FBI Probes Dark Web Service Selling 153M+ Drivers Licenses

FBI Probes Service Selling 153M+ Drivers Licenses

FBI Probes Dark Web Service Selling 153M+ Drivers Licenses

A new dark web service called Nexus is selling scans of over 153 million U.S. and Canadian driver's licenses, including those of top government officials. KrebsOnSecurity traces the likely source to idscan.net, a Louisiana-based identity verification company, after timestamps on leaked images match car rentals and other ID scans. The FBI's New Orleans field office has opened an investigation, and the service has since gone offline.

These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe.
  1. ethagnawl

    I know some modern, normal countries have done variations of this but the US missed a golden opportunity to give everyone an RSA keypair when they were coerced into signing up for an Enhanced/REAL ID.

    Instead of scanning, taking photos of or holding licences up to webcams (I was asked to do this recently) you provide your public key or, better, a signed message containing the name, website or other identifier which gets cross-referenced by the legit provider against the id.gov database.

    Of course the devil is in the details and I wouldn't trust GrandePelotas and friends to vibe code such a system but it is absolutely possible and is something we should, at the very least, be thinking about.

  2. Nition

    The thing that really gets me about this one is that surely you can easily just delete the data after you've verified someone? But instead they decided to keep 153,347,439 of them.

  3. tgsovlerkhgsel

    If there was some kind of fixed minimum compensation - even a single dollar per affected person - and strict liability (doesn't matter how you allegedly did everything to protect the data, if it leaked it's on you), companies would suddenly be very motivated to a) secure b) minimize the data they hold.

    Without penalties, e.g. Hertz has little reason not to keep 10+ years of drivers licenses just in case they come in useful in a fraud case or as ML training data later. If having the data was a $153 million liability, they'd think twice.

  4. trollbridge

    One of the more absurd things these ID verification services do is ask for a front and back scan of your licence and then use an app that has you tilt your head around in camera.

    They obviously do not have actual access to the original photos, so a sophisticated attacker can simply forge the whole thing, but the rest of us have to update very detailed facial information + government ID documents that we all know are going to get retained indefinitely.

  5. fishfasell

    So an online identity verification service had millions of IDs exfiltrated, many of which were linked to marijuana dispensaries? Oh man, my ID is definitely out there, shit.

  6. rswail

    The main question to government is:

    1. You already know who everyone is. By definition identification as an individual is by government.

    2. Why is there not a system that allows a business or other service to ask for government identification that is encrypted and only visible to government, but that allows a business to ask for certain details, required for the operation of the business (eg confirmation of driving license, or age)?

    3. Why is that evidence not provided directly, but as a confirmation from the government service ("Yes, this person is over 18", not "Yes, this person is 37")?

    Governments need to protect the public, not allow businesses open slather on collecting PII.

  7. wolvoleo

    Ooh I thought they sold that many fake ones lol. I know fake IDs are a big thing in the US because of the really high drinking age (were I'm from it was 16). But even then it's a lot.

    But no it's about leaked data. That wasn't very clear from the title.

  8. ChrisMarshallNY

    > vendors who collect this sensitive data need to be held to a higher standard.

    They already do that, in Europe. I assume that it works, as I don’t hear about this level of stuff, over there (though it could be because I am not plugged into European news).

    One thing about the US, is that companies that have the means, can afford regulatory capture, or even strait-up bribery. This is often magnified, at the local level. I am constantly hearing anecdotal stories about the absurd levels of naked corruption, in my town. Much of this, comes from my friends, who own businesses.

    The more plugged-in we are, the more access these small, corrupt municipalities have; so a bribed bureaucrat in a small town, could have access to a national database. We’re hearing a lot about small-town cops, accessing Flock camera data.

More from this day

2026-09-02