
A significant data breach has come to light involving the unauthorized sale of driver’s license information on the dark web. According to an investigation published this week by cybersecurity journalist Brian Krebs, a service operating under the name Nexus was offering more than 153 million driver’s licenses for purchase. The licenses included high-resolution scans capturing both front and back images, along with additional formats showing infrared and ultraviolet spectrum data—technical variations that could potentially enable the creation of counterfeit identification documents designed to bypass security features like holograms.
The breach appears to have unfolded in real time, with newly scanned licenses becoming available for sale within hours or even days of individuals presenting them at rental agencies and other businesses. Documentation obtained during the investigation indicated that the licenses may have originated from multiple sources, including commercial driver’s licenses and government-issued access cards. The service also advertised other identity documents, including marijuana dispensary cards. Over a single 24-hour period, the number of available licenses grew by approximately 400,000, suggesting the breach has been ongoing and continuously harvesting new information.
Investigation by Krebs pointed to IDScan.net, a New Orleans-based company that specializes in scanning identification documents, as a potential source of the compromised data. Public records indicated that IDScan.net has commercial relationships with multiple businesses including a major car rental company and a cannabis dispensary chain. The company announced it captures both infrared and ultraviolet image spectra as part of its scanning services. IDScan.net stated it is investigating the matter, while the FBI has also launched an investigation into the breach.
Nexus went offline shortly after the initial reporting, preventing affected individuals from independently verifying whether their personal identification information was included in the compromised database. The incident affects individuals who had their licenses scanned at businesses using IDScan.net’s services.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI