LexisNexis and other large data brokers hacked by underground identity theft service SSNDOB
Data Broker Giants Hacked by ID Theft Service — An identity theft service that sells Social Security numbers, birth records, credit and background reports on millions of Americans …
Context & Ripple Effects
This is the second time in two years that a criminal crew has gone after aggregated personal records rather than end-user accounts — following AntiSec's theft of thousands of personal records in August 2011, the target here is the supply side itself: the brokers whose business is holding Americans' identities at scale.
Krebs on Security's reporting that SSNDOB, an underground service already confirmed as selling Social Security numbers, birth records, and credit and background reports on millions of Americans, had turned those same brokers into its victims traveled unusually widely for a breach story — picked up same-day by InfoWorld, The Register, The Verge, Cisco's blog, Gartner, Securosis, Help Net Security and Digital Trends, signaling how much attention broker-side security now commands.
First-order effects
- LexisNexis and the other named brokers lose control of their core inventory: SSNs, birth records, credit and background reports on millions of Americans flow directly to an active identity theft storefront rather than leaking passively onto forums.
- Consumers whose files sit with these brokers face concrete fraud exposure right now — the compromise hands SSNDOB exactly the data needed to open accounts or impersonate victims, with no consumer action having caused it.
Second-order effects
- Rival data brokers and background-check firms face immediate pressure to re-examine who can query their systems and how credentials are issued, since SSNDOB's method shows an attacker can become a customer-grade user of the pipeline.
- Banks and credit issuers that rely on broker-sourced identity verification inherit a trust problem: if the reference databases themselves are compromised, verification answers stop being reliable signals.
Third-order effects
- If brokers keep proving to be the softest path to mass identity data, the pattern points toward regulatory scrutiny of the largely unregulated data-broker sector and toward treating the SSN-as-authenticator model as structurally broken.
- A durable market may emerge for monitoring and remediation services aimed at broker-originated breaches — identity protection shifting from consumer opt-in product to something institutions buy on consumers' behalf when the custodians themselves fail.
The trend: Identity theft is industrializing by attacking the aggregators that hold everyone's records at once, making data brokers the highest-value targets in the breach economy.