
A substantial data breach involving driver’s licenses has been reported by cybersecurity journalist Brian Krebs, with the FBI conducting an investigation into the matter. According to the exposé published Tuesday, more than 153 million identification documents became available through a dark web marketplace called Nexus. The licenses included high-resolution scans capturing both front and back images, along with infrared and ultraviolet spectrum versions that could potentially be used to create counterfeit IDs capable of bypassing security measures such as hologram verification.
The breach appears to be unfolding in real time, with new identification documents appearing for sale within hours or days of victims presenting their IDs at businesses such as car rental agencies and cannabis dispensaries. Krebs documented that the number of available driver’s licenses increased by approximately 400,000 within a single 24-hour period. The rapid availability of scans following initial presentation suggests that the responsible party has immediate access to data from the third-party scanning service handling identity verification for multiple businesses.
Investigation has focused on IDScan.net, a New Orleans-based ID scanning company that provides services to Hertz car rental and at least 11 other establishments. The company’s scanning technology specifically captures ultraviolet and infrared spectra alongside standard images. IDScan.net representatives indicated the company is investigating the matter, though they did not provide additional details. Representatives from the affected car rental company did not respond to inquiries regarding the breach.
Beyond driver’s licenses, Nexus allegedly offered other identification documents including commercial driver’s licenses, government-issued Common Access Cards used for accessing secure federal buildings, and cannabis dispensary identification cards. The breach raises significant concerns regarding identity theft and fraud given the sophisticated nature of the scans available. The marketplace subsequently went offline shortly after the public disclosure, preventing affected individuals from verifying whether their credentials were compromised. The FBI’s ongoing investigation represents the primary official response to the incident at this time.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI