Full Report
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […] The post 14th September – Threat Intelligence Report appeared first on Check Point Research.
Analysis Summary
# Incident Report: Unauthorized Data Access at IDScan.net
## Executive Summary
IDScan.net, a U.S.-based identity verification provider, disclosed a significant data breach following the detection of unauthorized access to its systems. The incident resulted in the exposure of sensitive government identification data, which was subsequently found advertised for sale on a criminal marketplace.
## Incident Details
- **Discovery Date:** September 1, 2026
- **Incident Date:** Ongoing/Discovered September 1, 2026
- **Affected Organization:** IDScan.net
- **Sector:** Technology / Identity Verification
- **Geography:** United States
## Timeline of Events
### Initial Access
- **Date/Time:** Preceding September 1, 2026
- **Vector:** Unauthorized access (Specific entry method not disclosed in brief)
- **Details:** Attackers gained entry to environments housing identity verification data.
### Lateral Movement
- **Details:** Not explicitly disclosed, but attackers moved from initial entry points to databases containing customer identity documents.
### Data Exfiltration/Impact
- **Details:** Attackers successfully exfiltrated a collection containing "millions" of identity documents, including driver’s licenses, names, and government identification numbers.
### Detection & Response
- **How it was discovered:** Internal monitoring detected unauthorized access on September 1.
- **Response actions taken:** The company disclosed the breach and initiated an investigation into the scope of the exposed data.
## Attack Methodology
*Note: Specific technical maneuvers for this incident were not fully detailed in the report summary; the following is based on the disclosed impact.*
- **Initial Access:** Unauthorized access to verification service databases.
- **Collection:** Gathering of government-issued IDs and PII.
- **Exfiltration:** Transfer of millions of documents to external servers.
- **Impact:** Data theft and subsequent sale on criminal marketplaces.
## Impact Assessment
- **Financial:** High potential for regulatory fines (GDPR/CCPA) and litigation.
- **Data Breach:** Millions of identity documents, including driver's licenses and government ID numbers.
- **Operational:** Disruption to verification service integrity.
- **Reputational:** High; loss of trust in a provider specifically tasked with securing identity data.
## Indicators of Compromise
- **Behavioral indicators:** Unusual database query patterns; unauthorized access from unrecognized IP addresses; presence of data for sale on illicit marketplaces.
## Response Actions
- **Containment measures:** Disclosed unauthorized access was identified and addressed.
- **Recovery actions:** Identification of affected individuals and disclosure to relevant authorities.
## Lessons Learned
- **Third-Party Risk:** Providers handling sensitive PII are Tier-1 targets; their compromise has a massive downstream impact on their clients.
- **Marketplace Monitoring:** The appearance of data on criminal marketplaces often serves as a secondary confirmation of the breach's severity.
## Recommendations
- **Encryption at Rest:** Ensure all stored identity documents are encrypted with robust key management.
- **Zero Trust Architecture:** Implement strict identity and access management (IAM) to ensure that even if one credential is stolen, access to the entire ID database is restricted.
- **Database Activity Monitoring (DAM):** Deploy tools to alert on bulk data exports or unusual query volumes.
---
# Secondary Incident Brief: Mathspace CVE Exploitation
## Incident Details
- **Affected Organization:** Mathspace
- **Vector:** Exploitation of CVE-2026-72898 (Metabase SQL Injection)
- **Impact:** Exposure of 1 million records (names, emails, locations)
- **Response:** Check Point IPS provides protection against this specific Metabase threat.
# Secondary Incident Brief: Revolut Social Engineering
## Incident Details
- **Affected Organization:** Revolut
- **Vector:** Business Email Compromise (BEC) / Fraudulent Government Request
- **Technique:** Attackers used a legitimate government domain to send fraudulent information requests.
- **Impact:** Exposure of KYC (Know Your Customer) data, including selfies, IBANs, and transaction histories.