IL PROGRESSO

Independent journalism on global markets, technology, and the forces reshaping the world economy

Ufficio Emissioni · VeneziaEmissione N. 1412
Home /Technology /Emissione
Technology01 MIN

Nexus Data Breach: FBI Probes Sale of 153 Million Driver’s Licenses

FBI Probes Dark-Web Service Selling 153 Million Driver’s Licenses A dark-web identity theft service called Nexus has claimed to possess digital scans of more than 153 million U.S. and Canadian driver’s licenses, along with millions of addit

Nexus Data Breach: FBI Probes Sale of 153 Million Driver’s Licenses

FBI Probes Dark-Web Service Selling 153 Million Driver’s Licenses

A dark-web identity theft service called Nexus has claimed to possess digital scans of more than 153 million U.S. and Canadian driver’s licenses, along with millions of additional identity documents, and the FBI’s New Orleans field office has opened an official inquiry into the source of the images. The scale of the alleged breach — which also includes over 10 million identification cards, three million travel documents, and nearly 580,000 medical cards — represents one of the largest known exposures of government-issued identity data. If confirmed, the incident would compromise the personal information of a substantial portion of the North American adult population and raises urgent questions about the security practices of the identity verification industry.

According to reporting by KrebsOnSecurity, which broke the story, the Nexus service first appeared on the Russian cybercrime forum Exploit on August 31. The service’s proprietor offered a free sample of the reporter’s own Virginia driver’s license to demonstrate authenticity. The service claimed to be continuously exfiltrating new data from “a major identity verification company” whose clients include multiple Fortune 500 firms. Over a 24-hour period following the initial report, the number of driver’s license records listed on Nexus increased by nearly 400,000, suggesting ongoing data theft. KrebsOnSecurity traced the likely source by comparing timestamps on stolen license images with the times their owners had their IDs scanned at specific locations, including a Hertz rental counter and a Planet13 dispensary. Both businesses use identity verification services from Louisiana-based idscan.net, whose technology scans documents using infrared and ultraviolet light. After the story was published, the Nexus website vanished from the dark web, replaced by a message stating, “This service is no longer available.”

The incident highlights a critical vulnerability in the infrastructure used by businesses to verify customer identities. Identity verification companies like idscan.net aggregate vast databases of sensitive personal data, including facial images, addresses, and document numbers. A sustained breach over more than a year, if confirmed, suggests that either the company’s network security was inadequate or the attackers had persistent access that went undetected. For the individuals whose licenses are now for sale, the consequences extend beyond identity theft. Driver’s licenses are a primary document for opening bank accounts, obtaining credit, and passing age verification checks. The inclusion of facial images enables sophisticated synthetic identity fraud, where criminals combine real data with fabricated details to create new fraudulent identities. The fact that the service offered a free sample of a specific reporter’s license also underscores the targeted nature of such data markets, where journalists, executives, and public figures may be at elevated risk.

The FBI probe will likely focus on whether idscan.net or another unnamed firm suffered a breach and whether the company notified affected individuals as required by state and federal law. The disappearance of the Nexus service may indicate that the operators are attempting to evade law enforcement or that the service was taken down by the hosting provider under pressure. Either way, the data is almost certainly already distributed across other criminal networks. For the identity verification industry, the case serves as a stark reminder that centralized databases of sensitive documents represent a single point of failure. Regulators may now face pressure to mandate stronger security standards, including encryption of data at rest and in transit, regular third-party audits, and stricter limits on data retention. For consumers, the incident reinforces the need for monitoring services and the adoption of more secure identity verification methods, such as biometrics that do not rely on storing images in a central repository.

The Nexus case is not an isolated data dump but a live exfiltration operation that may have been running for over a year. The disappearance of the sales platform does not erase the exposure of 153 million driver’s licenses; it only means the marketplace has moved. The fundamental takeaway for investors, policymakers, and security professionals is that the identity verification ecosystem, built on trust in third-party processors, remains dangerously porous. Until the industry adopts architectures that minimize data aggregation and maximize breach resilience, such incidents will continue to erode the very identity infrastructure that modern commerce depends on.

Source & Credits

Originally reported by Slashdot.

Written for Il Progresso by Zhicheng Wang.

↑ Torna alla prima pagina