Hackers Apparently Stole 150 Million IDs, Because Of Course They Did
150 million driver's licenses and passports reportedly stolen from an ID verification firm - because storing everyone's most sensitive data in one place always ends well.
If you've ever flashed your driver's license at a bar, a weed store, or a rental car counter, there's a decent chance your face and personal details are now floating around the dark web. That's according to a report by security journalist Brian Krebs, who uncovered what looks like a massive breach at a major ID verification company.
Krebs found that a new dark web site called Nexus, which launched this week, lets users search through more than 150 million driver's licenses and passports from the U.S. and Canada. The site's ad on a Russian cybercrime forum brags that it adds about half a million new documents daily, sourced from a "major identity verification company" - which suggests the hackers had a direct tap into the company's systems. Because why would you steal data once when you can just keep stealing it forever?
Krebs confirmed the data was real by finding his own driver's license in the database. Even Secretary of Defense Pete Hegseth made an appearance, his photo listed on the site. The Department of Defense said it's "aware of these reports and is evaluating them," which is government-speak for "we're looking into it, please stop asking."
Working with security researcher Zach Edwards - who also had his ID swiped - Krebs identified the likely source as IDScan, a Louisiana-based company that verifies tens of millions of IDs each month for major tech and consumer brands. IDScan's CEO didn't respond to TechCrunch's request for comment, but COO Jillain Kossman told Krebs the company is investigating. The FBI's New Orleans field office is also on the case, though they didn't respond to our questions either. Nexus went offline shortly after Krebs' report went live - nothing says "we're definitely not guilty" like vanishing into the digital ether.
This breach comes at a time when governments are pushing age verification laws, which require adults to upload IDs to prove they're old enough to enter websites. Privacy advocates have warned for years that storing massive troves of identity documents is a treasure trove for hackers. And here we are: the largest known single breach of identity documents in recent memory. It's almost like the warnings were justified.
The Good Times
News in your inbox.
One sardonic roundup, delivered on your schedule. Free. Unsubscribe whenever your tolerance for wit runs out.
Already subscribed but we never reach your inbox? Check your spam folder and hit 'Not spam' (or 'Remove from spam') to bust us out of junk-mail purgatory. You'll be helping everyone else too.
Don't open any of our emails for a month and you'll be automatically removed from the mailing list.
Rewrite Article
Select parts to regenerate with a fresh AI pass. Translations will be updated automatically.
Generate AI Image
Creates a sardonic version of the article image using OpenAI.