Back Infosecurity-Magazine FBI Probes Possible Breach of 153 Million Driver’s Licenses
The FBI is reportedly investigating a potentially massive breach of identity data that may have swept up the details of as many as 170 million North Americans.
First revealed by investigative journalist Brian Krebs, the “Nexus” service offered access to digital scans of identity documents to users of the Exploit Russian cybercrime forum.
It apparently claimed to have over 153 million driver’s licenses for mainly American as well as Canadian drivers, alongside ID cards, travel documents, medical cards and more.
The operators of Nexus reportedly claimed the trove came from an active breach at “a major identity verification company.”
Although the Nexus service went dark shortly after Krebs published his post, he managed to track activity from his own and other identified victims’ movements to link the data to New Orleans-based identity verification provider IDScan.net.
The firm said it is currently investigating the matter.
Understanding the Impact
Seemant Sehgal, founder and CEO of BreachLock, said the incident may have far-reaching consequences.
"A license contains the owner's date of birth, address, physical descriptors, and a government-issued ID number. This is enough data to pass identity verification checks that most financial institutions and government agencies still treat as reliable,” he explained.
“The harder problem is that unlike a compromised password, none of those fields can be changed, so every person in this dataset will carry this exposure with them for life. It's good that this isn't being taken lightly, but it may be time to raise the standard for ID verification checks."
Denis Calderone, CTO at Suzu Labs, argued that businesses using identity verification vendors need to ask harder questions how long scans are retained after verification, if there are contractual data minimization obligations, and whether they can audit said firms.
"Right now there is no infrastructure analogous to a credit freeze that lets someone flag a compromised driver's license number,” he added.
“Every organization collecting and centralizing government-issued identity documents needs to treat those data stores with at least the same security posture they'd apply to payment card data, if not higher. You can get a new credit card number in 24 hours. You can't get a new face."
UK Cyber Cops 225 Million Passwords with Breach Site News 21 December 2021
UK Cyber Cops 225 Million Passwords with Breach Site
FBI and French Police Shutter BreachForums Domain Again News 13 October 2025
FBI and French Police Shutter BreachForums Domain Again
Data Breach Site WeLeakInfo Suspended as Feds Swoop News 17 January 2020
Data Breach Site WeLeakInfo Suspended as Feds Swoop
FBI Warns Parents of Edtech Security Risk News 18 September 2018
FBI Warns Parents of Edtech Security Risk
Someone’s got to pay Magazine Feature 1 July 2008
What’s Hot on Infosecurity Magazine?
65% of Enterprises Have Seen AI Agents Act Out of Scope
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Healthcare Giant McKesson Investigates Data Breach Incident
Manchester Airports Group Hit by Cyber Incident
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
Manchester Airports Group Hit by Cyber Incident
DDoS Attack Hits Norwegian Government Services
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
Linux Foundation Introduces TRACE Standard for AI Runtime Evidence
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How To Enhance Security Operations with AI-Powered Defenses
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Dispelling the Myths of Defense-Grade Cybersecurity
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
Revisiting CIA: Developing Your Security Strategy in the SaaS Shared Reality
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
