A threat actor this week started offering on the dark web digital scans of over 153 million US and Canadian driver’s licenses.
The driver’s licenses emerged on an identity theft service called Nexus. Simultaneously, a threat actor started promoting the service on a Russian cybercrime forum, claiming the possession of the IDs of over 170 million individuals.
On Nexus, visitors could find over 153 million driver’s licenses, more than 10 million identification cards, over 3 million travel documents and international IDs, and roughly 580,000 medical cards.
According to investigative journalist Brian Krebs, a blank search on Nexus appeared to return approximately 153 million results. Only around 1.1 million driver’s licenses were from Canada.
The threat actor behind Nexus alleged that the documents were exfiltrated from an active breach at an identity verification firm that serves multiple Fortune 500 companies, Krebs reports.
After verifying the presence of his own driver’s license on Nexus, as well as that of other individuals, Krebs concluded that the documents were likely siphoned from identity verification platform IDScan.net.
The Louisiana-based firm provides ID fraud prevention, access management, and age verification services, along with an ID-activated door lock and mobile ID scanners.
The company says it works with large brands across a dozen industries, including automotive, banking and fintech, gaming, education, transportation, hospitality, law enforcement, retail, and security, performing over 21 million verifications each month at more than 20,000 locations.
SecurityWeek has emailed IDScan for a statement on the potential data breach and will update this article if the company responds.
According to Krebs, the Nexus platform was shut down shortly after his article on the stolen IDs was published.
However, the FBI apparently caught wind of the potential IDScan data breach and launched an official investigation into the matter. Some of the driver’s licenses the threat actor behind Nexus had exfiltrated apparently belong to FBI agents.
“The first takeaway lesson is that organizations should design identity systems on the assumption that identity evidence may eventually be compromised. A genuine-looking document cannot remain sufficient proof of identity indefinitely. Organizations should inventory identity data and establish who collects it, why it is needed, where it flows, and when it is deleted,” NCC Group senior adviser and director Tim Rawlins said.
“Contracts with identity providers should establish requirements for logging, data segregation, retention, incident notification, access to evidence, and independent assurance. Organizations should also monitor for abnormal bulk access and potential data exfiltration, including unusual activity involving service accounts, application programming interfaces, and administrative accounts,” Rawlins added.
Individuals should avoid sharing copies of their driver’s licenses unless absolutely necessary and, when presenting an ID for verification, ask whether it can be checked without being scanned, photographed, or retained.
Related: Ransomware Gang Claims Nutex Health Data Breach
Related: 9.5 Million Impacted by Aesto Health Data Breach
Related: McKesson Confirms Data Breach as Attacker Deadline Looms
Related: Extortion Group Claims Manchester Airports Group Data Breach


