Skip to content
Breaking:

FBI Investigates Dark Web Sale of 153 Million Scanned Driver's Licenses and Identity Cards

High-resolution ID scans captured in infrared and ultraviolet spectra were listed on dark web marketplace Nexus shortly after consumers presented them at rental car agencies and storefronts.

By The Company Wire4 min read
Share
IDScan.net — FBI Investigates Dark Web Sale of 153 Million Scanned Driver's Licenses and Identity Cards
IDScan.net — FBI Investigates Dark Web Sale of 153 Million Scanned Driver's Licenses and Identity Cards. Photo: Ars Technica.

Federal law enforcement authorities are investigating a massive data breach involving an illicit dark web platform that offered more than 153 million stolen identity documents for sale, with some driver's licenses appearing online mere hours after being scanned at commercial storefronts, as first reported by Ars Technica following an inquiry by security research publication KrebsOnSecurity.

The illicit digital marketplace, known as Nexus, compiled high-resolution digital scans containing both the front and back of physical identification cards. Beyond standard photographic records, the compromised data packages included specialized image captures rendered in the infrared and ultraviolet light spectrums. Security experts emphasize that multi-spectrum image formats are typically generated by commercial verification hardware to assess document validity, meaning their exposure could allow bad actors to produce forged physical identification cards capable of defeating automated hologram checks.

The vast database encompassed personal credentials from a broad spectrum of the population, impacting ordinary consumers as well as prominent public figures and security experts. Confirmed entries in the repository included driver's licenses belonging to security journalist Brian Krebs, his mother, an assistant director at the Federal Bureau of Investigation, multiple cybersecurity researchers, and an Ars Technica reporter who had rented an SUV shortly before their data surfaced online.

In addition to standard state-issued driver's licenses, Nexus advertised a variety of specialized government and commercial identity documents. Listings on the service contained source notations labeled "CDL," indicating commercial driver's licenses, as well as "CAC," a designation for Common Access Cards issued by the U.S. government to grant personnel physical access to federal buildings and restricted installations. The service also offered scans of state medical and recreational marijuana dispensary cards, with one victim confirming a recent visit to a Las Vegas location of cannabis dispensary operator Planet 13.

The continuous flow of recently scanned credentials—frequently surfacing on Nexus within hours or a day of physical presentation at corporate counters—indicates that the perpetrators held active, real-time access to live data feeds routed through identity verification software. Demonstrating the active nature of the compromise, security researchers observed the repository expand by nearly 400,000 driver's licenses over a single 24-hour window, confirming that the breach was generating new records continuously rather than relying on a static historical data dump.

Investigative findings linked the specific multi-spectral file formats back to processing technology developed by IDScan.net, an identity verification software developer based in New Orleans. IDScan.net has historically highlighted its technology's ability to scan documents across both infrared and ultraviolet spectra. Public promotional materials from IDScan.net listed an exclusive vendor agreement with Planet 13, alongside client relationships with car rental giant Hertz and at least 11 other corporate entities using its scanning solutions.

Following outreach from researchers, a spokesperson for IDScan.net informed KrebsOnSecurity that the firm was conducting an investigation into the matter, though neither IDScan.net nor major rental car companies immediately provided further responses to press inquiries. Within hours of the initial KrebsOnSecurity report detailing the breach, the Nexus platform ceased operations and went offline. Although the site's shutdown leaves affected individuals unable to verify whether their personal records were compromised, the FBI's ongoing law enforcement investigation remains active.

Sources

  1. Ars Technica

Company: IDScan.net

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.