip, expose what's buried, and know that the real story is never on the surface.
195K Followers 412 FollowingSANS is the most trusted and by far the largest source for information & cyber security training, certification and research in the world.
69K Followers 2 FollowingThis is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD