Abstract:
A darknet identity information trading platform called "Nexus" recently began to publicly sell more than 153 million scanned copies of U.S. and Canadian driver's licenses, as well as more than 10 million identity documents, 3 million travel documents and 579,000 medical cards.
The current total number of licensed drivers in the United States is about 242 million, which means that nearly two out of every three American drivers have their driver's license scanned copies listed on the dark web shelves.

According to reports, the security research organization KrebsOnSecurity intervened in the investigation after receiving a tip from an informant at the end of last month. Founder Brian Krebs conducted a blank search on the Nexus website, and the system returned 11.5 million pages of results, with 15 records displayed on each page. The total amount was basically consistent with the 153 million claimed by the hackers.
Most of these scanned copies are American driver's licenses, and a small number are Canadian driver's licenses. They are not limited to ordinary driver's licenses, but also include high-authority documents such as commercial driver's licenses (CDL), military and federal government personnel certification cards (CAC).
Even more shockingly,
a scan of U.S. Secretary of Defense Pete Hegseth’s driver’s license also appeared in the database.
Krebs also discovered that the identity of an FBI assistant director was also included. The hackers even used a scan of Krebs’ Virginia driver’s license as a “product display sample,” which was quite provocative.
After in-depth tracing, Krebs identified the source of the leak as IDScan.net, an identity verification service provider in New Orleans. The company provides document scanning and verification technology to more than 20,000 outlets around the world, processing more than 21 million verification requests every month. Its customer list includes well-known companies such as Hertz Car Rental, Target, FedEx, and Caesars Entertainment.
The timestamps of multiple victims' driver's license scans accurately matched records of them handing in their documents at Hertz rental counters. Krebs's and his mother's driver's licenses were scanned at the same Hertz counter on the same day, within seconds of each other.

Nexus claimed that the data came from an ongoing intrusion into a large identity verification company, and nearly 400,000 new driver's license scans were added within 24 hours of discovery, indicating that the source of the leak may still be exporting data to this day. The FBI's New Orleans branch has launched an official investigation into the matter.
What is quite dramatic is that shortly after KrebsOnSecurity's report was published, the Nexus website disappeared from the dark web, replaced by a "Service is no longer available" prompt. However, the security community generally believes that once data flows into the darknet ecosystem, it will be resold and copied many times. Taking a site offline does not prevent the information from continuing to spread.
The reason why scanned driver's licenses are dangerous is that they contain complete biometric and personal information such as name, address, date of birth, ID number, photos and even barcodes, which can be directly used to open accounts under false names, bypass identity verification on other platforms, etc.
For senior officials like Hegseth, leaking driver's license information could also create physical security risks.Security experts recommend that ordinary people who are worried about their information being leaked should freeze their credit reports as soon as possible, monitor bank account changes, enable strong multi-factor authentication, and report suspected identity theft through IdentityTheft.gov.
Considering that IDScan customers cover many industries such as car rental, retail, finance, and medical care, almost everyone who has lived in the United States and has presented physical documents has reason to check their information security status.
Comments