
Dell Posts Record AI Server Orders as Enterprise Spending Surges
Dell’s fiscal second-quarter results reveal an enterprise technology spending cycle of unusual magnitude. The company booked $60.9 billion in new orde…
Independent journalism on global markets, technology, and the forces reshaping the world economy
The FBI’s New Orleans field office has opened an inquiry into a dark-web identity theft service, Nexus, that claims to be selling digital scans of more than 153 million U.S. and Canadian driver’s licenses, along with millions of other ident…

The FBI’s New Orleans field office has opened an inquiry into a dark-web identity theft service, Nexus, that claims to be selling digital scans of more than 153 million U.S. and Canadian driver’s licenses, along with millions of other identity documents. The investigation follows a report from KrebsOnSecurity, which traced the apparent source of the stolen data to a Louisiana-based identity verification company called idscan.net, whose technology is widely used by Fortune 500 firms and retail locations. The scale of the breach, if confirmed, would rank among the largest identity-data exposures in North American history, with serious implications for consumer privacy, corporate liability, and the security of third-party verification services.
Nexus first advertised on the Russian cybercrime forum Exploit on August 31, offering access to a database that includes more than 153 million driver’s licenses, over 10 million identification cards, more than three million travel documents, and at least 579,000 medical cards. The service claimed that the images were being obtained through an active breach at a major identity verification company, and that it had been exfiltrating data for over a year. The scale of the database is unusually large, and the claim that it includes both front and back scans of licenses, often with customer photos, suggests that the data was captured during the verification process rather than from a single static file.
KrebsOnSecurity was able to verify that the stolen images correspond to real identity documents by comparing metadata timestamps with when individuals had their IDs scanned at locations such as Hertz rental counters and a Planet13 dispensary. Both of those businesses use identity-verification services from idscan.net, a Louisiana company whose systems scan IDs using infrared and ultraviolet light to check for authenticity. The matching timestamps strongly suggest that the breach originated from idscan.net’s infrastructure or that of a linked partner. Since the story was published, the Nexus login page was replaced with a message stating that the service is no longer available, though the database itself may still be in circulation among criminals who already purchased access.
The breach highlights a structural vulnerability in the digital identity verification industry. Companies like idscan.net process millions of sensitive documents daily for clients ranging from car rental agencies to cannabis dispensaries to financial institutions. Because the verification process often involves scanning the full front and back of a license, the captured data goes far beyond what is printed on the front of the card, including barcodes and machine-readable zones that can be used to forge documents. Any compromise of the verification pipeline can therefore expose not only names and addresses but also the raw data needed to create convincing fakes.
For the FBI, the investigation will focus on identifying the method of exfiltration and whether the breach was the work of external hackers or an insider. The disappearance of the Nexus site may complicate efforts to track buyers and sellers, but the forensic trail left by the data itself could still yield leads. For businesses that rely on verification services, this breach will likely accelerate scrutiny of vendor security practices and the data retention policies that allow massive caches of raw identity documents to accumulate over time. For consumers, the breach is a stark reminder that handing over physical identification to a third-party scanner, even for a routine transaction, can create a data trail that persists far beyond the point of sale and may be vulnerable to large-scale theft.
Source & Credits
Originally reported by Slashdot.
Written for Il Progresso by Zhicheng Wang.