AI Security AI安全 5h ago Updated 2h ago 更新于 2小时前 46

FBI Probes Service Selling 153M+ Drivers Licenses FBI调查出售1.53亿+驾照信息的服务

A dark web service called Nexus is selling digital scans of over 153 million U.S. and Canadian drivers licenses, plus millions of additional identity documents The data appears to originate from a breach at a Louisiana-based identity verification company serving Fortune 500 clients, with exfiltration ongoing for over a year FBI's New Orleans field office has launched an official inquiry into the source of the stolen images Timestamps on the license scans correlate with real-world events such as 暗网新服务Nexus泄露超1.53亿张美加驾照及大量身份文件,数据疑似来自路易斯安那州某身份验证公司 泄露数据包含红外/紫外图像、时间戳,且持续以每日约40万条速度更新 FBI新奥尔良办事处已启动正式调查,美国国防部长等高级官员驾照也在列 时间戳与受害者租车/旅行记录高度吻合,初步排除机场安检泄露可能

72
Hot 热度
68
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • A dark web service called Nexus is selling digital scans of over 153 million U.S. and Canadian drivers licenses, plus millions of additional identity documents
  • The data appears to originate from a breach at a Louisiana-based identity verification company serving Fortune 500 clients, with exfiltration ongoing for over a year
  • FBI's New Orleans field office has launched an official inquiry into the source of the stolen images
  • Timestamps on the license scans correlate with real-world events such as car rentals and travel, suggesting the data is captured during active identity verification processes
  • The dataset includes high-profile individuals, including U.S. Defense Secretary Pete Hegseth, and contains multi-spectral images (infrared, ultraviolet) indicating access to professional-grade verification equipment

Why It Matters

This breach represents one of the largest compilations of government-issued identity documents ever sold on the dark web, directly compromising the privacy and security of over 153 million individuals. For AI and cybersecurity practitioners, it highlights the critical risk posed by third-party identity verification vendors that aggregate sensitive biometric and document data, and underscores the need for stricter data handling audits across the verification supply chain.

Technical Details

  • The Nexus service provides search access to a database containing 153M+ drivers licenses, 10M+ ID cards, 3M+ travel documents, and 579K+ medical cards, with records growing by approximately 400,000 drivers license entries within a 24-hour window
  • Each compromised record can include up to six image files: three pairs of front/back license photos, a basic scan, and infrared and ultraviolet versions, with timestamps appended to filenames
  • Timestamp analysis across multiple verified records correlates with real-world activities such as car rentals (Hertz) and travel, with timezones appearing to align with GMT
  • The data source is attributed to a major identity verification company in Louisiana whose client base includes multiple Fortune 500 companies, suggesting the breach exploits the document capture infrastructure used during customer onboarding and KYC (Know Your Customer) verification flows
  • The dataset also contains records marked with source notations such as "CDL" (commercial drivers license) and "CAC" (Common Access Cards), indicating the breach extends beyond standard consumer licenses into government and specialized identity documents

Industry Insight

  • Organizations relying on third-party identity verification vendors must urgently audit their providers' security postures, data retention policies, and access controls, as a single compromised vendor can expose millions of customers across multiple Fortune 500 companies simultaneously
  • The continuous exfiltration over more than a year suggests the breach may involve insider access or persistent unauthorized API/database access, reinforcing the need for real-time data loss prevention monitoring and anomaly detection on identity verification pipelines
  • The inclusion of multi-spectral license images indicates the source has access to professional verification hardware, not just standard camera captures; companies should evaluate whether their verification partners are implementing proper device security, encryption at rest, and strict access logging on all document capture endpoints

TL;DR

  • 暗网新服务Nexus泄露超1.53亿张美加驾照及大量身份文件,数据疑似来自路易斯安那州某身份验证公司
  • 泄露数据包含红外/紫外图像、时间戳,且持续以每日约40万条速度更新
  • FBI新奥尔良办事处已启动正式调查,美国国防部长等高级官员驾照也在列
  • 时间戳与受害者租车/旅行记录高度吻合,初步排除机场安检泄露可能

为什么值得看

该事件揭示了身份验证产业链的数据安全漏洞,对依赖第三方验证的金融机构和科技企业具有直接警示意义。同时展示了暗网数据交易的技术细节和验证方法,为安全研究者提供了新型数据泄露的分析样本。

技术解析

  • 数据来源推测:泄露图像带有精确时间戳,与受害者租车记录(如Hertz)高度吻合,排除机场安检场景,指向身份验证服务商的API接口或数据库泄露
  • 数据特征:包含多光谱图像(普通/红外/紫外)、时间戳文件名、部分记录标注来源类型(CDL商用驾照、CAC政府门禁卡)
  • 验证方法:记者通过提供个人驾照作为免费样本验证数据真实性,并交叉比对9位亲友的旅行记录确认时间戳关联性
  • 规模验证:空搜索返回1150万页结果(每页15条),美国记录占绝对多数,加拿大安大略省占47.3万条

行业启示

  • 身份验证服务商需立即进行安全审计,Fortune 500企业客户应重新评估第三方数据供应商的风险管控
  • 建议企业建立驾照图像泄露监测机制,对时间戳异常的数据源进行溯源分析
  • 个人应定期检查自身身份信息是否在暗网流通,对涉及多光谱图像泄露的记录需警惕身份盗用风险

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究