deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (hnrss.org)

Dark web service sold 153 million driver's licenses in breach linked to IDScan

Krebs on Security found a dark web service selling 153 million US and Canadian driver's licenses — about 63% of all US licenses — in a breach circumstantially tied to identity verifier IDScan.

Dark web service sold 153 million driver's licenses in breach linked to IDScan

What happened

According to Krebs on Security, a dark web service calling itself Nexus has been selling access to a trove of identity documents: about 3 million travel documents and 153 million driver's licenses belonging to US and Canadian citizens. The operators claimed they had broken into a major identity verification company and had spent more than a year steadily siphoning fresh records into a private database. Krebs noted that the license count grew by nearly 400,000 in a single day, suggesting data was still flowing in rather than sitting in a static dump.

The licenses appear to be genuine. Krebs confirmed that the database held his own license along with those of nine friends and family members, as well as licenses belonging to senior US officials, including Secretary of War Pete Hegseth and an assistant director of the FBI.

Attribution to IDScan

Based on circumstantial evidence, Krebs connected the incident to IDScan, a company whose website advertises checking that an ID is authentic, that it is being presented by its legitimate owner, and that fraudulent documents are detected. The FBI is investigating, and IDScan has confirmed it is looking into a data breach. Shortly after Krebs published his findings, the Nexus service disappeared from the dark web — but the people behind it have not claimed to have deleted anything, and a Lawfare analysis suggests they are simply waiting for the attention to pass.

Why intelligence services want your license

For ordinary criminals, a license database is fuel for identity theft and phishing. The Lawfare piece, republished from the Seriously Risky Business newsletter, argues the national security stakes are considerably larger. A driver's license is a foundational identity document, and license numbers are reused across many other databases. Stitched together with a photograph and a home address, stolen records let an adversary tie otherwise anonymous data to a specific, named person.

There is precedent. In the mid-2010s, Chinese espionage groups assembled complementary datasets from breaches at the insurer Anthem, the credit bureau Equifax, Marriott hotels, United Airlines and — most significantly — security clearance files held by the Office of Personnel Management. The US intelligence community believes that combined haul was used to counter American intelligence operations against China, as chronicled in a series of Foreign Policy articles by Zach Dorfman.

Open-source investigators show what such data can do in practice. In 2022, Bellingcat used a hacked database containing a key piece of travel information to identify a deep-cover GRU officer attempting to infiltrate a NATO command post in Naples. In 2018, its researchers identified suspects in the Novichok attack on Sergei Skripal. Bellingcat said in 2020 that it had acquired dozens of leaked databases to cross-reference against new material. Lawfare's conclusion is blunt: if a small investigative outfit can do this with Russian data, foreign intelligence services are certainly doing the same with American data.

A recurring weak point

The scale is striking — Lawfare calculates that the US licenses in the database amount to roughly 63 percent of all licenses in the country — but identity verification vendors get breached regularly. The past two years alone have seen incidents at AU10TIX, at 5CA (the provider behind Discord's age verification), and at National Public Data. These services exist to fight fraud, yet when their security fails they become concentrated stores of exactly the documents criminals and spies want. Lawfare argues that the sensitivity and volume of what they handle justifies strict regulation and oversight, while acknowledging that swift government action is unlikely. In the short term, class-action law firms are already circling IDScan, and the piece suggests attention from the Federal Trade Commission would not hurt either.

Why it matters

Roughly six in ten American driver's licenses may now sit in a criminal database that was still growing when it was exposed, and nothing indicates the data has been destroyed. Beyond the coming wave of identity theft, the breach hands any buyer — including foreign intelligence services — a lookup table linking names, faces and home addresses at national scale, the same kind of aggregated data that has previously been turned against US intelligence personnel. It also exposes a structural problem: an industry built to verify identity has become a single point of failure for it, with little regulatory pressure to do better.

  • #security
  • #data-breach
  • #identity-theft
  • #dark-web
  • #identity-verification

Related posts