Over 150m driver’s licenses posted on dark web after data breach 

The breach reportedly dumped driver’s licenses onto the dark web, exposing names, addresses, and other sensitive information

A staggering trove of more than 150 million driver's licenses has reportedly surfaced on the dark web | ©Image Credit: Facebook / New York State Department of Motor Vehicles
A staggering trove of more than 150 million driver's licenses has reportedly surfaced on the dark web | ©Image Credit: Facebook / New York State Department of Motor Vehicles

A person’s driver’s license is supposed to be proof of who they are. Now, according to a new investigation, someone is allegedly selling millions of those IDs on the dark web. A cybercrime service called Nexus reportedly claimed to have access to 153 million U.S. and Canadian driver’s licenses, along with millions of other identification and travel documents. The FBI is investigating.

And these aren’t just lists of names and numbers. The trove reportedly contains digital scans of actual government-issued IDs, potentially including information such as addresses, birthdays, license numbers and photos.

A nightmare-sized identity theft buffet

The story came to light after cybersecurity journalist Brian Krebs was alerted to a post on the Russian cybercrime forum Exploit. The seller advertised access to identity documents belonging to more than 170 million people across North America. As proof, the service reportedly offered Krebs’ own Virginia driver’s license as a free sample.

According to Krebs, unlocking the full details of the license cost $100. The service claimed its database contained 153 million driver’s licenses from the U.S. and Canada, more than 10 million identification cards, more than 3 million travel documents, and at least 579,000 medical cards.

Those numbers have not been independently verified, and the Nexus service has since disappeared. But the FBI has confirmed that it is looking into the incident.

These are ID scans

A leaked password is bad. You can change it. But a leaked driver’s license is considerably harder to deal with. A high-quality image of a government ID can give scammers a ready-made collection of information for impersonating someone. That information can potentially be combined with data stolen in other breaches to target victims with convincing phishing attacks or attempt to open accounts in their names.

Beyond that, security experts warn that stolen ID photos and other personal information could potentially be used alongside AI-generated deepfakes to make impersonation scams even more convincing. People’s faces, unfortunately, don’t come with a “change password” button.

If the claims are accurate, experts say this could rank among the largest leaks involving government-issued identification. And stolen ID data doesn’t necessarily lose its value quickly. Unlike a credit card number, a driver’s license contains information that can remain useful for years. Even if someone replaces their license, criminals may still have the original image and can combine it with information from future or previous breaches.

Where did the IDs come from?

According to the claims made by Nexus, the documents came from an ongoing breach at a major identity-verification company used by multiple Fortune 500 companies. The service reportedly claimed it had been continuously stealing new data for more than a year.

One New Orleans-based identity-verification company, IDScan.net, has been linked to the investigation after the company said it was looking into an incident. But there is no confirmed public evidence yet that it was the source of the leaked IDs.

Are you caught up in this?

If you are worried your information may have been caught up in this or another breach, the best way out, as recommended by experts, is to make yourself a much harder target. To start with, freeze your credit. A credit freeze can make it significantly harder for someone to open new credit accounts in your name.

You can also place a fraud alert on your credit files and keep a close eye on financial accounts for anything suspicious.

And going forward, think twice before handing over a scan of your driver’s license to a random website or service. Ask why it is needed, how the information will be stored and how long it will be retained. Because the more companies that collect copies of your identity, the more places there are for that identity to get out there. And remember, unlike a password, you can’t simply log in and change your face.

Sources: UNILAD, TIME