top of page

Massive data leak: Over 153 million driver's licenses offered for sale on the Dark Web

Hundreds of millions of personal identity records have recently surfaced on underground markets, raising severe cybersecurity concerns for online identity verification systems. This incident directly threatens the privacy of a vast number of individuals across North America.

Scale of data listed on the Dark Web

A service specializing in trading stolen identity credentials, operating under the name Nexus, recently began offering bulk digital scans of US and Canadian driver's licenses for sale. The threat actor behind the operation also heavily promoted this stash on a Russian cybercrime forum, claiming to hold data belonging to over 170 million individuals.

Actual statistics on the Nexus platform reveal an enormous volume of illicitly obtained information:

  • Over 153 million driver's licenses: Including approximately 1.1 million records from Canada, with the vast majority belonging to US citizens.

  • Over 10 million identity cards and roughly 580,000 medical cards.

  • Over 3 million travel documents and international IDs.

The figure of 153 million driver's license records was verified by investigative journalist Brian Krebs after conducting a live blank search query directly on the Nexus system.

Suspected leak from service provider IDScan.net

The threat actor leaking the data claimed that the entire collection was exfiltrated during a prolonged intrusion targeting an identity verification provider that serves numerous Fortune 500 enterprises.

After personally searching the system and locating digital scans of his own driver's license alongside many others on Nexus, journalist Brian Krebs concluded that the breach likely originated from IDScan.net. Headquartered in Louisiana, USA, IDScan.net specializes in fraud prevention, access management, age verification, ID-activated door locks, and mobile ID scanners. The vendor processes over 21 million verifications monthly across more than 20,000 locations, serving diverse industries including banking, retail, transportation, education, entertainment, hospitality, physical security, and law enforcement.

Shortly after Brian Krebs published his report, the Nexus platform was taken offline. Although media outlet SecurityWeek reached out to IDScan.net for comment without an immediate response, the Federal Bureau of Investigation (FBI) has reportedly been briefed and launched an official investigation. Notably, several exfiltrated driver's licenses were confirmed to belong to active FBI agents.

Cybersecurity recommendations for organizations and individuals

This incident provides crucial lessons for both platform operators and consumers. According to Tim Rawlins, Senior Advisor and Director at NCC Group, organizations and individuals must fundamentally shift their data management mindset.

Below are specific core principles and mitigation measures designed to reduce risk exposure:

Target audience

Core management mindset

Specific implementation measures

Organizations & Enterprises

Assume by default that all identity documents are compromised; never treat a valid-looking document as permanent proof of secure authentication

  • Data auditing: Inventory all identity data, clearly identifying data collectors, processing purposes, data flows, and disposal schedules

  • Vendor management: Contracts with identity verification providers must strictly govern logging, data segregation, retention, independent security auditing, and mandatory incident notification

  • System monitoring: Monitor systems and configure automated alerts to block anomalous or bulk exfiltration attempts via APIs (application programming interfaces) or administrative accounts

Individuals

Minimize digitizing and leaving copies of personal identity documents with third-party services unless strictly required

  • Exercise caution when sharing: Refuse to provide copies or photographs of driver's licenses or national identity cards if deemed unnecessary

  • Proactive protection: When asked to show identification, proactively request that staff conduct a direct visual inspection (eye check) rather than allowing them to scan, photograph, or store document images in their databases

This breach serves as a critical reminder that once personal data is converted into digital form, it remains vulnerable to unauthorized access unless storage systems are comprehensively governed and secured.

Reference: SecurityWeek

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page