Nexus Dark Web Service Leaks 153M US and Canadian Driver's Licenses
A newly surfaced dark web operation called Nexus has been selling access to a trove of identity documents, including roughly 3 million travel documents and 153 million U.S. and Canadian driver’s licenses—about 63 percent of all American licenses. First reported by Krebs on Security, the service claimed to have breached a major identity verification firm and spent over a year continuously siphoning fresh records, with the database growing by nearly 400,000 licenses in a single day. Krebs verified the data as genuine, finding licenses belonging to himself, associates, and senior officials including Defense Secretary Pete Hegseth and an FBI assistant director, and linked the incident to verification vendor IDScan. The FBI and IDScan are both investigating, and Nexus went quiet shortly after the story broke—though its operators have not claimed to delete anything.
The real danger goes beyond ordinary identity theft and phishing. Driver’s licenses tie a real person to a home address, photo, and license number that recurs across other databases, making them ideal fuel for foreign intelligence services trying to correlate stolen datasets and unmask covert personnel. This is not hypothetical: Chinese APT groups previously stitched together breaches at Anthem, Equifax, Marriott, United Airlines, and OPM to counter U.S. intelligence operations, and open-source investigators like Bellingcat have used leaked databases to expose GRU officers and the Skripal poisoning suspects. Any adversary intelligence agency can be expected to hoover up leaked American identity data the same way.
Breaches at identity verification providers are becoming routine—recent incidents hit AU10TIX, Discord age-check vendor 5CA, and National Public Data—yet these firms sit on enormous volumes of sensitive records with little regulatory oversight. The author argues that meaningful government action is unlikely in the near term, leaving class-action lawsuits (already forming against IDScan) and potential FTC scrutiny as the main levers to push these companies toward better security.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.