The Federal Bureau of Investigation is reportedly investigating a potential data breach that may have exposed the identity information of up to 170 million North Americans, primarily impacting individuals in the United States and Canada. The incident first came to light through the investigative work of journalist Brian Krebs.
The alleged breach involves a service named "Nexus," which was offered on the Russian cybercrime forum Exploit. Nexus claimed to provide access to digital scans of identity documents, including over 153 million driver's licenses, as well as ID cards, travel documents, and medical cards. The operators of Nexus asserted that this extensive trove of data originated from an active breach at a "major identity verification company."
Although the Nexus service ceased operations shortly after Krebs published his findings, his investigation, which involved tracking activity from his own and other identified victims' movements, linked the data to IDScan.net, an identity verification provider based in New Orleans. IDScan.net has confirmed it is currently investigating the matter.
A compromised driver's license can have significant and lasting repercussions, as it contains sensitive personal details such as date of birth, address, physical descriptors, and a government-issued identification number. This information is often sufficient to bypass identity verification checks used by many financial institutions and government agencies. Unlike passwords, these core identity details cannot be changed, meaning affected individuals could face lifelong exposure to this risk.
Experts suggest that this incident underscores the need for higher standards in identity verification processes. Businesses that rely on third-party identity verification vendors are advised to scrutinize their data retention policies, particularly regarding how long scans are kept after verification is complete. They should also inquire about contractual obligations for data minimization and the possibility of auditing these vendors.
The absence of a mechanism similar to a credit freeze for compromised driver's license numbers highlights a critical gap in current identity protection measures. Organizations that collect and centralize government-issued identity documents are urged to implement security protocols for these data stores that are at least as robust as those applied to payment card data, if not more stringent. While a new credit card number can be obtained relatively quickly, a new face, or the core identity details associated with it, cannot.






