LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
security

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity a

zeroday.news ·

The Federal Bureau of Investigation's New Orleans field office has initiated an inquiry into a dark web service, "Nexus," which claims to be selling over 153 million driver's license scans from individuals in the United States and Canada. The service, which emerged on the Russian cybercrime forum Exploit on August 31, 2026, also advertises access to more than 10 million identification cards, over 3 million travel documents, and at least 579,000 medical cards. Among the purported victims is U.S. Defense Secretary Pete Hegseth.

The operators of Nexus assert that the images originate from an ongoing breach at a prominent identity verification company based in Louisiana. They claim to have been continuously exfiltrating new data for over a year. Evidence supporting this claim includes a nearly 400,000 increase in available driver's license records within a 24-hour period, suggesting an active data harvesting operation.

Analysis of the stolen records indicates that many include six image files per license—three pairs of front and back scans in basic, infrared, and ultraviolet formats. Each image file is appended with a date and timestamp. Researchers investigating the breach discovered that these timestamps often correspond to dates when individuals used their driver's licenses for specific transactions, such as car rentals or dispensary visits. The timestamps appear to be set to Greenwich Mean Time (GMT).

One notable pattern emerged from the investigation: several individuals whose licenses were found in Nexus had rented vehicles from Hertz around the time indicated by the timestamps. In one instance, a researcher and their mother, whose licenses were found with timestamps just seconds apart, both recalled handing their licenses to a Hertz rental car representative simultaneously. Hertz has not yet commented on the matter.

Further investigation into the timestamps and associated activities led to a potential link with IDScan.net, a New Orleans-based identity verification provider. IDScan.net's services are utilized by various major brands, including Hertz, Target, FedEx, and Motorola Solutions. The company also announced an exclusive identity verification agreement in 2022 with Planet13, a multi-state cannabis dispensary chain.

A security researcher whose driver's license was available on Nexus confirmed that its timestamp aligned with a trip to Las Vegas for the DEFCON security conference. While in Las Vegas, the researcher presented their license at a TSA checkpoint, a marijuana dispensary (Planet13), and their hotel. They specifically noted that the Planet13 dispensary scanned their ID using a device. IDScan.net states it processes ID verification for over 1,000 marijuana dispensaries across 19 U.S. states.

The Nexus service offers previews of records with sensitive information redacted, and customer photos are displayed if available. The database contains documents from both Canada and the United States, with the majority being American records. A search for Canadian driver's licenses yielded approximately 1.1 million results, with Ontario accounting for the largest concentration at 473,673 records. Curiously, some records also include marijuana dispensary cards, and certain entries are marked with "CDL" (presumably commercial driver's license) or "CAC" (possibly Common Access Cards).

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

malware

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

23-year-old botnet down

malware

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system

phishing

FBI raises alarm over deceptive phishing campaign targeting prominent people

The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop.

breach

Another Artifactory CVE under attack by AI agents or humans

Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit