The FBI is investigating a dark web identity theft service that claimed to be selling access to more than 153 million U.S. and Canadian driver’s license records, although authorities have not verified the advertised total or identified the source.
The FBI confirmed Wednesday that it was investigating the report. The bureau said it was “looking into the incident” but could not comment further “due to the ongoing nature of the investigation.”
Dark web site advertises identity records
Independent cybersecurity journalist Brian Krebs reported Tuesday that a service called Nexus advertised access to digital scans of identity documents belonging to people across North America.
Nexus claimed its collection included more than 153 million driver’s license records, more than 10 million identification cards, more than 3 million travel documents or international IDs and at least 579,000 medical cards. Those figures represent records advertised by Nexus, not a verified count of affected individuals.
A blank search of Nexus returned approximately 11.5 million pages with about 15 results per page, Krebs found. The marketplace claimed it had continuously taken new data for more than a year, but authorities have not confirmed that assertion.
Krebs verifies nine records
Krebs reported that Nexus offered his own Virginia driver’s license as a free sample on a Russian cybercrime forum. Some records contained front-and-back images, infrared and ultraviolet scans and timestamps.
Krebs searched for licenses belonging to more than a dozen friends and relatives and found records for nine of them. Each person confirmed activity near the date attached to the images, including travel and car rentals.
The advertised number of driver’s license records increased by nearly 400,000 within 24 hours, according to Krebs. That increase suggested an active stream of data, although investigators have not publicly confirmed an ongoing breach.
Evidence points toward IDScan.net
Krebs matched several timestamps with transactions at businesses that used services from IDScan.net, a New Orleans-based identity-verification company. The company’s technology can scan identification documents with infrared and ultraviolet light, and IDScan.net says its systems conduct more than 21 million verifications each month at more than 20,000 locations worldwide.
IDScan.net told Krebs that it was investigating but had not confirmed unauthorized access, the source of the records or the number of people potentially affected.
“At this point I’m not able to share any additional information,” Jillian Kossman, an IDScan.net marketing and operations leader, told Krebs.
Reuters could not independently establish the source of the records, and IDScan.net did not answer the outlet’s repeated requests for comment.
Identity-scanning risks draw scrutiny
The Nexus site disappeared from the dark web shortly after Krebs published his findings. Its disappearance does not establish that copies of the records no longer exist.
“There’s never been a breach of driver’s licenses at this scale,” cybersecurity researcher Zach Edwards told Reuters. Edwards said his own license appeared on the site and warned that the exposure could create national security risks for high-profile officials.
The report also places new scrutiny on businesses and online services that require customers to surrender government-issued identification to third-party verification vendors. Unlike a password, personal information shown on a driver’s license cannot easily be changed after exposure.
The Federal Trade Commission advises people whose driver’s license information may have been exposed to contact their state motor vehicle agency and check, freeze and monitor their credit. Consumers can place and lift credit freezes for free through Equifax, Experian and TransUnion.