메뉴
BL
Ars Technica • 23일 전

렌터카 빌렸더니 몇 시간 만에 내 운전면허증이 다크웹에서 팔렸다

IMP
8/10
핵심 요약

KrebsOnSecurity의 폭로에 따르면 1억 5,300만 개 이상의 신분증·운전면허증 스캔본이 'Nexus'라는 다크웹 신원 도용 서비스에서 판매되고 있다. 렌터카 회사나 대마 판매점 등이 사용하는 제3자 신분증 스캐닝 서비스(IDScan.net 등)에서 실시간으로 데이터가 유출되는 것으로 추정되며, FBI가 수사에 착수했다.

번역된 본문

얼마 전 저는 유명 렌터카 회사에서 SUV를 빌렸습니다. 직원이 제 운전면허증을 스캔한 지 몇 시간 만에, 제 신분증의 고해상도 스캔본이 다크웹에서 판매되고 있었습니다.

화요일 KrebsOnSecurity가 공개한 폭로 기사에 따르면, 제 면허증은 새로운 신원 도용 서비스인 'Nexus'를 통해 판매 가능한 1억 5,300만 개 이상의 신분증 중 하나였습니다. 저널리스트 브라이언 크렙스(Brian Krebs)와 그의 어머니, FBI 국장보, 여러 보안 연구자들의 면허증을 포함해, 그곳에서 판매되는 다른 운전면허증들과 마찬가지로 제 면허증도 신분증 앞면과 뒷면을 보여주는 여러 이미지 파일을 포함하고 있다고 합니다. 기본 이미지 스캔 외에도 이 파일들은 적외선 및 자외선 스펙트럼에서 촬영된 이미지도 담고 있었습니다. 아마도 이러한 추가 포맷은 복제 기반 위조 신분증이 홀로그램 검사를 통과할 수 있게 해줄 것으로 보입니다.

날로 늘어나는 규모

Nexus는 운전면허증 외에도 다양한 다른 형태의 신분증을 판매하겠다고 광고했습니다. 여기에는 다음이 포함됩니다:

  • 신분 확인 카드
  • 여행 카드
  • 국제 운전면허증/신분증
  • 의료 카드
  • 공용 접근 카드(Common Access Card)
  • 거주 카드
  • 취업 허가 문서

크렙스는 FBI가 수사 중이라고 밝혔습니다. 크렙스가 확인한 일부 기록의 '출처(source)'는 'CDL'로 표기되어 있었는데, 이는 '상업용 운전면허증(commercial driver's license)'의 약자로 보입니다. 다른 기록의 출처는 'CAC'로 표기되어 있었는데, 이는 크렙스에 따르면 '정부 건물과 보안 구역에 대한 물리적 접근 권한을 부여하는 정부 발급 신원 카드'인 공용 접근 카드(Common Access Card)를 가리키는 것으로 보입니다.

Nexus는 대마 판매점 카드의 스캔본도 제공한다고 주장했습니다. 크렙스가 인터뷰한 피해자 중 한 명은 여러 주에 걸쳐 체인을 운영하는 대마 판매점인 Planet13의 라스베이거스 매장을 방문한 적이 있다고 말했습니다.

새로운 스캔본이 등록되는 시점—제 경우와 소수의 다른 피해자 샘플의 경우, 렌터카 회사 등에 신분증을 제시한 후 하루 이내, 심지어 몇 시간 만에—을 고려하면, Nexus는 이들 기업이 사용하는 제3자 스캐닝 서비스를 통과하는 데이터에 거의 실시간으로 접근할 수 있는 것으로 보입니다.

24시간 동안 크렙스가 관찰한 바에 따르면, 판매 가능으로 등록된 운전면허증 수가 거의 40만 개 증가했습니다. 이는 침해가 계속 진행 중이며, 새 카드가 수집된 직후 곧바로 등록되고 있다는 또 다른 증거입니다.

크렙스는 공개 정보를 통해 뉴올리언스에 본사를 둔 신분증 스캐닝 서비스 업체 IDScan.net이 Planet13과 독점 계약을 맺었다고 발표한 사실을 발견했습니다. 또한 이 회사는 허츠(Hertz)를 포함한 12개 기업이 자사 서비스를 사용한다고 명시했습니다. IDScan.net은 자사 스캔이 적외선과 자외선 스펙트럼을 모두 캡처한다고 밝혔습니다. IDScan 대표들은 이메일로 보낸 질문에 즉시 답변하지 않았습니다. IDScan.net 대변인은 크렙스에게 회사가 수사 중이라고 말했습니다. 제가 이용한 렌터카 회사 대표들도 즉시 답변하지 않았습니다.

돈을 지불할 의향이 있는 누구나 제 운전면허증을 구할 수 있다는 사실은 결코 유쾌한 생각이 아닙니다. 물론 제 개인정보—현재 및 과거 주소, 사회보장번호, 인구통계 정보 등—는 전 세계 수백만, 아니 수십억 명의 다른 사람들처럼 이전에도 유출된 적이 있습니다. 하지만 이번 덤프는 자외선과 적외선 스캔본까지 포함되어 있다는 점에서 더욱 심각합니다.

다행히 Nexus는 KrebsOnSecurity의 폭로가 나온 지 몇 시간 만에 사이트가 폐쇄되었지만, 이는 사람들이 자신의 신분증이 포함되어 있는지 확인할 방법이 없다는 의미이기도 합니다. FBI의 진행 중인 수사도 어느 정도 위안이 되는 부분입니다.

댄 구딘(Dan Goodin) 수석 보안 에디터. Ars Technica의 수석 보안 에디터로 멀웨어, 컴퓨터 스파이 활동, 봇넷, 하드웨어 해킹, 암호화, 비밀번호 관련 보도를 총괄하고 있다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Not long ago, I rented an SUV from a well-known car rental company. Within hours of an employee scanning my driver’s license, a high-resolution scan of my ID was available for sale on the dark web. An exposé published Tuesday by KrebsOnSecurity reports that my license was one of more than 153 million that were available through Nexus, the name of the new ID theft service. Like other driver’s licenses available there—including some belonging to journalist Brian Krebs, his mother, an FBI assistant director, and several security researchers—my license was purported to include multiple image files showing both the front and back of the ID. Besides a basic image scan, the files also captured the images in the infrared and ultraviolet spectrums. Presumably, the additional formats may allow cloned-based counterfeit IDs to pass hologram tests. Growing by the day Besides advertising the availability of driver’s licenses, Nexus offered to sell a bevy of other forms of ID. They included: Identification cards Travel cards International DL/ID Medical cards Common Access Cards Residence cards Employment authorizations Krebs said the FBI is investigating. Some of the records Krebs observed listed their “source” as “CDL,” which may be short for “commercial driver’s license.” Other records identified the source notation as “CAC,” which may refer to Common Access Cards, which Krebs said are “government issued identity cards that grant physical access to government buildings and secure rooms.” Nexus also claimed to provide scans of marijuana dispensary cards. One of the victims he talked to reported visiting a Las Vegas outlet of Planet13, a multi-state dispensary chain. The timing of newly available scans—typically within a day, if not hours, of me and a small sample of other victims presenting them at rental companies or others—likely means that Nexus has near real-time access to data flowing through the third-party scanning service these businesses are using. Over a span of 24 hours, Krebs said the number of driver’s licenses listed as available grew by almost 400,000. That’s another indication that the breach has been ongoing and new cards become available shortly after they’re harvested. Using publicly available information, Krebs found that IDScan.net , a New Orleans-based ID scanning service, has announced an exclusive arrangement with Planet13. It also listed Hertz and 11 other companies as using its services. IDScan.net went on to say that its scans capture both infrared and ultraviolet spectra. Representatives from IDScan didn’t immediately answer questions sent by email. An IDScan.net spokesperson told Krebs the company is investigating. My car rental company representatives also didn’t immediately answer questions. The availability of my driver’s license to anyone willing to cough up a fee isn’t exactly a comforting thought. Yes, my personal details—including current and former addresses, Social Security number, demographics, and more—have been breached before, just as they have for millions, if not billions, of others around the world. This dump is more troubling because of the purported availability of scans in ultraviolet and infrared. Fortunately, Nexus went dark within hours of the KrebsOnSecurity scoop, although that also means there’s no way for people to check if their IDs are included. Also somewhat consoling is the ongoing investigation by the FBI. Dan Goodin Senior Security Editor Dan Goodin Senior Security Editor Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Dan is based in San Francisco. Follow him at here on Mastodon and here on Bluesky. Contact him on Signal at DanArs.82. 35 Comments