FBI Probes Service Selling 153M+ Drivers Licenses (krebsonsecurity.com)
- Reference: 0185362002
- News link: https://yro.slashdot.org/story/26/09/02/0611226/fbi-probes-service-selling-153m-drivers-licenses
- Source link: https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
> On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit. The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.
>
> [...] The people behind Nexus claim the license images are coming from an active breach at "a major identity verification company" whose customers include multiple Fortune 500 companies. "We have been continuously exfiltrating new data for over a year into our private database," the service enthused in its introductory post on Exploit. "Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available." Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis.
KrebsOnSecurity traced the apparent source by comparing timestamps on stolen license images with when their owners had their IDs scanned, including at Hertz rental counters and a Planet13 dispensary. Both companies use identity-verification services from Louisiana-based idscan.net, whose technology also scans IDs using infrared and ultraviolet light.
Since the story was published, Krebs reports that the Nexus identity theft service website "vanished from the darkweb, replacing its login page with a plain text message that reads, 'This service is no longer available.'"
[1] https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
Flock, is that you (Score:2)
The only thing these idiots did wrong is they forgot to get law enforcement to pay for the service- then its just policing!
Once again (Score:2)
Private industry doing it better than the government.
Holy crap! (Score:5, Interesting)
170 million? That's fairly close to being half of the combined population of USA and Canada!
When you adjust for the people who don't have driving licences, that would seem to be pretty close to the total number of legal drivers in the two countries. Ouch!
Re: (Score:2)
Only about 100 million short of having them all. AI says 268.4 million drivers combined across the two countries.
Charge an excise tax on leaked data (Score:3)
Of $500 per record.
That will clear up these leaks real quick
Re: (Score:2)
who's doing the enforcement?
Re: (Score:2)
Wouldn't that give the data collectors a huge incentive to NOT report any leaks?
Re: (Score:2)
More like increase costs for everyone as cyber insurance rates go through the roof and are passed on to the customer.
Re: (Score:2)
Why should the government get anything? Each person's data that the company leaked should get a direct $30,000 payment. If the company can't do that, hold an auction on all non-data assets and split it up among the victims. The company is dead.
"Selling" isn't the root problem (Score:5, Informative)
Oh, goody, the website selling our licenses is down. Whelp, toothpaste back in the tube, we can all rest easy knowing that the day is saved!
Of course, the next obvious step if they can't sell them is to simply release the entire batch into the wild. And how dare any of you think this might somehow be the fault of sweet innocent idscan.net for inadequately protecting the highly sensitive data they were grudgingly entrusted with in the first place.
We need a hell of a lot more CEOs in prison, and we need any politicians that requires / supports / allows this bullshit to join them. Of course, absolutely none of that is going to happen because Joe Sixpack has zero clue any of this is going on; and even if he somehow catches wind of it from a Facebook meme, oh well, it's just one more breach, who cares, he gets notices of those on a monthly basis and has been intentionally trained to treat them as junk mail.
Re: (Score:2)
Yeah I do this when I play Whack-A-Mole. I hit one singular Mole into the hole, then I camp that hole ignoring all others while I proclaim that I have eradicated all Moles, everywhere.
Everyone believes me at my word because if skeptical, everyone will just attack that person with my fictional baby-saving eldery-helping image and not my real drunk-kid-knocking-on-the-wrong-door-with-hands-up actions..
Who (Score:3)
"a major identity verification company"
Why is their identity being protected?
Re: (Score:2)
Because corporations have MORE rights than you do, obviously!
Re: (Score:2)
It's called continued engagement, or to us - click-bait. The answer is right there in the summary near the end. You can read that far?
Re: Who (Score:2)
IDScan is the company that appears to be the source of the leak
I've wondered about this (Score:2)
Every time I apply for a job, I have to send them a copy of my driver's license to prove my idea. Likewise, when somebody claimed on Facebook that I was impersonating myself, I had to send Facebook a copy of my driver's license (which they misread, since it was last name first, and changed my Facebook ID to lastname firstname middle name). So it would be trivially easy to solicit job applications and collect DL scans.
You thought this too (Score:2)
Is it bad that my first thought when reading this headline was "To buy it or to arrest them?"
This is why (Score:4, Interesting)
This right here is why people are so adamantly against giving websites a copy of their ID card
to prove their age.
These vendors then become priority targets for ID theft since the laws, as currently written, do
not force them to take security of said data very seriously. When there is a breach, the company
gets a slap on the wrist, a laughable fine and then it's right back to business as usual.
In the meantime, everyone who gave their ID to said company is now on the hook for potential
ID thieves and the nightmare that goes with it should they draw the short straw.
Before we implement any sort of mandatory age verification that requires your ID going into any
sort of digital online storage, the laws need to be rewritten to make the financial penalties so painful,
that the company in question will find it cheaper to simply do security the right way the first time.
Would cold/offline storage have helped? (Score:1)
Assume there's a legitimate company out there that will verify driver's licenses. Do they really need to store everything "online"? No, they do not.
They can store it "offline" with a 1- or 2- minute delay to access the data, caching it in "online" systems for maybe 15 minutes.
This, plus alarms when large amounts of data is being moved from "offline" to "online" in a short period of time, would've either made this leak slower than it was or, more likely, led to this year-long leak being discovered and plug
FaaS - Fascism as a Service (Score:2)
(alt subject : "Oops, all data breaches!")
Nothing to see here, just normal day-to-day government work circumventing the 4th amendment by outsourcing data collection to the private sector. This kind of thing happens all the time.
Move along, Citizen!
Re: (Score:2)
Pretty sure 'the government' already has a copy of your photo id and all the related details... why did you give it to them?
Digital IDs (Score:2)
This was the whole point of Digital IDs. To prevent ID theft. Banks, DMV, IRS already know who you are and have your data.
They can use this data to confirm your identity to any other 3rd Party. Just like OAUTH, they only need to send a token out as confirmation.
In A Surpise To Only The Stupidest Of People (Score:5, Insightful)
The KYC verified identities are leaking exactly was expected.
The present age verification laws are creating FAR more problems than they solve.
This will come as a surprise only to the stupidest and most moronic people around. A cohort that vastly outnumbers the rest.
Re:In A Surpise To Only The Stupidest Of People (Score:5, Insightful)
> including at Hertz rental counters and a Planet13 dispensary
These are not online age verifications, the dispensary may be age related, but it's also residency so they know how much you can purchase, Hertz on the other hand is not going to rent you a car if you don't have a valid license.
Re: (Score:2)
Fake IDs have improved. Hertz will always see a lot of out-of-state (and out-of-nation) licenses, which are harder to visually verify.
Why they'd feel the need to keep the scans in a database, I do not know. Seems unnecessary and didn't do them any favors.
Re: (Score:2)
> So why does that mean that the licenses need to be uploaded into a central database? It's not enough for the clerk to just LOOK at the license?
> Hertz was founded in 1918. I could be wrong, but I'm pretty sure they didn't have central databases of driver license images back in 1918, and yet somehow Hertz seemed to operate just fine. I'd go so far as to say Hertz was operating in the 21st century without a third party central database of driver licenses.
From my experience over the decades, it wasn't enough for them to just look . They had to take your license, hold it up near their face and squint at it, then set it at the top of the keyboard of their mainframe terminal and peck in a few characters. Then they had to pick it up again, squint and peck some more, then repeat this cycle for at least a couple of minutes.
This was of course followed by scrawling a dozen circles on the reams of fine print for you to put your initials in, topped off by a long argume
Re: (Score:2)
Looks like standard ID verification to me. Yes, both of those places care about age, but Hertz at least is more interested in the license being valid, as they are going to deal with out-of-state licenses (harder to detect a fake) on a daily basis.
Re: (Score:1)
"Think of how stupid the average person is, and realize half of them are stupider than that." - George Carli
Re: (Score:3)
The dispensary might be for age verification, but Hertz wants to verify the driver's license is legitimate. Only the stupidest and most moronic people around would jump to the conclusion that this was caused by a brand new social media age verification law.
Re: (Score:2)
> The present age verification laws are creating FAR more problems than they solve.
Which is what the OS age verification was supposed to solve - the OS verifies your age and that's it. You don't have to send your ID to a million third party agencies. Of course, these agencies don't have to worry about OS verification taking over since not every OS will have that functionality (usually phrased as "open source OS exclusion").
All those Linux users will be keeping those third party services alive.