1525 stories
·
0 followers

My driver's license is one of 153 million for sale on a new dark website

1 Share

Not long ago, I rented an SUV from a well-known car rental company. Within hours of an employee scanning my driver's license, a high-resolution scan of my ID was available for sale on the dark web.

An exposé published Tuesday by KrebsOnSecurity reports that my license was one of more than 153 million that were available through Nexus, the name of the new ID theft service. Like other driver's licenses available there—including some belonging to journalist Brian Krebs, his mother, an FBI assistant director, and several security researchers—my license was purported to include multiple image files showing both the front and back of the ID. Besides a basic image scan, the files also captured the images in the infrared and ultraviolet spectrums. Presumably, the additional formats may allow cloned-based counterfeit IDs to pass hologram tests.

Growing by the day

Besides advertising the availability of driver's licenses, Nexus offered to sell a bevy of other forms of ID. They included:

  • identification cards
  • travel cards
  • international DL/ID
  • medical cards
  • common access cards
  • residence cards
  • employment authorizations

Krebs said the FBI is investigating.

Some of the records Krebs observed listed their “source” as “CDL,” which may be short for “commercial drivers license.” Other records identified the source notation as “CAC,” which may refer to Common Access Cards, which Krebs said are “government issued identity cards that grant physical access to government buildings and secure rooms.” Nexus also claimed to provide scans of marijuana dispensary cards. One of the victims he talked to reported visiting a Las Vegas outlet of Planet13, a multi-state dispensary chain.

The timing of newly available scans—typically within a day if not hours of me and a small sample of other victims presenting them at rental companies or others—likely means that Nexus has near real-time access to data flowing through the third-party scanning service these businesses are using. Over a span of 24 hours, Krebs said the number of driver's licenses listed as available grew by almost 400,000. That’s another indication the breach has been ongoing and new cards become available shortly after they’re harvested.

Using publicly available information, Krebs found that IDScan.net, a New Orleans-based ID scanning service, has announced an exclusive arrangement with Planet13. It also listed Hertz and 11 other companies as using its services. IDScan.net went on to say that its scans capture both infrared and ultraviolet spectra. The information suggests that the scanning service is connected to the breach.

Representatives from IDScan didn’t immediately answer questions sent by email. An IDScan.net spokesperson told Krebs the company is investigating. My car rental company representatives also didn't immediately answer questions.

The availability of my driver's license to anyone willing to cough up a fee isn’t exactly a comforting thought. Yes, my personal details—including current and former addresses, Social Security number, demographics, and more—have been breached before, just as they have for millions, if not billions, of others around the world. This dump is more troubling because of the purported availability of scans in ultraviolet and infrared. Fortunately, Nexus went dark within hours of the KrebsOnSecurity scoop. Also somewhat consoling is the ongoing investigation by the FBI.

Read full article

Comments



Read the whole story
Share this story
Delete

I asked 100 companies for my data. Some deleted it instead.

1 Share

I filed a request with McDonald’s earlier this month to access all of the personal data the fast food company collected about me, and I received a stunning 515-page report a few days later that detailed my app interactions in granular detail and predicted I would never stop eating there.

Under the California Consumer Privacy Act, I have the legal right to request access to information from large companies that collect personal data. So I was curious what others might have on me, and I spent the next week filing more than 100 requests.

The CCPA went into effect in 2020, and three of its key provisions are the right to opt out of the selling of personal information, the right to delete that info, and the right to request a copy for yourself.

I focused solely on the latter—access requests—to better understand what data is being collected. Most companies must list two ways for you to file. These are often via a web form, phone number, or email address, as designated in their privacy policy. After you submit a request, companies can take 45 days to complete it.

My experience placing these data access requests was incredibly time-consuming, from finding the right filing methods to verifying my identity multiple times. Most exasperating during this process were the companies that either responded to my access requests with messages concerning the deletion of information, which I explicitly said not to do, or refused to process the request through a method listed in their privacy policy.

Consumer advocates I spoke with were upset with how these requests were handled. “That's crazy,” said Ben Winters, director of AI and privacy at the Consumer Federation of America. “That's not an acceptable status quo.” Winters sees these examples as exhibiting the weaknesses of policy frameworks that rely on companies to act responsibly and in good faith.

In accordance with WIRED’s policies, I am disclosing that I used generative AI to draft bureaucratic emails and update my tracking spreadsheet as part of this report. I wrote the body of this article mainly by hand in my scratch notebook.

One of the first errors came from Crunchbase, known for its database about tech startups. I emailed my access request to its privacy address on August 17. My message laid out the rights I wanted to exercise and included a direct request not to erase anything: “I am not requesting deletion at this time. Please do not treat this as a deletion request.” I received a reply two days later from a Crunchbase support representative.

“Thanks so much for your patience. Your account has been permanently deleted from Crunchbase. Please let me know if you need anything else!” the message read in full.

I followed up via email almost immediately, reiterating that I wanted data access, not data deletion. “Your Crunchbase user account was deleted. Other data located on Crunchbase was not deleted,” read the follow-up support response explaining what happened. If I wanted to have a Crunchbase account, I would have to reregister.

When I reached out to Crunchbase for comment, a spokesperson blamed the mistake on a “processing error” and said that the company would proceed with my original access request as filed. The spokesperson also claimed the misclassified response came from “a person on our customer success team” and not a generative AI tool.

My interactions with BeenVerified, a searchable database that gathers public records, also encapsulate my friction-filled experience placing these access requests.

I emailed BeenVerified’s dedicated CCPA compliance address on the morning of August 19. It laid out that I was a California resident placing an access request, not a deletion request. You’ll never guess what happened next.

Two days later, I received a message from a BeenVerified support representative about removing information. “It appears your person report has already been removed from our Person Search results,” read its initial response. “In addition, we have removed the requested phone number and email address from our search results. This change should be reflected within 24 hours.” Not at all what I asked it to do.

When I sent my next email explaining that I had submitted an access request, not a deletion request, the support representative followed up 15 minutes later, denying my claim and saying the company couldn’t verify my identity. That was perplexing, since it located some of my details earlier in the message thread and didn’t even attempt to explain what I might need to share for verification.

At my wit's end, I sent another email explaining how confused I was feeling by these responses. “Please be assured that we're able to process your opt-out request and have removed your information from our website,” read the support representative's response. If I wasn’t already bald, I would have pulled out the rest of my hair at that moment.

I found solace in chatting with an academic researcher who had previously helped place access requests with over 500 data brokers under the same California law and also encountered multiple misclassifications. “Sometimes I would make an access request, and the automatic answer was ‘We will opt you out’ or ‘We will delete your data,’” says Elina van Kempen, a PhD student at UC Irvine and coauthor of Consumer Beware! Exploring Data Brokers' CCPA Compliance. While some data brokers followed up with corrections, other times the researcher was left without any resolution.

When I reached out to BeenVerified for comment, Greg Hammond, senior counsel and senior director of compliance at its parent company, claimed via email that support agents receive annual privacy training, including how to process CCPA requests. “Unfortunately, despite the training, the agent who handled this matter was mistaken and misunderstood the request type,” he wrote. Hammond says the company now plans to provide refresher training on correct processing and to audit recent work.

My attempts to place an access request with Cash App, a money-sending service offered by Block, were equally frustrating, even without a deletion mistake. The company’s privacy policy, in bold, states that California residents can place access requests through Cash App’s website or by a toll-free phone call. I opted to test out the phone number.

The first time I called and explained that I was a California resident who wanted to place an access request, it was as if I had started speaking in a language from outer space. I was placed on hold multiple times before being told to check the privacy policy and call the number listed there, which I had just done to get to this point. My attempt to process an access request over the phone was being effectively denied.

“OK, sure, I'll call this number right back,” I said before I hung up, a bit of anger bubbling up in my voice despite my best efforts to remain professional. My interactions with the next customer support agent were similarly burdensome. After being put on hold, I was asked to call back later so the support team would have more time to review their resources and understand how to handle my call.

“Customers can access or delete their personal information directly through Cash App, which allows us to more quickly verify identity before providing access to financial account information or deleting an account,” a Cash App spokesperson wrote over email when I reached out for comment. “Our phone support teams are trained to help customers understand how to submit these requests, and we also provide customers with instructions they can access through our online Help Center."

The spokesperson did not respond to follow-up questions asking why the phone number was explicitly listed in Cash App’s privacy policy as a way for consumers to exercise their data rights.

Experts I spoke with questioned whether companies are putting in enough effort to be legally compliant. “It shows how potentially little resources the companies are putting toward compliance and making sure that people can have access to their data,” says Mayu Tobin-Miyaji, a law fellow at the Electronic Privacy Information Center.

Both Winters and Tobin-Miyaji mentioned a beefed-up approach to “data minimization” as a potential better path forward for consumers. This would essentially mean companies can collect only the data they need to process standard business operations. For example, saving your credit card information in the app for future purchases might be allowed, but collecting personal demographic information to sell to brokers might be blocked.

Data minimization is a more holistic approach that shifts the burden away from consumers, who are currently forced to navigate a bureaucratic obstacle course just to see what companies know about them. Instead, by limiting what companies can collect about you in the first place, consumers can have more peace of mind without going through the headache-inducing process I endured.

This story originally appeared on wired.com.

Read full article

Comments



Read the whole story
Share this story
Delete

FBI Probes Service Selling 153M+ Drivers Licenses

1 Share

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

A record available at this identity theft service that includes the drivers license for U.S. Defense Secretary Pete Hegseth, one of several high-ranking U.S. government officials whose drivers licenses can be found for sale.

On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.

The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.

A quick look around Nexus finds they are likely not exaggerating about that 153 million number: Running a blank search in Nexus (with no search parameters entered) returns approximately 11.5 million pages of results, with roughly 15 results displayed per page. It includes documents from people in both Canada and the United States, but the bulk of these records are on Americans: searching for just Canadian drivers licenses returns approximately 1.1 million results, with the largest concentration from Ontario (473,673 records).

Curiously, the identity records include not only drivers licenses but also marijuana dispensary cards. Some of the records list their “source” as “CDL,” presumably short for “commercial drivers license.” Other records carry the source notation of “CAC,” which may refer to Common Access Cards, government issued identity cards that grant physical access to government buildings and secure rooms.

The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.

The record totals listed by the Nexus identity theft service. The number of drivers license records increased by nearly 400,000 in the span of just 24 hours.

“We have been continuously exfiltrating new data for over a year into our private database,” the service enthused in its introductory post on Exploit. “Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available.”

Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.

The record that features my drivers license includes six image files — three pairs of photos of the license’s front and back — a basic image scan — as well as infrared and ultraviolet versions of the same images. A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the midwest United States to attend a family funeral.

Some of the 153 million+ license scans — including mine — feature six image files with date and timestamps appended to the filenames. Not all records include photos, and some that do feature photos do not display the associated filenames.

Intent on discovering the source of this data, KrebsOnSecurity asked more than a dozen friends and family members for permission to search for their licenses in this service. Each person whose license could be found (nine of them) confirmed having traveled on or very close to the dates in the timestamps attached to their images. It is unclear what timezone these timestamps are in, but from reviewing car rental records shared by several people who helped with this research, it appears the timezone is set to Greenwich Mean Time (GMT).

At first, I thought the source of the data might have something to do with airports. However, that theory went out the window when it became apparent there were no passports in this data set. Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel. One person whose license was in Nexus hadn’t flown at all recently, but was renting a car from Hertz for several months around the date of their timestamp.

Two of those who agreed to help are federal employees who said they shared other forms of government identification when passing through airport security. However, those individuals each said they shared their state-issued drivers licenses later that day when renting vehicles at their respective destinations, and that both rented their cars from Hertz.

After finding a note in my calendar for the day of my June 2025 flight reminding me to bring my passport, I remembered that I also never actually shared my drivers license when I went through security at Reagan National Airport on that day because I did not yet have a Real ID, a security-enhanced drivers license that is now required by the Transportation Security Administration (TSA) for all domestic travel. Instead, I showed the TSA agent my government-issued U.S. passport.

Here’s where it gets interesting: I was able to find my mother’s drivers license in this service as well, and the timestamps for her images are just a few seconds apart from mine. That’s notable because we both handed our licenses to the Hertz rental car representative at the same time.

According to my mom, the only place she gave her drivers license to that day was the rental car company, and if memory serves that is also true for me. I don’t recall if the rental car representative inserted our licenses into any kind of machine, but I remember they held onto them for several minutes behind the counter while we were signing various forms. KrebsOnSecurity sought comment from Hertz and will update this story in the event they reply.

Zach Edwards is a well-known security and privacy researcher who recently launched a service called DecryptAds to help people better understand how online advertisers are tracking them. A scan of Edwards’s drivers license is available for purchase on this identity theft service, and Edwards said the timestamp on his record corresponds to the middle of a trip last month to Las Vegas for the annual DEFCON security conference.

Edwards told KrebsOnSecurity that although he did not rent a car in Vegas, he did hand over his license at the TSA checkpoint, at a marijuana dispensary in Vegas, and at his hotel (the Aria). But he said the only one of those three that for sure scanned his ID in some kind of device was the dispensary.

To enter Planet13’s weed dispensary in Las Vegas, one must pass through a red telephone booth. Image: Zach Edwards.

Edwards said the dispensary he visited that day was Planet13, a multi-state chain with stores in California, Florida, Illinois and Nevada. In 2022, the New Orleans-based identity provider idscan.net published a press release announcing an exclusive identity verification agreement with Planet13’s dispensaries nationally. IDScan says it processes ID verification for more than 1,000 marijuana dispensaries in 19 U.S. states.

The “trust” page of idscan.net states that the company provides identity verification services for numerous big brands, including Hertz, Target, Fedex, Motorola Solutions, the financial services giant Jack Henry, and Caesars Entertainment. And as idscan.net’s own documentation states, the technology scans IDs with both infrared and ultraviolet light. Idscan.net says the company’s systems and technology perform more than 21 million verifications monthly, at more than 20,000 locations around the world.

Image: idscan.net.

Contacted by KrebsOnSecurity, idscan.net said it was investigating the matter, but the company has not yet shared an official statement or a substantive reply to specific questions sent via email.

“At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” wrote Jillian Kossman, a marketing and operations leader at idscan.net.

During the course of my research for this story, word got around to the FBI that I was poking at the apparent source of this new identity theft service’s data. Probably they were tipped off when I shared with a trusted source that Nexus also is selling the drivers license information for the assistant director of the FBI (I did not find FBI Director Kash Patel’s license in Nexus).

Earlier this afternoon, I was added to a conference call with a half-dozen FBI agents, including senior leaders from the agency’s cyber division. During that call, the FBI shared that earlier today their New Orleans field office opened an official investigation into an apparent breach involving idscan.net.

Edwards said that as more in-person and online experiences require sharing drivers licenses, vendors who collect this sensitive data need to be held to a higher standard.

“This episode should further strengthen the resolve for people who are fighting back against online ID schemes which are requiring countless providers to ask for drivers licenses in order to access services under the guise of protecting kids,” Edwards told KrebsOnSecurity. “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.”

Larry Baldwin is principal intelligence researcher at the cybersecurity firm Cybera. Baldwin said a front and back scan of his drivers license available at Nexus contains timestamps that correspond to the date of a car rental from Hertz on a recent vacation.

Baldwin said the Nexus identity theft service presents multiple serious security and privacy threats, noting that state-issued drivers licenses are commonly used as proof of one’s identity when opening new lines of credit. Baldwin said the service could also dangerously expose many people who do not wish to be found but who cannot meaningfully change their appearance (or at least not enough to fool today’s AI-based image matching tools).

This category of people, he said, includes those fleeing domestic violence, and even people who have been assigned a whole new life and identity as part of the federal government’s witness protection program, which is generally reserved for criminal defendants in racketeering and conspiracy investigations who agree to cooperate with federal authorities.

“Just when it seems like we’re making some headway in improving authentication controls through drivers license verification systems, this happens and the very thing those improvements are dependent on are compromised,” Baldwin said.

Update, 8:56 p.m. ET: Shortly after this story was published, the Nexus identity theft service website vanished from the darkweb, replacing its login page with a plain text message that reads, “This service is no longer available.”

This is a potentially fast-moving story. Any changes or updates will be noted here along with a timestamp.

Read the whole story
Share this story
Delete

The TV vs projector value debate isn't close — here's why

1 Share

If you want the largest image for the least amount of money, a projector is the only choice.

Read the whole story
Share this story
Delete

Dismantling the Roadless Rule threatens to disrupt wildlife and water in US

1 Share

Pause for a moment and listen. What do you hear? Chances are, somewhere in the background, is the ever-present hum of a road.

More than 4.2 million miles of public roads crisscross the lower 48 states—enough to reach the Moon and back almost nine times. This vast network of roads spiderwebs its way across the contiguous US, leaving only about 5 percent as an inventoried roadless area or wilderness.

Now, some of those last remaining lands free of roads are under threat from the Trump administration’s proposed rollback of the 2001 Roadless Rule. That includes southeast Alaska’s Tongass National Forest, where eagles, bears, salmon, and many other species thrive in old-growth coastal forest along the Inside Passage.

In announcing its plan, the administration said rescinding the rule would remove prohibitions on road construction and logging on nearly 59 million acres of national forest, arguing that the rule slowed economic development. A 30-day public comment period on the formal proposal starts once it is published in the Federal Register. Instructions on how to submit comments are included in the proposal.

In Congress, another effort is underway to try to change the law through an amendment to the Wildfire Prevention Act. That change, if approved, would both remove the Roadless Rule and prevent the US Forest Service from reinstituting it in the future, despite overwhelming public support for the rule.

As ecologists who have spent decades studying wilderness and the animals and ecological functions that depend on undisturbed habitats, we believe it’s important to understand that preserving roadless areas has value for environmental health, clean water, wildlife survival and people’s own well-being.

What is the Roadless Rule?

The National Forest Roadless Area Conservation Policy, better known as the Roadless Rule, was issued in January 2001 by President Bill Clinton. It has had overwhelming public support and received more public comments than any other rule in history.

The rule prohibits road construction, maintenance and commercial timber harvest in inventoried roadless areas within the National Forest System. It applies to over 58 million acres across the country, excluding Idaho and Colorado, which have their own state-specific roadless rules. While most of these roadless areas are in the western states and Alaska, 38 total states as well as Puerto Rico host roadless areas.

The nation’s inventoried roadless areas are primarily in the western US and include large parts of southeast Alaska, where 14,779,000 acres of roadless areas are within National Forest System land. Credit: US Forest Service Enterprise Map Services Program

The primary goal of the Roadless Rule is to maintain forest health and productivity for future generations. It also helps avoid exacerbating the US Forest Service’s road maintenance backlog by not making new roads.

The Roadless Rule prohibits new road construction, with very limited exceptions, as well as commercial logging in designated roadless areas. It does not restrict other uses that are compatible with the management plan, such as hiking and mountain biking, or resource uses such as grazing livestock and working existing mining claims.

Beyond providing vital habitat for species and enabling healthy forests, the rule protects drinking water for the millions of Americans whose water flows from national forests. It also preserves high-quality recreation opportunities—hiking, camping, hunting, and fishing—that Americans cherish.

The problem with roads in national forests

While roads can provide benefits, such as access to forests, they can also do ecological harm.

Roads enable invasive weeds to spread by being carried on vehicle tires and deposited in exposed soils, erode sediments into streams and fragment habitat that wildlife rely on. Vehicles directly kill and injure animals through collisions. They occasionally start fires, too. A recent study found that fires are more likely to start in areas with roads than in areas without.

Studies show that road noise displaces wildlife, increases stress, and can affect wildlife behavior patterns at distances of over a mile from the road.

And roads don’t just cause problems for species on land. Most roads cross streams and rivers, which requires building a way for those waters to keep flowing under the road (structures called culverts). While culverts can be designed to allow fish to pass through and maintain ecological connections, they are rarely built to do so. This leads to declines in the health of fish populations and can leave some species locally extinct.

The benefits of roadless areas

Inventoried roadless areas are among the most ecologically intact and wildest places left in the United States, yet—unlike Wilderness Areas and National Parks—there are no signs acknowledging their boundaries when you enter one.

Most are part of larger ecosystems, directly adjacent or ecologically connected to better known national parks and wilderness areas. Removing Roadless Rule protections would erode ecological buffers to these more famous protected lands.

For some species, roadless areas protect critical core habitat. For instance, over half the suitable habitat for relictual slender salamander, a critically imperiled species native to the Sierra Mountains of California, occurs in a roadless area. Nearly 40 percent of Mount Pinos, lodgepole chipmunk, an imperiled subspecies of the lodgepole chipmunk, also live in roadless areas in California.

Research shows that every formal roadless area provides habitat for at least two wildlife species of conservation concern – those facing risks to their long-term survival – with the median roadless area supporting 10 of these imperiled species. Some Arizona roadless areas contain habitat for up to 62 of these species.

Roadless areas also protect watersheds that supply drinking water to 47 million Americans.

Without this protection, these watersheds would still provide water, but their long-term health and hydrological sustainability could be compromised if roads block stream flow and increase sediments flowing into waterways. The result can be higher costs for water purification.

The Forest Service’s own watershed health assessment, known as the Watershed Condition Framework, uses road density as a key indicator of conditions that can disrupt water quantity and quality.

What is at risk in rescinding the Roadless Rule?

The Trump administration’s proposed rollback, expected to be formalized in 2026, would open these last wild places to development, fragmenting habitats that can never be restored.

The American public spoke loudly in 2001 when they supported the Roadless Rule. Two decades later, the public comments submitted on the rescission notice overwhelming opposed rolling back the rules, a Center for Western Priorities review found, reaffirming that US roadless forests remain as vital and valued as ever.

Protecting these areas is about promoting healthy ecosystems on public lands so they can provide hiking, hunting, and fishing opportunities for generations to come to enjoy the tranquility of being in nature.

Mariah Meek, Associate Professor of Integrative Biology, Michigan State University and Travis Belote, Assistant Professor of Landscape Ecology, Montana State University. This article is republished from The Conversation under a Creative Commons license. Read the original article.

Read full article

Comments



Read the whole story
Share this story
Delete

CDC reported then deleted two measles deaths that were questioned by RFK Jr.

1 Share

The Centers for Disease Control and Prevention is excluding two measles deaths reported by Pennsylvania health officials last week from its latest update of national measles data, publicly challenging the accuracy of the state's death determinations in an extraordinary move that breaks precedent that states are the arbiters of case and death determinations, not the CDC.

The New York Times reported Monday that the CDC's new director, Erica Schwartz, is behind the decision. Schwartz—less than a month into the job—reportedly ordered CDC staff to add an unusual statement onto the CDC's website for measles surveillance data. The statement notes that the update will not include the deaths reported by Pennsylvania and continues: "At this time, available information does not establish whether measles caused or contributed to the deaths or whether the individuals died from other causes while infected with measles."

The Washington Post reported Monday that the CDC had actually changed the information provided on that page multiple times over the weekend. On Saturday, August 29, at 2:33 pm ET, the website listed the total measles deaths for 2026 as "0" in a chart. On Sunday, August 30 at 12:09 pm ET, the chart was updated to list the total deaths for 2026 as "2." There was also a note underneath the chart that read: "Health departments make determinations about measles-associated deaths and share relevant information with CDC." By the 3:23 pm ET Sunday, the chart was changed again to delete the two deaths, replacing it with an asterisk as a reference to the unusual statement about the deaths not being included. The asterisk and statement remain as of Tuesday.

The move comes after anti-vaccine Health Secretary Robert F. Kennedy Jr. got into a public spat with Pennsylvania Governor Josh Shapiro over Kennedy's anti-vaccine rhetoric. Kennedy then shared measles misinformation on social media amid news of the deaths, then suggested without evidence that the state may have "fabricated" the deaths and that the governor announced them with "giddy delight."

State health officials initially refused to release information about the two people who died, including their ages, citing privacy concerns. But news has since trickled out that one of the people who died was a newborn and, according to reporting Tuesday by the Times, the other was a child. Both were unvaccinated and from Lancaster County. Outside medical experts have criticized the lack of information provided from health officials, leaving more space for doubt and misinformation.

What we know about the deaths

Controversy about the deaths flared after Lancaster County Coroner Stephen Diamantoni, a Republican first elected coroner in 2007, claimed that a pathologist determined that the newborn died of a ruptured spleen and didn't believe measles played a role. The baby was born infected with the virus, according to testing, and had evidence of a measles infection in lung tissue. The newborn's mother was severely ill from measles at the time of birth, according to reporting from The Atlantic, which spoke with the baby's parents amid the uproar.

The parents, who are Amish, were not aware that their baby's death was in the national news and a source of contention. They believed without question that their baby died of measles. The mother said she contracted the virus amid the ongoing local outbreak and after several of her other children had fallen ill. She became so ill she couldn't speak above a whisper and "didn’t have a single piece of energy" as she went into labor. The baby was born with a pulse, but was not breathing. The baby, a boy, was declared dead less than a half-hour later, after paramedics had been called and attempted to give the newborn oxygen and chest compressions, the parents said.

Measles can cause a baby's spleen to enlarge and the fibrous tissue around the organ to thin. In such a vulnerable state, the spleen can rupture during birth. Diamantoni has claimed that the pathologist who examined the newborn didn't report an enlarged spleen. But after a spleen ruptures it can be difficult to determine whether it was previously enlarged or not, according to Paul Offit, a vaccine and pediatric infectious disease expert at Children’s Hospital of Philadelphia. Overall, a ruptured spleen is extremely rare in newborns, he says.

Offit told reporters that he has been in touch with state officials and learned enough about the two deaths to say that "these patients would not have died were it not for measles." He has publicly called for the coroner to provide an alternative explanation for the baby's ruptured spleen if it was not from measles.

Far less is publicly known about the second death, which was reported as being in a child as of Tuesday. Though Diamantoni is the coroner for Lancaster County, where both the deceased baby and child lived, the county does not have its own local health department and gets information from the state health department. Diamantoni told The Washington Post late Monday that he had only recently received information about the second death and that his office is still working to determine the cause of death. It's unclear on what grounds they are challenging the state's determination that it was caused by measles without having the information previously.

Kennedy's anti-vaccine agenda

Last week, amid Kennedy's comments, the CDC said on social media that "CDC is working to determine what actually occurred" and claimed that the "Governor’s Office has not provided CDC with information relevant to the outbreak and has declined our offers of assistance."

The state's health department officials said they reported the deaths to CDC staff on August 25 prior to their public announcement and met with CDC officials the next day.

As a spokesperson for the state health department told the Times, "Every reported measles case is thoroughly reviewed to confirm it meets the Centers for Disease Control and Prevention’s (CDC) case definition for a measles case. To date, [the state health department] has provided all required epidemiological data to the CDC."

As an ardent anti-vaccine activist, Kennedy has a long history of spreading vaccine misinformation and disinformation, downplaying the severity and risks of vaccine-preventable diseases and spreading doubt and misinformation about vaccine-preventable deaths. Amid the pandemic, Kennedy and like-minded allies similarly assailed reports of deaths from COVID-19, arguing that they were deaths "with" the deadly virus not "from" it. While Kennedy's pattern is clear, outside experts have raised concern about whether new CDC director Schwartz—who has championed use of vaccines in the past—would stand up to Kennedy's anti-vaccine agenda.

The CDC's decision to challenge the death determinations of Pennsylvania health officials appears to confirm those fears and stand to only exacerbate the flagging public health systems in the US, experts say. “This is a moment for the CDC director to speak publicly about the outbreak," Debra Houry, CDC's former chief medical officer, told the Times. "Delays in reporting of data further erode trust and create confusion."

Read full article

Comments



Read the whole story
Share this story
Delete
Next Page of Stories