{"id":2125812,"date":"2026-09-02T23:48:27","date_gmt":"2026-09-02T20:48:27","guid":{"rendered":"https:\/\/analyse.optim.biz\/?p=2125812"},"modified":"2026-09-02T23:48:27","modified_gmt":"2026-09-02T20:48:27","slug":"identity-verification-is-broken-the-153-million-drivers-licenses-now-for-sale-are-proof","status":"publish","type":"post","link":"https:\/\/analyse.optim.biz\/?p=2125812","title":{"rendered":"Identity Verification Is Broken. The 153 Million Driver\u2019s Licenses Now for Sale Are Proof"},"content":{"rendered":"<p>[analyse_image type=&#8221;featured&#8221; src=&#8221;https:\/\/gizmodo.com\/app\/uploads\/2026\/09\/id-scan-1200&#215;675.jpg&#8221;]<\/p>\n<article class=\"post-2000806437 post type-post status-publish format-standard has-post-thumbnail hentry category-privacy-and-security tag-coin-center tag-dark-web tag-data-breaches tag-data-security tag-fbi tag-krebs\">\n<div class=\"entry-content prose dark:prose-invert lg:prose-xl prose-main dark:prose-main\">\n<p>A dark web identity theft service is offering more than 153 million U.S. and Canadian driver\u2019s license scans for sale, and the FBI is investigating where the data came from. The apparent breach is a particularly stark example of the problem with the modern identity verification economy where proving who you are means providing a third party with permanent copies of sensitive documents.<\/p>\n<div class=\"not-prose my-8 escape-mx sm:max-w-xl sm:mx-auto\"><\/div>\n<p>According to KrebsOnSecurity\u2060, the service, called Nexus, launched on a Russian-language cybercrime forum and claims to have more than 153 million driver\u2019s licenses, along with more than 10 million other identification cards, more than 3 million travel documents and international IDs, and hundreds of thousands of medical cards.<\/p>\n<p>The number is difficult to independently verify, but Krebs found evidence suggesting the service is not simply bluffing. The database contained the licenses of Krebs himself and U.S. Defense Secretary Pete Hegseth, among other government officials. The licenses included multiple images of the documents, including front and back scans and, in some cases, infrared and ultraviolet versions.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos1\" class=\"Mobile_Pos1 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_1\" class=\"Content_1 od-desktop\"><\/div>\n<\/div>\n<p>The data also appeared to be fresh. Nexus\u2019s advertised collection grew by nearly 400,000 driver\u2019s license records in roughly 24 hours, while the operators claimed they had been continuously exfiltrating information for more than a year.<\/p>\n<p>Krebs traced the apparent source to IDScan.net\u2060, a New Orleans-based identity verification company. The company says its technology processes more than 21 million identity verifications every month at more than 20,000 locations around the world.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos2\" class=\"Mobile_Pos2 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_2\" class=\"Content_2 od-desktop\"><\/div>\n<\/div>\n<p>IDScan.net\u2019s customer materials show just how deeply this type of infrastructure is embedded in everyday commerce. Its official site lists companies and brands including Holiday Inn, 7-Eleven, GameStop, DraftKings, Hertz, Target, FedEx, Shell, and Caesars Entertainment among its customers or integrations.<\/p>\n<p>The connection is particularly striking because Krebs found that timestamps attached to several leaked licenses corresponded with trips, hotel stays, car rentals, and other real-world interactions where people handed over their IDs.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos3\" class=\"Mobile_Pos3 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_3\" class=\"Content_3 od-desktop\"><\/div>\n<\/div>\n<p>IDScan.net said it is investigating the incident but has not publicly confirmed that its systems were the source of the Nexus database. The company told Krebs that it was unable to provide additional information while its investigation continued. The FBI has also opened an investigation through its New Orleans field office into the apparent breach.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">\u203c\ufe0f New article from Brian Krebs: FBI Probes Service Selling 153M+ Drivers Licenseshttps:\/\/t.co\/S5KEn9pb5v<\/p>\n<p>Dark Web Onion discussed: http:\/\/nexusdbbulkq5345qlqyc2iprxzsrwvavd6r5qwel3o3vxs5svg5mjyd[.]onion pic.twitter.com\/HVsrjGrL9x<\/p>\n<p>\u2014 Dark Web Informer (@DarkWebInformer) September 2, 2026<\/p>\n<\/blockquote>\n<p>Shortly after Krebs published its report, the Nexus site itself disappeared from the dark web and was replaced with a message saying the service was no longer available.<\/p>\n<p>Peter Van Valkenburgh, a longtime cryptocurrency policy advocate and Coin Center Executive Director, argued in an essay\u2060 that the breach was not some bizarre one-off accident. He called the hack \u201cinevitable\u201d and said society is \u201clong, long, long overdue to reduce the amount of KYC we do.\u201d<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos4\" class=\"Mobile_Pos4 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_4\" class=\"Content_4 od-desktop\"><\/div>\n<\/div>\n<p>Van Valkenburgh\u2019s argument is fundamentally about data minimization. Every time a company demands a scan of a government ID, it creates another repository containing information that can potentially be stolen, resold, or abused.<\/p>\n<p>\u201cWe deputize a sea of s*itty quasi-government contractors to perform data collection and monitoring,\u201d Van Valkenburgh wrote, arguing that the resulting databases become attractive targets precisely because they contain so much valuable information in one place.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos5\" class=\"Mobile_Pos5 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_5\" class=\"Content_5 od-desktop\"><\/div>\n<\/div>\n<p>The problem gets even harder to ignore as governments and companies push identity verification into more parts of daily life. Age verification, financial compliance, hotel check-ins, car rentals, gambling, cannabis sales, and online services can all require some form of ID scan.<\/p>\n<p>Security and privacy researcher Zach Edwards, whose own driver\u2019s license was found in the Nexus database, told Krebs that the incident highlights the risks of outsourcing identity verification to an expanding network of third-party vendors. \u201cThese systems are putting sensitive data into more and more 3rd party vendors, and we don\u2019t have nearly the oversight to ensure they are safe,\u201d Edwards said.<\/p>\n<p>Indeed, the very systems that have been built are a contradiction in themselves. While there are increasingly sophisticated processes put in place to determine whether someone is really who they claim to be, those systems often require collecting enough information to create a devastating situation if the security surrounding the associated database fails.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos6\" class=\"Mobile_Pos6 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_6\" class=\"Content_6 od-desktop\"><\/div>\n<\/div>\n<p>And this is hardly the first time the scale of the problem has become absurd. In 2025, education software company PowerSchool was breached in an attack that exposed sensitive information belonging to tens of millions of students and teachers, including Social Security numbers, dates of birth, and medical information. In 2024, AT&amp;T also disclosed that hackers had obtained the Social Security numbers, dates of birth, phone numbers, email addresses, and other information of 73 million current and former customers. A separate incident exposed phone records belonging to nearly all of the company\u2019s customers.<\/p>\n<h1>Solutions are Available<\/h1>\n<p>Technical solutions to this underlying problem of creating honey pots of sensitive customer data are available. For example, zero-knowledge proofs can allow someone to prove that they satisfy a particular condition without revealing all of the information contained in the underlying credential. Instead of handing over a complete driver\u2019s license to prove that you are over 21, a system could theoretically verify the relevant fact without receiving your name, address, license number, and other information printed on the card.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">153M drivers licenses leaked!<br \/>Identity documents should only be authenticated using zero-knowledge proofs. Stop revealing all your personal details just to prove you have a valid drivers license.https:\/\/t.co\/ebdV54Zk78<\/p>\n<p>\u2014 Remco (@recmo) September 2, 2026<\/p>\n<\/blockquote>\n<p>While these technologies do not magically make identity verification secure in all scenarios, they offer a way to redesign the system so that verifying someone\u2019s identity does not create other, second-order issues.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos7\" class=\"Mobile_Pos7 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_7\" class=\"Content_7 od-desktop\"><\/div>\n<\/div>\n<p>Of course, there is also a less convenient reality behind all of this in that some of the data collection is not simply a matter of companies deciding they want more information. Laws and regulations can require businesses to collect, verify, or retain identifying information in certain circumstances. In other words, changes to the regulations around personal data collection are needed on top of the adoption of various technical innovations.<\/p>\n<p>Whether these technical or regulatory changes will be implemented anytime soon remains to be seen. \u201cRisk-averse compliance departments and set-in-their-ways regulators prefer old practices and the appearance of rigorous compliance\u2014box checking\u2014to actually protecting people through data minimization and auditable, verifiable alternatives,\u201d wrote Van Valkenburgh.<\/p>\n<\/p><\/div>\n<\/article>\n<div class=\"entry-content prose dark:prose-invert lg:prose-xl prose-main dark:prose-main\">\n<p>A dark web identity theft service is offering more than 153 million U.S. and Canadian driver\u2019s license scans for sale, and the FBI is investigating where the data came from. The apparent breach is a particularly stark example of the problem with the modern identity verification economy where proving who you are means providing a third party with permanent copies of sensitive documents.<\/p>\n<div class=\"not-prose my-8 escape-mx sm:max-w-xl sm:mx-auto\"><\/div>\n<p>According to KrebsOnSecurity\u2060, the service, called Nexus, launched on a Russian-language cybercrime forum and claims to have more than 153 million driver\u2019s licenses, along with more than 10 million other identification cards, more than 3 million travel documents and international IDs, and hundreds of thousands of medical cards.<\/p>\n<p>The number is difficult to independently verify, but Krebs found evidence suggesting the service is not simply bluffing. The database contained the licenses of Krebs himself and U.S. Defense Secretary Pete Hegseth, among other government officials. The licenses included multiple images of the documents, including front and back scans and, in some cases, infrared and ultraviolet versions.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos1\" class=\"Mobile_Pos1 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_1\" class=\"Content_1 od-desktop\"><\/div>\n<\/div>\n<p>The data also appeared to be fresh. Nexus\u2019s advertised collection grew by nearly 400,000 driver\u2019s license records in roughly 24 hours, while the operators claimed they had been continuously exfiltrating information for more than a year.<\/p>\n<p>Krebs traced the apparent source to IDScan.net\u2060, a New Orleans-based identity verification company. The company says its technology processes more than 21 million identity verifications every month at more than 20,000 locations around the world.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos2\" class=\"Mobile_Pos2 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_2\" class=\"Content_2 od-desktop\"><\/div>\n<\/div>\n<p>IDScan.net\u2019s customer materials show just how deeply this type of infrastructure is embedded in everyday commerce. Its official site lists companies and brands including Holiday Inn, 7-Eleven, GameStop, DraftKings, Hertz, Target, FedEx, Shell, and Caesars Entertainment among its customers or integrations.<\/p>\n<p>The connection is particularly striking because Krebs found that timestamps attached to several leaked licenses corresponded with trips, hotel stays, car rentals, and other real-world interactions where people handed over their IDs.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos3\" class=\"Mobile_Pos3 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_3\" class=\"Content_3 od-desktop\"><\/div>\n<\/div>\n<p>IDScan.net said it is investigating the incident but has not publicly confirmed that its systems were the source of the Nexus database. The company told Krebs that it was unable to provide additional information while its investigation continued. The FBI has also opened an investigation through its New Orleans field office into the apparent breach.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">\u203c\ufe0f New article from Brian Krebs: FBI Probes Service Selling 153M+ Drivers Licenseshttps:\/\/t.co\/S5KEn9pb5v<\/p>\n<p>Dark Web Onion discussed: http:\/\/nexusdbbulkq5345qlqyc2iprxzsrwvavd6r5qwel3o3vxs5svg5mjyd[.]onion pic.twitter.com\/HVsrjGrL9x<\/p>\n<p>\u2014 Dark Web Informer (@DarkWebInformer) September 2, 2026<\/p>\n<\/blockquote>\n<p>Shortly after Krebs published its report, the Nexus site itself disappeared from the dark web and was replaced with a message saying the service was no longer available.<\/p>\n<p>Peter Van Valkenburgh, a longtime cryptocurrency policy advocate and Coin Center Executive Director, argued in an essay\u2060 that the breach was not some bizarre one-off accident. He called the hack \u201cinevitable\u201d and said society is \u201clong, long, long overdue to reduce the amount of KYC we do.\u201d<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos4\" class=\"Mobile_Pos4 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_4\" class=\"Content_4 od-desktop\"><\/div>\n<\/div>\n<p>Van Valkenburgh\u2019s argument is fundamentally about data minimization. Every time a company demands a scan of a government ID, it creates another repository containing information that can potentially be stolen, resold, or abused.<\/p>\n<p>\u201cWe deputize a sea of s*itty quasi-government contractors to perform data collection and monitoring,\u201d Van Valkenburgh wrote, arguing that the resulting databases become attractive targets precisely because they contain so much valuable information in one place.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos5\" class=\"Mobile_Pos5 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_5\" class=\"Content_5 od-desktop\"><\/div>\n<\/div>\n<p>The problem gets even harder to ignore as governments and companies push identity verification into more parts of daily life. Age verification, financial compliance, hotel check-ins, car rentals, gambling, cannabis sales, and online services can all require some form of ID scan.<\/p>\n<p>Security and privacy researcher Zach Edwards, whose own driver\u2019s license was found in the Nexus database, told Krebs that the incident highlights the risks of outsourcing identity verification to an expanding network of third-party vendors. \u201cThese systems are putting sensitive data into more and more 3rd party vendors, and we don\u2019t have nearly the oversight to ensure they are safe,\u201d Edwards said.<\/p>\n<p>Indeed, the very systems that have been built are a contradiction in themselves. While there are increasingly sophisticated processes put in place to determine whether someone is really who they claim to be, those systems often require collecting enough information to create a devastating situation if the security surrounding the associated database fails.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos6\" class=\"Mobile_Pos6 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_6\" class=\"Content_6 od-desktop\"><\/div>\n<\/div>\n<p>And this is hardly the first time the scale of the problem has become absurd. In 2025, education software company PowerSchool was breached in an attack that exposed sensitive information belonging to tens of millions of students and teachers, including Social Security numbers, dates of birth, and medical information. In 2024, AT&amp;T also disclosed that hackers had obtained the Social Security numbers, dates of birth, phone numbers, email addresses, and other information of 73 million current and former customers. A separate incident exposed phone records belonging to nearly all of the company\u2019s customers.<\/p>\n<h1>Solutions are Available<\/h1>\n<p>Technical solutions to this underlying problem of creating honey pots of sensitive customer data are available. For example, zero-knowledge proofs can allow someone to prove that they satisfy a particular condition without revealing all of the information contained in the underlying credential. Instead of handing over a complete driver\u2019s license to prove that you are over 21, a system could theoretically verify the relevant fact without receiving your name, address, license number, and other information printed on the card.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">153M drivers licenses leaked!<br \/>Identity documents should only be authenticated using zero-knowledge proofs. Stop revealing all your personal details just to prove you have a valid drivers license.https:\/\/t.co\/ebdV54Zk78<\/p>\n<p>\u2014 Remco (@recmo) September 2, 2026<\/p>\n<\/blockquote>\n<p>While these technologies do not magically make identity verification secure in all scenarios, they offer a way to redesign the system so that verifying someone\u2019s identity does not create other, second-order issues.<\/p>\n<div class=\"od-wrapper od-wrapper-both  od-background\">\n<div id=\"optidigital-adslot-Mobile_Pos7\" class=\"Mobile_Pos7 od-mobile\"><\/div>\n<div id=\"optidigital-adslot-Content_7\" class=\"Content_7 od-desktop\"><\/div>\n<\/div>\n<p>Of course, there is also a less convenient reality behind all of this in that some of the data collection is not simply a matter of companies deciding they want more information. Laws and regulations can require businesses to collect, verify, or retain identifying information in certain circumstances. In other words, changes to the regulations around personal data collection are needed on top of the adoption of various technical innovations.<\/p>\n<p>Whether these technical or regulatory changes will be implemented anytime soon remains to be seen. \u201cRisk-averse compliance departments and set-in-their-ways regulators prefer old practices and the appearance of rigorous compliance\u2014box checking\u2014to actually protecting people through data minimization and auditable, verifiable alternatives,\u201d wrote Van Valkenburgh.<\/p>\n<\/p><\/div>\n<p>[analyse_source url=&#8221;https:\/\/gizmodo.com\/identity-verification-is-broken-the-153-million-drivers-licenses-now-for-sale-are-proof-2000806437&#8243;]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[analyse_image type=&#8221;featured&#8221; src=&#8221;https:\/\/gizmodo.com\/app\/uploads\/2026\/09\/id-scan-1200&#215;675.jpg&#8221;] A dark web identity theft service is offering more than 153 million U.S. and Canadian driver\u2019s license scans for sale, and the FBI is investigating where the data came from. The apparent breach is a particularly stark example of the problem with the modern identity verification economy where proving who you are [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[226,53],"class_list":["post-2125812","post","type-post","status-publish","format-standard","hentry","category-politics","tag-crawlmanager","tag-gizmodo-com"],"_links":{"self":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts\/2125812","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2125812"}],"version-history":[{"count":0,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts\/2125812\/revisions"}],"wp:attachment":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2125812"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2125812"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2125812"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}