Security nightmare: FBI investigates dark-web service selling 153 million driver’s license scans

(Unsplash)

The FBI is investigating what could be one of the most devastating identity-data breaches ever uncovered in North America.

A newly launched dark-web service called “Nexus” claims to be selling actual digital scans of more than 153 million driver’s licenses belonging to people across the and Canada, according to cybersecurity journalist Brian Krebs, who first reported the incident.

This is not merely another database containing stolen names, email addresses, and passwords.

The criminals reportedly obtained digital images of government-issued identification documents, including front-and-back scans and, in some cases, the infrared and ultraviolet images used to authenticate them.

According to cybersecurity journalist Brian Krebs, the massive collection allegedly includes:

  • More than 153 million driver’s licenses
  • More than 10 million identification cards
  • More than 3 million travel documents and international IDs
  • At least 579,000 medical cards

The database reportedly contains the driver’s license of Secretary of War Pete Hegseth, along with identification documents belonging to other high-ranking federal officials, including an assistant director of the FBI. According to the report, the hacker offered Hegseth’s driver’s license for $100.

Krebs discovered that his own Virginia driver’s license was also in the database after the criminals behind Nexus displayed it as a free sample while advertising their service on the Russian-language cybercrime forum Exploit.

According to Krebs, his record contained six separate image files: three sets of front-and-back photographs consisting of a standard scan and infrared and ultraviolet versions.

“This is an identity thief’s dream—and a security nightmare for potentially more than half of America’s licensed drivers.”

A blank search of the Nexus database reportedly returned approximately 11.5 million pages, with roughly 15 results displayed per page, suggesting that the criminals may not be exaggerating about the enormous size of the archive.

The number of available driver’s license records reportedly increased by nearly 400,000 in just 24 hours.

The criminals behind Nexus claimed they had been continuously stealing new information for more than a year.

Krebs traced multiple exposed licenses to occasions when their owners presented identification during travel or while renting vehicles. The timestamps attached to several licenses reportedly matched dates when the victims rented cars from Hertz.

The apparent trail led investigators toward IDScan.net, a Louisiana-based identity-verification company whose technology scans and authenticates identification documents.

IDScan.net advertises that its technology processes more than 21 million identity verifications every month at over 20,000 locations worldwide. Its website lists major companies and organizations such as Hertz, FedEx, Shell, Chevrolet, Caesars Entertainment, Target, and financial-services provider Jack Henry among its customers or integrations.

Krebs reported that the FBI’s New Orleans field office opened an official investigation into an apparent breach involving IDScan.net after he participated in a conference call with senior officials from the bureau’s cyber division.

IDScan.net has not been conclusively confirmed as the source of the entire database.

The company told Krebs it was investigating the allegations but had not yet determined whether unauthorized access occurred or what information may have been exposed.

Shortly after Krebs published his bombshell report, the Nexus website suddenly vanished from the dark web. Its login page was replaced with a short message declaring, “This service is no longer available.”

The breach could allow criminals to impersonate victims, establish fraudulent accounts, defeat identity-verification systems, or target individuals using information taken directly from official documents.

The incident also reveals the enormous danger created by the growing corporate and government push to make Americans surrender digital copies of their identification for routine transactions.

Americans are repeatedly told that uploading or scanning their government-issued IDs will make systems more secure.

But every company that collects and stores those documents creates another massive target for hackers.

Leave a Comment