I rented a car, and within hours, my driver's license was for sale
Over 153 million driver's licenses and other government-issued IDs were listed for sale on Nexus, a dark web marketplace, with scans including infrared and ultraviolet spectrum images capable of bypassing hologram verification The breach appears linked to IDScan.net, a New Orleans-based scanning service used by major companies including Hertz and dispensary chain Planet13, with new records appearing within hours of being scanned The scale of the breach—growing by approximately 400,000 licenses p
Analysis
TL;DR
- Over 153 million driver's licenses and other government-issued IDs were listed for sale on Nexus, a dark web marketplace, with scans including infrared and ultraviolet spectrum images capable of bypassing hologram verification
- The breach appears linked to IDScan.net, a New Orleans-based scanning service used by major companies including Hertz and dispensary chain Planet13, with new records appearing within hours of being scanned
- The scale of the breach—growing by approximately 400,000 licenses per day—suggests a sustained, near real-time data exfiltration operation rather than a one-time dump
- High-profile victims include journalist Brian Krebs, his mother, an FBI assistant director, and multiple security researchers, indicating the threat landscape extends to those investigating cybercrime
- Nexus went dark shortly after the KrebsOnSecurity exposé, and the FBI is actively investigating, though victims currently have no way to verify whether their data was compromised
Why It Matters
This breach represents a severe escalation in identity theft capabilities, as the inclusion of infrared and ultraviolet scans could allow counterfeit IDs to pass security checks that previously relied on multi-spectral verification. For AI and cybersecurity practitioners, it underscores the critical risk of third-party data processors and the need for rigorous vendor security audits, especially in industries handling sensitive personal information.
Technical Details
- Nexus marketplace offered multi-spectral ID scans (visible, infrared, and ultraviolet) for driver's licenses, Common Access Cards (CAC), medical cards, travel cards, employment authorizations, and marijuana dispensary cards
- The scanning service IDScan.net explicitly advertises the capture of both infrared and ultraviolet spectra, matching the data quality found on Nexus
- Data appeared on the dark web within hours to a day of victims presenting their IDs at rental car companies or dispensaries, indicating a near real-time exfiltration pipeline through the third-party scanning infrastructure
- The breach grew by approximately 400,000 driver's license records in a 24-hour window, suggesting automated, continuous data harvesting rather than a static leaked database
- IDScan.net has an exclusive arrangement with Planet13 and serves at least 11 other companies, including Hertz, widening the potential attack surface across multiple industries
Industry Insight
- Organizations relying on third-party ID verification or scanning services must conduct immediate security assessments of their vendors, including evaluating data handling practices, access controls, and encryption standards throughout the scanning pipeline
- The multi-spectral nature of this breach means affected individuals should consider more than just credit monitoring—physical identity theft via counterfeit IDs is now a tangible risk, and victims may need to explore enhanced identity protection services
- The rapid takedown of Nexus after public exposure highlights the ephemeral nature of dark web marketplaces; companies should assume breach data persists in mirrored or relocated forms and prepare for long-term incident response scenarios
Disclaimer: The above content is generated by AI and is for reference only.