Technology
Ars Technica - All content

I rented a car, and within hours, my driver's license was for sale

Source Entity

Dan Goodin

September 4, 2026
I rented a car, and within hours, my driver's license was for sale

A massive data breach involving the 'Nexus' dark web service has exposed over 150 million driver's licenses and passports. The FBI is currently investigating the incident, which originated from an identity verification provider.

The Nexus Breach: A Crisis of Identity Verification

A disturbing new reality in cybersecurity has emerged following reports from security journalist Brian Krebs regarding a service called 'Nexus.' This dark web platform allegedly hosted a database of over 150 million driver's licenses and passports belonging to citizens in the United States and Canada. The breach serves as a stark reminder that the very mechanisms designed to ensure security—ID verification services—have become lucrative targets for cybercriminals.

The Mechanics of the Theft

The data exfiltrated in this incident is particularly alarming due to its depth. Unlike simple text-based data leaks, this breach reportedly includes high-resolution scans of both the front and back of identification cards. Even more concerning is the reported inclusion of images captured in infrared and ultraviolet spectrums. These specialized formats suggest that the perpetrators are not merely looking for personal identifiable information (PII) but are seeking the raw material necessary to create high-fidelity, cloned physical IDs.

Implications of Pervasive Verification

In recent years, the convenience of digital verification has led to a proliferation of ID scanning at bars, cannabis dispensaries, and rental agencies. Each time a consumer hands over their physical ID to be scanned, they are trusting a third-party intermediary with their most sensitive biometric and legal data. This incident highlights a systemic vulnerability: when a single verification service is compromised, the downstream impact affects millions of individuals who never directly interacted with the breached company.

The Dark Web Marketplace

Nexus operated as a sophisticated search engine for stolen identities, demonstrating how organized crime has industrialized the sale of personal information. By offering searchable access to millions of records, the service lowered the barrier to entry for identity theft. The fact that the list included high-profile targets, including an FBI assistant director and security researchers, underscores the indiscriminate nature of these data harvesting operations.

Current Investigative Status

The FBI has reportedly opened an investigation into the breach as it continues to unfold. While the Nexus site has since been shut down, the data remains in the hands of malicious actors who have likely already distributed or sold the information. The legal and regulatory fallout will likely focus on the security standards maintained by the unnamed ID verification provider that served as the original source of the exfiltrated documents.

Future Trends and Security Outlook

This incident will likely accelerate the push toward decentralized identity verification, where users maintain control over their data rather than relying on centralized databases that serve as honeypots for hackers. As identity theft evolves to include the reproduction of sophisticated security features like UV markings, the public must be increasingly vigilant. Moving forward, the industry will face immense pressure to adopt more secure, privacy-preserving verification methods that do not require the permanent storage of high-resolution ID scans.

Multiple Citing Sources

Verification Required?

Read the full report from the primary source

Go to Ars Technica - All content