AI News AI资讯 14h ago Updated 9h ago 更新于 9小时前 44

I rented a car, and within hours, my driver's license was for sale 我租了一辆车,几小时内我的驾照就被挂上了暗网

Over 153 million driver's licenses and other government-issued IDs were listed for sale on Nexus, a dark web marketplace, with scans including infrared and ultraviolet spectrum images capable of bypassing hologram verification The breach appears linked to IDScan.net, a New Orleans-based scanning service used by major companies including Hertz and dispensary chain Planet13, with new records appearing within hours of being scanned The scale of the breach—growing by approximately 400,000 licenses p Nexus暗网服务泄露超1.53亿张驾照信息,含红外/紫外多光谱扫描数据 数据通过IDScan.net第三方扫描服务实时获取,24小时内新增近40万条记录 多光谱扫描技术可使克隆假证通过全息图验证测试 FBI已介入调查,服务在报道发布后数小时内关闭

62
Hot 热度
68
Quality 质量
58
Impact 影响力

Analysis 深度分析

TL;DR

  • Over 153 million driver's licenses and other government-issued IDs were listed for sale on Nexus, a dark web marketplace, with scans including infrared and ultraviolet spectrum images capable of bypassing hologram verification
  • The breach appears linked to IDScan.net, a New Orleans-based scanning service used by major companies including Hertz and dispensary chain Planet13, with new records appearing within hours of being scanned
  • The scale of the breach—growing by approximately 400,000 licenses per day—suggests a sustained, near real-time data exfiltration operation rather than a one-time dump
  • High-profile victims include journalist Brian Krebs, his mother, an FBI assistant director, and multiple security researchers, indicating the threat landscape extends to those investigating cybercrime
  • Nexus went dark shortly after the KrebsOnSecurity exposé, and the FBI is actively investigating, though victims currently have no way to verify whether their data was compromised

Why It Matters

This breach represents a severe escalation in identity theft capabilities, as the inclusion of infrared and ultraviolet scans could allow counterfeit IDs to pass security checks that previously relied on multi-spectral verification. For AI and cybersecurity practitioners, it underscores the critical risk of third-party data processors and the need for rigorous vendor security audits, especially in industries handling sensitive personal information.

Technical Details

  • Nexus marketplace offered multi-spectral ID scans (visible, infrared, and ultraviolet) for driver's licenses, Common Access Cards (CAC), medical cards, travel cards, employment authorizations, and marijuana dispensary cards
  • The scanning service IDScan.net explicitly advertises the capture of both infrared and ultraviolet spectra, matching the data quality found on Nexus
  • Data appeared on the dark web within hours to a day of victims presenting their IDs at rental car companies or dispensaries, indicating a near real-time exfiltration pipeline through the third-party scanning infrastructure
  • The breach grew by approximately 400,000 driver's license records in a 24-hour window, suggesting automated, continuous data harvesting rather than a static leaked database
  • IDScan.net has an exclusive arrangement with Planet13 and serves at least 11 other companies, including Hertz, widening the potential attack surface across multiple industries

Industry Insight

  • Organizations relying on third-party ID verification or scanning services must conduct immediate security assessments of their vendors, including evaluating data handling practices, access controls, and encryption standards throughout the scanning pipeline
  • The multi-spectral nature of this breach means affected individuals should consider more than just credit monitoring—physical identity theft via counterfeit IDs is now a tangible risk, and victims may need to explore enhanced identity protection services
  • The rapid takedown of Nexus after public exposure highlights the ephemeral nature of dark web marketplaces; companies should assume breach data persists in mirrored or relocated forms and prepare for long-term incident response scenarios

TL;DR

  • Nexus暗网服务泄露超1.53亿张驾照信息,含红外/紫外多光谱扫描数据
  • 数据通过IDScan.net第三方扫描服务实时获取,24小时内新增近40万条记录
  • 多光谱扫描技术可使克隆假证通过全息图验证测试
  • FBI已介入调查,服务在报道发布后数小时内关闭

为什么值得看

该事件揭示了第三方身份验证服务存在的数据链安全漏洞,多光谱扫描技术的滥用可能颠覆现有证件防伪体系。对AI从业者而言,这凸显了生物识别数据保护与多模态验证技术安全性的紧迫性。

技术解析

  • IDScan.net服务采用红外/紫外多光谱成像技术,可捕获证件全息图特征数据
  • 数据通过租车公司/药店等终端扫描设备实时传输至第三方服务器
  • 泄露数据包含SSN、地址等敏感信息,支持制作可绕过物理验证的克隆证件
  • 数据增长速率达16,000条/小时,表明存在自动化数据采集管道

行业启示

  • 第三方数据服务商需建立端到端加密与访问审计机制
  • 证件防伪标准应升级至抗多光谱克隆技术
  • 企业应限制敏感数据在第三方服务的留存周期与访问权限

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究