LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
breach

FBI Probes Possible Breach of 153 Million Driver’s Licenses

The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web

zeroday.news ·

The Federal Bureau of Investigation is reportedly investigating a potential data breach that may have exposed the identity information of up to 170 million North Americans, primarily impacting individuals in the United States and Canada. The incident first came to light through the investigative work of journalist Brian Krebs.

The alleged breach involves a service named "Nexus," which was offered on the Russian cybercrime forum Exploit. Nexus claimed to provide access to digital scans of identity documents, including over 153 million driver's licenses, as well as ID cards, travel documents, and medical cards. The operators of Nexus asserted that this extensive trove of data originated from an active breach at a "major identity verification company."

Although the Nexus service ceased operations shortly after Krebs published his findings, his investigation, which involved tracking activity from his own and other identified victims' movements, linked the data to IDScan.net, an identity verification provider based in New Orleans. IDScan.net has confirmed it is currently investigating the matter.

A compromised driver's license can have significant and lasting repercussions, as it contains sensitive personal details such as date of birth, address, physical descriptors, and a government-issued identification number. This information is often sufficient to bypass identity verification checks used by many financial institutions and government agencies. Unlike passwords, these core identity details cannot be changed, meaning affected individuals could face lifelong exposure to this risk.

Experts suggest that this incident underscores the need for higher standards in identity verification processes. Businesses that rely on third-party identity verification vendors are advised to scrutinize their data retention policies, particularly regarding how long scans are kept after verification is complete. They should also inquire about contractual obligations for data minimization and the possibility of auditing these vendors.

The absence of a mechanism similar to a credit freeze for compromised driver's license numbers highlights a critical gap in current identity protection measures. Organizations that collect and centralize government-issued identity documents are urged to implement security protocols for these data stores that are at least as robust as those applied to payment card data, if not more stringent. While a new credit card number can be obtained relatively quickly, a new face, or the core identity details associated with it, cannot.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

nation-state

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms

Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Institute of Science and Technology (KAIST), working with the National University of Singapore and Singapore Management University

security

UK's Online Safety Act has made 'absolutely no difference,' kids say

Children's Commissioner also furious with Ofcom over a string of failures

patch

Windows memory integrity switches on automatically for eligible devices in October 2026

Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory integrity is the layer that allows only trusted kernel-mode code and drivers to run, which is how it stops an attacker who is tr

ai

Smashing Security podcast #483: This AI helps thieves steal your iPhone

You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees