Read as article
153 Million Driver's Licenses Offered on Dark Web, FBI Probes
By @sharedot · · 7 pages
The FBI is investigating a suspected breach of an ID verification firm after a dark-web service offered over 153 million driver's license scans, including Hegseth's.
What Happened
The FBI has opened an investigation into an alleged cybersecurity breach of an ID verification company that potentially exposed millions of scans of driver's licenses, NBC News reports. Cybercriminals advertised the data through a dark-web service called Nexus, which claimed to hold more than 153 million U.S. and Canadian driver's licenses plus millions of other identity documents, including identification cards, travel cards, Common Access Cards, residence cards, and employment authorizations. Among the IDs offered for sale was the driver's license of Defense Secretary Pete Hegseth, according to NBC News. Nexus went dark within hours of publication of an investigation by KrebsOnSecurity.
Why It Is Surprising
The scale and apparent intimacy of the exposure set this apart from ordinary data breaches. These were not name-and-number database records but high-resolution scans capturing the front and back of physical IDs, including infrared and ultraviolet images collected during document verification. The National CIO Review notes that access to these formats could let cloned counterfeit IDs pass hologram tests, challenging verification systems that rely on document authenticity. The apparent victims also include senior government officials and security researchers — KrebsOnSecurity's own Brian Krebs reportedly found his license searchable — making the breach a direct strike at people who spend their careers studying exactly this kind of compromise.
The Evidence Tying Records to IDScan
KrebsOnSecurity, working with researcher Zach Edwards, linked the stolen records to IDScan by matching timestamps on licenses with transactions where owners had their IDs scanned. According to The National CIO Review, timestamps on several stolen licenses matched occasions when their owners had IDs scanned during Hertz rentals, and Edwards found a similar connection after visiting Planet 13, a dispensary chain that had an exclusive arrangement with IDScan. Ars Technica's Dan Goodin reported that his own license appeared on Nexus within hours of being scanned at a car rental company, and that idscan.net, a New Orleans-based scanning service, had listed Hertz and 11 other companies as customers. IDScan said it was investigating and had not confirmed the source of the data.
The Stakes
Nexus claimed it had been extracting data from a major identity verification company for more than a year, and The National CIO Review cites Krebs's observation that the collection grew by nearly 400,000 driver's-license records in 24 hours — suggesting the source may have still been feeding the service during his investigation. If confirmed, that duration raises serious questions about the company's ability to detect unauthorized access and large data transfers. The National CIO Review also points to a broader problem: expanding age-verification requirements are pushing more identity documents through verification vendors, creating large repositories of reusable identity data. Government IDs are difficult to replace, so the risk to victims could persist long after the breach is contained.
What Comes Next
The FBI investigation is the concrete step now underway, according to NBC News and KrebsOnSecurity's reporting relayed by Ars Technica. IDScan has said it is investigating but has not confirmed the source of the data in the reporting provided to journalists, and its representatives did not immediately answer emailed questions, Ars Technica reports. For consumers, the closure of Nexus cuts both ways: the service went dark within hours of the exposé, but that also leaves people with no way to check whether their own IDs were included. Expect renewed scrutiny of how verification vendors retain scanned documents after checking them, and of whether ID-based age checks can expand without building exactly the kind of stockpile this breach appears to have exposed.