A new dark web ID theft service called Nexus has been caught selling more than 153 million driver’s license scans, some of which appeared for sale within hours of victims presenting their IDs at rental car counters and other businesses. The scale and speed of the operation point to near real-time access to data flowing through a third-party scanning service used by these companies.
The listings reportedly included high-resolution images of both the front and back of each ID. More concerning, the files captured images in the infrared and ultraviolet spectrums, formats that could help clone-based counterfeit IDs pass hologram verification tests. Reported victims include a journalist, his mother, an FBI assistant director, and several security researchers.
What Nexus offered for sale
Beyond driver’s licenses, Nexus advertised a wide range of other identity documents. The catalog included identification cards, travel cards, international driver’s licenses and IDs, medical cards, Common Access Cards, residence cards, and employment authorizations. It also claimed to sell scans of marijuana dispensary cards.
Some records listed their source as “CDL,” likely short for commercial driver’s license. Others were marked “CAC,” a probable reference to Common Access Cards, government-issued credentials that grant physical access to government buildings and secure rooms. One victim reported visiting a Las Vegas location of Planet13, a multi-state dispensary chain.
A breach growing by the hour
The database appears to be actively expanding. Over a 24-hour span, the number of driver’s licenses listed as available grew by almost 400,000, suggesting new cards become available shortly after they’re harvested. That rapid turnaround indicates an ongoing pipeline rather than a one-time dump.
Using publicly available information, investigators linked the activity to IDScan.net, a New Orleans-based ID scanning service. The company announced an exclusive arrangement with Planet13 and listed Hertz along with 11 other companies as clients. IDScan.net stated that its scans capture both infrared and ultraviolet spectra, matching the formats seen in the stolen files.
A spokesperson for IDScan.net said the company is investigating. The FBI is also investigating the incident. Representatives for the affected rental car company did not immediately respond to questions.
The presence of ultraviolet and infrared scans makes this exposure especially serious, since those formats are typically used to verify document authenticity. While many personal details such as addresses and Social Security numbers have circulated in prior breaches, high-fidelity multi-spectrum ID scans raise the risk of convincing counterfeit documents. Nexus went dark within hours of the report being published.
Source
Image: arstechnica.com