Identity Verification Is Broken. The 153 Million Driver’s Licenses Now for Sale Are Proof

Identity Verification Is Broken. The 153 Million Driver’s Licenses Now for Sale Are Proof

A dark web identity theft service is offering more than 153 million U.S. and Canadian driver’s license scans for sale, and the FBI is investigating where the data came from. The apparent breach is a particularly stark example of the problem with the modern identity verification economy where proving who you are means providing a third party with permanent copies of sensitive documents. According to KrebsOnSecurity⁠, the service, called Nexus, launched on a Russian-language cybercrime forum and claims to have more than 153 million driver’s licenses, along with more than 10 million other identification cards, more than 3 million travel documents and international IDs, and hundreds of thousands of medical cards. The number is difficult to independently verify, but Krebs found evidence suggesting the service is not simply bluffing. The database contained the licenses of Krebs himself and U.S. Defense Secretary Pete Hegseth, among other government officials. The licenses included multiple images of the documents, including front and back scans and, in some cases, infrared and ultraviolet versions. The data also appeared to be fresh. Nexus’s advertised collection grew by nearly 400,000 driver’s license records in roughly 24 hours, while the operators claimed they had been continuously exfiltrating information for more than a year. Krebs traced the apparent source to IDScan.net⁠, a New Orleans-based identity verification company. The company says its technology processes more than 21 million identity verifications every month at more than 20,000 locations around the world. IDScan.net’s customer materials show just how deeply this type of infrastructure is embedded in everyday commerce. Its official site lists companies and brands including Holiday Inn, 7-Eleven, GameStop, DraftKings, Hertz, Target, FedEx, Shell, and Caesars Entertainment among its customers or integrations. The connection is particularly striking because Krebs found that timestamps attached to several leaked licenses corresponded with trips, hotel stays, car rentals, and other real-world interactions where people handed over their IDs. IDScan.net said it is investigating the incident but has not publicly confirmed that its systems were the source of the Nexus database. The company told Krebs that it was unable to provide additional information while its investigation continued. The FBI has also opened an investigation through its New Orleans field office into the apparent breach. ‼️ New article from Brian Krebs: FBI Probes Service Selling 153M+ Drivers Licenseshttps://t.co/S5KEn9pb5v Dark Web Onion discussed: http://nexusdbbulkq5345qlqyc2iprxzsrwvavd6r5qwel3o3vxs5svg5mjyd[.]onion pic.twitter.com/HVsrjGrL9x — Dark Web Informer (@DarkWebInformer) September 2, 2026 Shortly after Krebs published its report, the Nexus site itself disappeared from the dark web and was replaced with a message saying the service was no longer available. Peter Van Valkenburgh, a longtime cryptocurrency policy advocate and Coin Center Executive Director, argued in an essay⁠ that the breach was not some bizarre one-off accident. He called the hack “inevitable” and said society is “long, long, long overdue to reduce the amount of KYC we do.” Van Valkenburgh’s argument is fundamentally about data minimization. Every time a company demands a scan of a government ID, it creates another repository containing information that can potentially be stolen, resold, or abused. “We deputize a sea of s*itty quasi-government contractors to perform data collection and monitoring,” Van Valkenburgh wrote, arguing that the resulting databases become attractive targets precisely because they contain so much valuable information in one place. The problem gets even harder to ignore as governments and companies push identity verification into more parts of daily life. Age verification, financial compliance, hotel check-ins, car rentals, gambling, cannabis sales, and online services can all require some form of ID scan. Security and privacy researcher Zach Edwards, whose own driver’s license was found in the Nexus database, told Krebs that the incident highlights the risks of outsourcing identity verification to an expanding network of third-party vendors. “These systems are putting sensitive data into more and more 3rd party vendors, and we don’t have nearly the oversight to ensure they are safe,” Edwards said. Indeed, the very systems that have been built are a contradiction in themselves. While there are increasingly sophisticated processes put in place to determine whether someone is really who they claim to be, those systems often require collecting enough information to create a devastating situation if the security surrounding the associated database fails. And this is hardly the first time the scale of the problem has become absurd. In 2025, education software company PowerSchool was breached in an attack that exposed sensitive information belonging to tens of millions of students and teachers, including Social Security numbers, dates of birth, and medical information. In 2024, AT&T also disclosed that hackers had obtained the Social Security numbers, dates of birth, phone numbers, email addresses, and other information of 73 million current and former customers. A separate incident exposed phone records belonging to nearly all of the company’s customers. Solutions are Available Technical solutions to this underlying problem of creating honey pots of sensitive customer data are available. For example, zero-knowledge proofs can allow someone to prove that they satisfy a particular condition without revealing all of the information contained in the underlying credential. Instead of handing over a complete driver’s license to prove that you are over 21, a system could theoretically verify the relevant fact without receiving your name, address, license number, and other information printed on the card. 153M drivers licenses leaked!Identity documents should only be authenticated using zero-knowledge proofs. Stop revealing all your personal details just to prove you have a valid drivers license.https://t.co/ebdV54Zk78 — Remco (@recmo) September 2, 2026 While these technologies do not magically make identity verification secure in all scenarios, they offer a way to redesign the system so that verifying someone’s identity does not create other, second-order issues. Of course, there is also a less convenient reality behind all of this in that some of the data collection is not simply a matter of companies deciding they want more information. Laws and regulations can require businesses to collect, verify, or retain identifying information in certain circumstances. In other words, changes to the regulations around personal data collection are needed on top of the adoption of various technical innovations. Whether these technical or regulatory changes will be implemented anytime soon remains to be seen. “Risk-averse compliance departments and set-in-their-ways regulators prefer old practices and the appearance of rigorous compliance—box checking—to actually protecting people through data minimization and auditable, verifiable alternatives,” wrote Van Valkenburgh.

Original Source

Read the full article at Gizmodo →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.