
A dark-web identity theft service called Nexus claimed to be selling more than 153 million U.S. and Canadian driver’s-license records, along with 10 million other identification cards, more than 3 million travel/international IDs, and at least 579,000 medical cards. Cybersecurity journalist Brian Krebs discovered the service after his own driver’s license was offered as a free sample, and he later found approximately 11.5 million pages of search results containing license records. Krebs verified licenses belonging to nine of more than a dozen friends and relatives he checked, while the records’ timestamps frequently matched their travel, car-rental, and other activities. The stolen licenses included ordinary scans as well as infrared and ultraviolet images, potentially providing information used by identity-verification systems to authenticate genuine documents. The service appeared to be receiving new data continuously, adding nearly 400,000 driver’s-license records in just 24 hours, suggesting ongoing or automated access to a source system.
The evidence pointed toward IDScan.net, a Louisiana-based identity-verification provider whose technology is used by numerous businesses, although the company had not publicly confirmed a breach or determined how many people were affected. The FBI’s New Orleans office confirmed that it was investigating, while Nexus disappeared shortly after Krebs reported on it. Security experts warned that the exposure is especially serious because driver’s licenses contain permanent identifying information; as BreachLock CEO Seemant Sehgal put it, “unlike a compromised password, none of those fields can be changed,” meaning victims may face the consequences for life. Another expert, Kevin Surace, said the activity looked less like a one-time theft and more like “persistent access to trusted systems or identities.” The incident therefore raises not only questions about how the attackers obtained the records, but also about why such extensive personal information was retained and accessible in the first place.
Read more about it here.