Trill News

Any sufficiently advanced technology is indistinguishable from magic. — Arthur C. Clarke
TECH

153 Million Driver's License Breach Is a National Security Threat

153 Million Driver's License Breach Is a National Security Threat
Illustrative Oregon DMV office; the breach involved a private verification company, not a state agency by OregonDOT (CC BY 2.0)
A dark web breach of 153 million driver's licenses is a national security problem, not just fraud, as foreign spies can tie these scans to other stolen data.

A service called Nexus offered the scans with 3 million travel documents, and Krebs on Security traced them to identity verification firm IDScan, which confirms an outsider accessed customer data.

Nexus claimed more than a year of access, though IDScan dates the intrusion from April 4 to September 2, 2026, and the trove held licenses belonging to Pete Hegseth and an FBI assistant director.

Licenses matter to intelligence services because their numbers link records across other databases to one person's photo and home address.

China has run this play before, stealing data from Anthem, Equifax, Marriott, United Airlines and the Office of Personnel Management in the mid 2010s, while Bellingcat has shown how leaked databases unmask Russian intelligence officers.

The haul covers roughly 63 percent of all U.S. licenses, and it follows breaches at AU10TIX, 5CA and National Public Data within two years.

With swift regulation unlikely, class action suits and Federal Trade Commission scrutiny may be the only pressure pushing identity verification firms to secure what they hold.
IDScan's updated notice lists names, birth dates and license and passport numbers, yet the records Krebs on Security examined carried front, back, infrared and ultraviolet images, a gap the notice still does not address. The images are what make this trove durable: a license number can be reissued, a face cannot, which leaves domestic violence survivors and people in witness protection exposed for years. Plaintiffs have already sued in Louisiana, where IDScan is based, over data collected through clients such as Hertz, BleepingComputer reports. Watch for those suits to be consolidated before a single judge, and for any Federal Trade Commission or state attorney general inquiry.

Read the original reporting at Lawfare.

Read Full Story at Lawfare →

FIND A BOOK ON BOOKSHOP.ORG