
A significant data breach involving driver’s licenses has come to light following an investigation by cybersecurity journalist Brian Krebs. The breach exposed more than 153 million licenses through a dark web service identified as Nexus, which advertised the availability of high-resolution scans of identification documents. The exposed materials allegedly included multiple image formats of licenses, capturing not only standard visible images but also infrared and ultraviolet spectrum captures, which security experts suggest could enable the creation of counterfeit IDs capable of bypassing hologram verification systems.
The investigation identified that numerous forms of identification were being offered through Nexus, spanning driver’s licenses from multiple states as well as other document types. Some records listed sources as “CDL” for commercial driver’s licenses and “CAC” for Common Access Cards, which are government-issued credentials used to control access to federal facilities. The service also reportedly offered scans of marijuana dispensary cards, with at least one victim reportedly having used a Las Vegas location of the chain Planet13.
The timing of the breach suggests that Nexus operators had near-real-time access to scanning data. In many cases, identification documents appeared for sale within hours or a single day of being scanned at businesses such as car rental companies. Data growth patterns indicated rapid expansion, with approximately 400,000 new driver’s licenses becoming available within a 24-hour period. This pattern suggests the breach was ongoing and actively acquiring new documents.
Investigation pointed to IDScan.net, a New Orleans-based identification scanning service, as a potential source. The company operates an exclusive arrangement with Planet13 and provides scanning services to Hertz and approximately 11 other businesses. IDScan.net’s service specifications indicate capabilities to capture both infrared and ultraviolet spectra of identification documents. The company stated it was investigating the matter, though representatives did not immediately respond to detailed inquiries. The FBI initiated an investigation into the breach. The Nexus service went offline shortly after the story became public, limiting the ability of affected individuals to verify whether their documents were included in the exposed database.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI