
A massive data breach involving driver’s licenses has come to light following an investigation by cybersecurity journalist Brian Krebs. The breach appears to center on Nexus, a dark web marketplace offering more than 153 million driver’s licenses for sale. According to reporting published earlier this week, the compromised licenses include high-resolution scans capturing both front and back images, as well as infrared and ultraviolet spectrum data, which could potentially be used to create counterfeit IDs capable of bypassing hologram security features.
The breach came to attention after the author rented an SUV from a major car rental company. Within hours of an employee scanning the driver’s license at the rental counter, a complete scan appeared for sale on the dark web marketplace. Similar incidents were reported by other individuals, including the journalist investigating the matter, his family members, and various security researchers. The FBI is reportedly investigating the incident.
Evidence suggests the compromised data is being sourced in real time from third-party ID scanning services used by businesses. Records observed included source notations such as “CDL” for commercial driver’s licenses and “CAC” for Common Access Cards, which provide physical access to government facilities. Additional document types offered through the marketplace included marijuana dispensary cards. The rapid availability of scans—often within hours of being presented to businesses—indicates the breach involves near-real-time access to data flowing through the scanning infrastructure.
Investigations point toward IDScan.net, a New Orleans-based ID scanning company that has announced exclusive arrangements with various businesses including a major car rental company and a multi-state dispensary chain. IDScan representatives indicated the company is investigating, and the car rental company involved has been contacted for comment. The Nexus marketplace went offline shortly after the reporting was published, preventing affected individuals from determining whether their information was included in the breach.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI