Is your personal data involved in the driver's license data breach?
The FBI is investigating a dark web service called Nexus that claims to possess over 153 million driver's license records from the United States and Canada. This massive driver's license data breach, which surfaced on a cybercrime forum in late August, also allegedly includes millions of other identification and medical cards. While the total number of unique individuals affected remains unconfirmed, the scale of the exposure has prompted a federal inquiry.
Researchers linked the stolen data to IDScan.net, an identity verification company, after discovering that timestamps on the license scans matched specific travel and identification presentation dates. IDScan.net has acknowledged a security incident involving unauthorized access to its cloud-based customer information. The company is currently notifying potentially affected individuals and providing credit monitoring services, though it has not officially confirmed that its systems are the source of the Nexus database.
How did investigators trace the stolen records?
Investigators identified the source by analyzing metadata attached to the stolen files. Cybersecurity experts found that license scans included infrared and ultraviolet images, which are consistent with the scanning technology used by IDScan.net. Furthermore, individuals whose records appeared in the database reported that the file timestamps aligned precisely with instances where they had presented their identification at various businesses, including rental car agencies and retail locations.