Forgot your password?
typodupeerror
Privacy Security

FBI Probes Service Selling 153M+ Drivers Licenses (krebsonsecurity.com) 60

A dark-web identity theft service called Nexus claims to be selling scans of more than 153 million U.S. and Canadian driver's licenses, along with millions of other identity documents. "Based on interviews with individuals whose licenses are available for purchase through the service, it appears to be siphoning images collected by a widely used Louisiana-based identity verification company," reports KrebsOnSecurity. The outlet also reports that the FBI's New Orleans field office has launched an official inquiry into the source of the images. From the report: On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit. The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.

[...] The people behind Nexus claim the license images are coming from an active breach at "a major identity verification company" whose customers include multiple Fortune 500 companies. "We have been continuously exfiltrating new data for over a year into our private database," the service enthused in its introductory post on Exploit. "Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available." Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.
KrebsOnSecurity traced the apparent source by comparing timestamps on stolen license images with when their owners had their IDs scanned, including at Hertz rental counters and a Planet13 dispensary. Both companies use identity-verification services from Louisiana-based idscan.net, whose technology also scans IDs using infrared and ultraviolet light.

Since the story was published, Krebs reports that the Nexus identity theft service website "vanished from the darkweb, replacing its login page with a plain text message that reads, 'This service is no longer available.'"
This discussion has been archived. No new comments can be posted.

FBI Probes Service Selling 153M+ Drivers Licenses

Comments Filter:
  • by SlashbotAgent ( 6477336 ) on Wednesday September 02, 2026 @12:03PM (#66319391)

    The KYC verified identities are leaking exactly was expected.

    The present age verification laws are creating FAR more problems than they solve.

    This will come as a surprise only to the stupidest and most moronic people around. A cohort that vastly outnumbers the rest.

    • by justMichael ( 606509 ) on Wednesday September 02, 2026 @12:14PM (#66319409)

      including at Hertz rental counters and a Planet13 dispensary

      These are not online age verifications, the dispensary may be age related, but it's also residency so they know how much you can purchase, Hertz on the other hand is not going to rent you a car if you don't have a valid license.

      • You're missing the point.

        Leaks of personal information like this are only possible because some company decided to collect and store it all in one place. It's never a matter of if, but only when, a database will be breached and data leaked.

        The age verification laws will create even more vast databases of personal information; names, addresses, financial information, various service accounts, even deep information about each person's habits and preferences. All in the hands private businesses who were the lo

    • Looks like standard ID verification to me. Yes, both of those places care about age, but Hertz at least is more interested in the license being valid, as they are going to deal with out-of-state licenses (harder to detect a fake) on a daily basis.
    • "Think of how stupid the average person is, and realize half of them are stupider than that." - George Carli
    • The dispensary might be for age verification, but Hertz wants to verify the driver's license is legitimate. Only the stupidest and most moronic people around would jump to the conclusion that this was caused by a brand new social media age verification law.
    • by tlhIngan ( 30335 )

      The present age verification laws are creating FAR more problems than they solve.

      Which is what the OS age verification was supposed to solve - the OS verifies your age and that's it. You don't have to send your ID to a million third party agencies. Of course, these agencies don't have to worry about OS verification taking over since not every OS will have that functionality (usually phrased as "open source OS exclusion").

      All those Linux users will be keeping those third party services alive.

    • Where could they get all this data I wonder. Image someone allowed Musk to just put together a crack team to suck all the data the gov has on everyone into a AI model and not understand the implications. I get this is separate but still.. that should be the bigger story.

  • The only thing these idiots did wrong is they forgot to get law enforcement to pay for the service- then its just policing!

  • Private industry doing it better than the government.

  • Holy crap! (Score:5, Interesting)

    by jenningsthecat ( 1525947 ) on Wednesday September 02, 2026 @12:30PM (#66319425)

    170 million? That's fairly close to being half of the combined population of USA and Canada!

    When you adjust for the people who don't have driving licences, that would seem to be pretty close to the total number of legal drivers in the two countries. Ouch!

    • Only about 100 million short of having them all. AI says 268.4 million drivers combined across the two countries.
    • by PPH ( 736903 )

      half of the combined population of USA and Canada!

      Soon just half the population of the USA.

      [ducking and running]

  • by djp2204 ( 713741 ) on Wednesday September 02, 2026 @12:37PM (#66319439)

    Of $500 per record.

    That will clear up these leaks real quick

  • by pla ( 258480 ) on Wednesday September 02, 2026 @12:46PM (#66319451) Journal
    Oh, goody, the website selling our licenses is down. Whelp, toothpaste back in the tube, we can all rest easy knowing that the day is saved!

    Of course, the next obvious step if they can't sell them is to simply release the entire batch into the wild. And how dare any of you think this might somehow be the fault of sweet innocent idscan.net for inadequately protecting the highly sensitive data they were grudgingly entrusted with in the first place.

    We need a hell of a lot more CEOs in prison, and we need any politicians that requires / supports / allows this bullshit to join them. Of course, absolutely none of that is going to happen because Joe Sixpack has zero clue any of this is going on; and even if he somehow catches wind of it from a Facebook meme, oh well, it's just one more breach, who cares, he gets notices of those on a monthly basis and has been intentionally trained to treat them as junk mail.
    • Yeah I do this when I play Whack-A-Mole. I hit one singular Mole into the hole, then I camp that hole ignoring all others while I proclaim that I have eradicated all Moles, everywhere.

      Everyone believes me at my word because if skeptical, everyone will just attack that person with my fictional baby-saving eldery-helping image and not my real drunk-kid-knocking-on-the-wrong-door-with-hands-up actions..

  • Who (Score:5, Interesting)

    by ThurstonMoore ( 605470 ) on Wednesday September 02, 2026 @01:09PM (#66319471)

    "a major identity verification company"

    Why is their identity being protected?

  • by Locke2005 ( 849178 ) on Wednesday September 02, 2026 @01:26PM (#66319503)
    Every time I apply for a job, I have to send them a copy of my driver's license to prove my idea. Likewise, when somebody claimed on Facebook that I was impersonating myself, I had to send Facebook a copy of my driver's license (which they misread, since it was last name first, and changed my Facebook ID to lastname firstname middle name). So it would be trivially easy to solicit job applications and collect DL scans.
  • Is it bad that my first thought when reading this headline was "To buy it or to arrest them?"
  • This is why (Score:5, Insightful)

    by nehumanuscrede ( 624750 ) on Wednesday September 02, 2026 @02:15PM (#66319575)

    This right here is why people are so adamantly against giving websites a copy of their ID card
    to prove their age.

    These vendors then become priority targets for ID theft since the laws, as currently written, do
    not force them to take security of said data very seriously. When there is a breach, the company
    gets a slap on the wrist, a laughable fine and then it's right back to business as usual.

    In the meantime, everyone who gave their ID to said company is now on the hook for potential
    ID thieves and the nightmare that goes with it should they draw the short straw.

    Before we implement any sort of mandatory age verification that requires your ID going into any
    sort of digital online storage, the laws need to be rewritten to make the financial penalties so painful,
    that the company in question will find it cheaper to simply do security the right way the first time.

    • This right here is why people are so adamantly against giving websites a copy of their ID card
      to prove their age.

      This leak wasn't from websites getting a copy of an ID card. This was from physical stores: car rental offices and dispensaries.

      • by PPH ( 736903 )

        This was from physical stores

        How do you think these "car rental offices and dispensaries" capture and transfer ID images? Pretty much the same way web sites take a picture of your ID. It's just using a specialized scanner. But otherwise an image upload.

      • ... a copy of an ID card.

        How they got the copy is largely, irrelevant. The business took a copy of an Id. card and stored it on a internet-facing computer: What happens next is a matter of "when", not "if". The task of 'preventing' crime is enabling criminals. It's much worse because IdScan are in the business of storing Identity Documents and they failed their core function. That should be punished with fines that prevent CxOs getting a bonus or pay-rise for a decade, even when they change corporations.

  • Assume there's a legitimate company out there that will verify driver's licenses. Do they really need to store everything "online"? No, they do not.

    They can store it "offline" with a 1- or 2- minute delay to access the data, caching it in "online" systems for maybe 15 minutes.

    This, plus alarms when large amounts of data is being moved from "offline" to "online" in a short period of time, would've either made this leak slower than it was or, more likely, led to this year-long leak being discovered and plug

    • No, the solution is to not store it at all. I've yet to see any justification for storing anything beyond maybe a hash
  • (alt subject : "Oops, all data breaches!")

    Nothing to see here, just normal day-to-day government work circumventing the 4th amendment by outsourcing data collection to the private sector. This kind of thing happens all the time.

    Move along, Citizen!
    • Pretty sure 'the government' already has a copy of your photo id and all the related details... why did you give it to them?
  • This was the whole point of Digital IDs. To prevent ID theft. Banks, DMV, IRS already know who you are and have your data.

    They can use this data to confirm your identity to any other 3rd Party. Just like OAUTH, they only need to send a token out as confirmation.
  • by BeaverCleaver ( 673164 ) on Wednesday September 02, 2026 @09:11PM (#66320390)

    If I ever have to upload an image of an ID (which is pretty rare) I always write on it "submitted to XXXX for" with the purpose and the date. It doesn't prevent leaks but if the ID shows up later in a breach like this, we know who is responsible.

    I have never had an ID picture rejected for doing this.

    • It's a good idea.
      I just was renewing my dl with the state of MN and to avoid really stupid amounts of time in registration (going from a normal to "enhanced" id they have you upload not just the front and back of your dl but also your passport. So I instead accepted that I'm going to spend my whole fucking day in their office.

      • It's a good idea.
        I just was renewing my dl with the state of MN and to avoid really stupid amounts of time in registration (going from a normal to "enhanced" id they have you upload not just the front and back of your dl but also your passport. So I instead accepted that I'm going to spend my whole fucking day in their office.

        This ^^^^

        Sometimes we have to accept that doing the job right will take longer. Especially when it comes to the convenience/privacy dichotomy.

    • Let me know how that works for you when your ID is scanned by a local business such as a liquor store or pharmacy.

      • Let me know how that works for you when your ID is scanned by a local business such as a liquor store or pharmacy.

        Then I write the name of the guy doing the scanning as well. "Scanned by Bob at LiquorMart 2026/04/09"

        If Bob objects, I know to take my ID and never return to that store.

To write good code is a worthy challenge, and a source of civilized delight. -- stolen and paraphrased from William Safire

Working...