FBI Probes Service Selling 153M+ Drivers Licenses
A dark web service is selling over 153 million driver's licenses, with evidence pointing to a widely-used identity verification company, sparking an FBI probe and leaving Hacker News aghast at the sheer scale of data compromise. The incident fuels discussions on the inherent risks of third-party ID services and the urgent need for more secure, government-backed identity solutions. It's a stark reminder that your ID is probably out there, chilling with a hacker.
The Lowdown
A chilling report from KrebsOnSecurity reveals the emergence of 'Nexus,' a dark web service peddling digital scans of more than 153 million US and Canadian driver's licenses, alongside other sensitive identification documents. The author's investigation, which involved finding his own driver's license in the breached data, strongly implicates idscan.net, a Louisiana-based identity verification company used by major entities like Hertz, Target, and numerous marijuana dispensaries.
- Nexus boasted an inventory of over 153 million driver's licenses, 10 million ID cards, and millions of other documents, with records continuously exfiltrated.
- Krebs's personal driver's license, complete with infrared and ultraviolet scans, appeared in Nexus, with a timestamp aligning perfectly with a car rental event.
- Further research with friends and family corroborated the link between license scans and travel/rental activities, often involving Hertz.
- The presence of marijuana dispensary cards in the data led to Planet13, a dispensary chain, which exclusively uses idscan.net for ID verification.
- idscan.net's documentation confirms their use of infrared and ultraviolet scanning technology, matching the image types found in the breach.
- The FBI's New Orleans field office has launched an official inquiry into idscan.net following Krebs's findings.
- Shortly after the story's publication, the Nexus dark web service abruptly vanished, displaying a 'no longer available' message.
This incident vividly underscores the profound vulnerabilities created by third-party identity verification services, exposing sensitive personal data on a massive scale. Experts warn of severe security and privacy implications, including heightened risks for identity theft, credit fraud, and even dangers for individuals in witness protection programs, pushing for greater oversight and more secure authentication methods.
The Gossip
Personal Information Plight & Protection
Commenters expressed immediate alarm and a sense of personal vulnerability upon realizing the massive scale of the breach, with many assuming their own driver's licenses were likely compromised. The discussion quickly pivoted to practical advice for mitigating risk, such as locking credit and enabling strong mobile carrier protections against SIM swapping, highlighting the pervasive threat of identity theft.
API Aspirations & Assurances
A significant portion of the discussion revolved around the inherent flaws of current identity verification practices. Users questioned why private companies are allowed to collect such sensitive data and advocated for a government-provided, zero-trust API. This proposed API would enable secure identity verification without requiring individuals to hand over physical documents or expose their PII to third-party services, which many feel are ill-equipped to protect it, often facilitating 'mass fraud.' Others pointed out that legal mandates often force businesses to collect this information, leaving them with little choice but to rely on third-party solutions.