A single operation exposing tens of millions of state IDs is the kind of story that stretches beyond cybercrime headlines into consumer safety, retail operations, and public policy. Today’s piece peels back what KrebsOnSecurity reported about the so‑called Nexus service, why a likely third‑party ID vendor is central to the problem, and what immediate steps affected people and businesses should take.
In Brief
FBI Probes Service Selling 153M+ Drivers Licenses
Why this matters now: The Nexus service reportedly offered scans and security‑feature images for more than 153 million U.S. and Canadian driver’s licenses, creating immediate risk for credit fraud, identity theft, and people whose safety depends on anonymity.
A new dark‑web service calling itself “Nexus” advertised front/back images of drivers’ licenses plus infrared/ultraviolet scans and timestamps for more than 153 million records, and KrebsOnSecurity tied the data to a likely compromise at a third‑party identity‑verification vendor used by retailers, dispensaries and car rental counters. The New Orleans FBI field office has opened an investigation; Nexus even used reporter Brian Krebs’ own license as a sample and claimed, “We have been continuously exfiltrating new data for over a year into our private database.”
Deep Dive
FBI Probes Service Selling 153M+ Drivers Licenses
Why this matters now: A breach at a third‑party ID‑scanning vendor (linked in reporting to idscan.net customers) threatens tens of millions of people and exposes weaknesses in how private firms collect, store, and share identity images.
Krebs’ reporting says the Nexus listings included not just the visible front/back photos you’d expect from a scanned ID, but also images captured with infrared and ultraviolet passes and precise timestamps — the kinds of captures used by verification tools to confirm authenticity. Those IR/UV images show the card’s hidden security elements; timestamps and rental details, in several cases, point to in‑person scans at places like car rental desks and cannabis dispensaries. Together that set of metadata makes the data far more actionable than a simple name‑and‑DOB dump.
“We have been continuously exfiltrating new data for over a year into our private database.”
That quote, taken from Nexus’ listing as reproduced in the reporting, matters because it implies ongoing access rather than a one‑time leak. Ongoing exfiltration raises two related problems: first, an attacker can collect fresh, timestamped evidence tying an individual to a location or transaction; second, the vendor ecosystem that ingests and temporarily stores those scans may be an under‑protected chokepoint. Krebs’ piece links customer records and sample files to an identity‑verification provider used by recognizable brands, which suggests this was not a single careless kiosk but a vendor platform used widely.
There are a few practical consequences worth calling out now. State IDs are often the key to opening new lines of credit, setting up accounts, or bypassing additional checks. Beyond financial fraud, leaked images and security‑feature photos can endanger people who rely on anonymity or protective status. And the inclusion of IR/UV scans and timestamps makes forgery or convincing social‑engineering attacks easier because attackers can study physical security features and prove recent physical access.
What should organizations and individuals do? For consumers: freeze your credit, enable carrier protections against SIM‑swap attacks, and monitor financial accounts — the usual triage for high‑value PII exposures. Ask any business that scanned your ID how long they retain images, whether they encrypt scans at rest, and whether they’ve audited third‑party vendors. For companies that accept in‑person IDs: minimize image retention, require end‑to‑end encryption from capture to vendor, and push vendors for independent security assessments and breach‑notification guarantees.
This incident also refocuses the debate over outsourcing identity verification. Many companies outsource ID scanning because it reduces friction and shifts compliance overhead, but outsourcing concentrates risk. Several commenters in technical communities suggested a government‑backed, privacy‑preserving verification API or a zero‑trust approach to attest identity without handing over full card images. That idea is worth watching: a federated attestation model (where a verifier returns a token stating “name matches state record and card checks out” without returning the raw images) would limit the usefulness of any single vendor compromise.
Regulatory and law‑enforcement angles are moving, too. The FBI’s involvement elevates the incident from a privacy breach to a federal investigation, which could force disclosure and remediation from the vendor and its customers. Expect scrutiny not just on the vendor but on the procurement and data‑retention practices of businesses that integrated the scanning solution.
Finally, balance: while many people’s personal data already circulates on black markets, the core harm here is the scale and the richness of the dataset — high‑quality scans plus timestamps and security‑feature images. Richer datasets accelerate targeted fraud and make defensive measures like credit freezes a less effective panacea for some abuse patterns. That reality is why this single story should prompt operational changes at retailers, sharper regulatory attention, and, for individuals, immediate defensive housekeeping.
Closing Thought
A leak of 153 million driver’s licenses is not just another data breach stat — it’s a realignment of risk toward vendors that collect sensitive biometric and document images. Short of sweeping policy changes, the fastest wins are operational: stop storing raw ID images unless absolutely necessary, demand better vendor security guarantees, and take the personal steps now to lock down credit and carrier accounts. If you or your organization relies on third‑party ID scanning, treat this as a wake‑up call.