Identity Verification Is Broken. The 153 Million Driver’s Licenses Now for Sale Are Proof
A dark web identity theft service is offering more than 153 million U.S. and Canadian driver’s license scans for sale, and the FBI is investigating where the data came from. The apparent breach is a particularly stark example of the problem with the modern identity verification economy where proving who you are means providing a third party with permanent copies of sensitive documents.
According to KrebsOnSecurity , the service, called Nexus, launched on a Russian-language cybercrime forum and claims to have more than 153 million driver’s licenses, along with more than 10 million other identification cards, more than 3 million travel documents and international IDs, and hundreds of thousands of medical cards.
The number is difficult to independently verify, but Krebs found evidence suggesting the service is not simply bluffing. The database contained the licenses of Krebs himself and U.S. Defense Secretary Pete Hegseth, among other government officials. The licenses included multiple images of the documents, including front and back scans and, in some cases, infrared and ultraviolet versions.
The data also appeared to be fresh. Nexus’s advertised collection grew by nearly 400,000 driver’s license records in roughly 24 hours, while the operators claimed they had been continuously exfiltrating information for more than a year.
Krebs traced the apparent source to IDScan.net, a New Orleans-based identity verification company. The company says its technology processes more than 21 million identity verifications every month at more than 20,000 locations around the world.
IDScan.net’s customer materials show just how deeply this type of infrastructure is embedded in everyday commerce. Its official site lists companies and brands including Holiday Inn, 7-Eleven, GameStop, DraftKings, Hertz, Target, FedEx, Shell, and Caesars Entertainment among its customers or integrations.
The connection is particularly striking because Krebs found that timestamps attached to several leaked licenses corresponded with trips, hotel stays, car rentals, and other real-world interactions where people handed over their IDs.
IDScan.net said it is investigating the incident but has not publicly confirmed that its systems were the source of the Nexus database. The company told Krebs that it was unable to provide additional information while its investigation continued. The FBI has also opened an investigation through its New Orleans field office into the apparent breach.
‼️ New article from Brian Krebs: FBI Probes Service Selling 153M+ Drivers Licenses https://t.co/S5KEn9pb5v
Dark Web Onion discussed: http://nexusdbbulkq5345qlqyc2iprxzsrwvavd6r5qwel3o3vxs5svg5mjyd[.]onion pic.twitter.com/HVsrjGrL9x
Shortly after Krebs published its report, the Nexus site itself disappeared from the dark web and was replaced with a message saying the service was no longer available.
Peter Van Valkenburgh, a longtime cryptocurrency policy advocate and Coin Center Executive Director, argued in an essay that the breach was not some bizarre one-off accident.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on gizmodo.com — the content belongs to Gizmodo.