The Spectrum Dispatch News

business

153 Million U.S. Driver's Licenses Exposed in Dark Web Breach

A dark web service called Nexus claimed unauthorized access to identity verification company IDScan, putting roughly 63% of U.S. licenses at risk of identity theft and

153 Million U.S. Driver's Licenses Exposed in Dark Web Breach

Last week, cybersecurity researcher Krebs on Security reported a major breach affecting approximately 153 million driver’s licenses from U.S. and Canadian citizens, along with 3 million travel documents. According to Krebs, a dark web service called Nexus claimed it had gained unauthorized access to a major identity verification company and spent more than a year continuously exfiltrating data into a private database. The service was adding roughly 400,000 new licenses daily.

153 Million U.S. Driver’s Licenses Exposed in Dark Web Breach

Krebs verified that the driver’s licenses were genuine by confirming he found licenses belonging to himself, nine friends and family members, and high-ranking U.S. government officials including Secretary of War Pete Hegseth and an FBI assistant director. Based on circumstantial evidence, Krebs linked the breach to IDScan, an identity verification service designed to detect fraud and confirm ID authenticity. IDScan confirmed it is investigating the data breach, and the Nexus service subsequently disappeared from the dark web after Krebs published his story, though the perpetrators did not claim to have deleted the data.

The incident has national security implications beyond typical identity theft and phishing attacks. According to the source, driver’s licenses are particularly valuable intelligence tools because they are key identity documents and license numbers are often used across other databases. When combined with home addresses and photos, this data becomes significantly more useful for intelligence operations. The source notes that Chinese cyber espionage actors in the mid-2010s stole complementary data from multiple sources—including health insurance, credit reporting, hotel, airline, and security clearance databases—to analyze the U.S. intelligence apparatus and counter American intelligence efforts against China.

The breach affects roughly 63 percent of the country’s total driver’s licenses. This incident reflects a broader vulnerability: identity verification services handle enormous volumes of sensitive data but have experienced multiple breaches in recent years, including at AU10TIX, Discord’s age verification provider 5CA, and National Public Data. The FBI is investigating the breach. Law firms are already preparing class-action suits against IDScan, and regulatory attention from the Federal Trade Commission has been suggested as a necessary consequence to encourage stronger security practices.

Key facts

  • Nexus claimed unauthorized access to IDScan and exfiltrated 153 million U.S. and Canadian driver’s licenses over more than a year
  • The breach represents roughly 63% of all U.S. driver’s licenses
  • Krebs verified the licenses were genuine, finding licenses of government officials including Secretary of War Pete Hegseth
  • Intelligence agencies can use driver’s license data linked with other databases to counter intelligence operations and identify covert government activity
  • Chinese cyber espionage actors previously combined data from multiple sources to analyze the U.S. intelligence apparatus
  • IDScan confirmed it is investigating the breach; the FBI is also investigating

Sources

← All posts