FBI confirms an investigation—not the advertised record count

WASHINGTON — The FBI says it is examining reports that a newly launched dark-web service offered digital scans of driver’s licenses belonging to people in the United States and Canada. The bureau told Reuters it was looking into the incident but could not comment further because the investigation is ongoing.

The service, called Nexus, advertised more than 153 million driver’s-license scans, more than 10 million other identification cards, more than 3 million travel documents or international IDs and at least 579,000 medical cards, according to the original investigation by cybersecurity journalist Brian Krebs.

Those totals came from the people operating the alleged criminal service. They are not an FBI-confirmed breach count, an audited inventory or a verified number of individual victims. The available reporting does not establish whether the categories overlap, whether every record is authentic or current, or whether each scan represents a different person.

Read the source: Reuters: FBI confirms it is examining the reported driver’s-license exposure

Krebs says he authenticated records with nine people

Krebs reported that his own Virginia driver’s license appeared as a free sample in an advertisement on a Russian-language cybercrime forum. He told Reuters he confirmed the authenticity of records with nine people whose documents appeared on the service.

That verification provides evidence that Nexus possessed genuine identity documents; it does not independently validate the entire 153 million figure. Krebs reported that the marketplace appeared to add records in real time and that the advertised totals rose during his review, suggesting a possible continuing data feed rather than only a static archive.

The Nexus site disappeared shortly after the investigation was published, Krebs and Reuters reported. Its disappearance does not establish that the data was deleted, recovered by authorities or removed from every person who may have copied it.

Read the source: KrebsOnSecurity: Original investigation, authentication checks and seller’s claimed totals

IDScan.net says it may be implicated but has not confirmed a breach

Krebs traced technical indicators and record timestamps to IDScan.net, a Louisiana-based identity-verification provider. Reuters said it could not independently establish the source of the data and received no response to repeated messages from the company.

In a customer notice quoted by Krebs, IDScan.net said it received information on September 1 suggesting certain information may have been exposed and that the company may be implicated. It said it was working urgently to determine whether unauthorized access occurred and, if so, its scope.

That statement is an acknowledgment of an investigation—not an admission that IDScan.net was breached or that it supplied every record advertised by Nexus. No government agency has publicly attributed the reported exposure to the company, identified a suspect or explained how the documents were obtained.

Read the source: Federal Trade Commission: Official credit-freeze and fraud-alert guidance

No California DMV breach has been confirmed

The service reportedly offered records from across the United States and Canada, but no verified state-by-state count is public. The reporting reviewed for this article does not establish that California’s Department of Motor Vehicles network was breached or that a government licensing database was the source.

Californians whose licenses were scanned by a private business could potentially appear in a third-party vendor’s records, but that possibility is not proof that any particular person, retailer, rental counter or other company is involved. No reliable public lookup tool currently allows consumers to check whether their license appeared in the Nexus collection.

Businesses known to use an identity-verification company should not automatically be described as breached customers. A vendor relationship alone does not establish that a business supplied any of the documents advertised on the dark web.

Read the source: IdentityTheft.gov: Official guidance when identification information is lost or exposed

What consumers can do without surrendering to panic

A scanned license can expose a photograph, name, address, date of birth, license number and machine-readable data that criminals may combine with information from other breaches. It can support convincing impersonation and new-account fraud even when it does not include a Social Security number.

The Federal Trade Commission says anyone may place free credit freezes with Equifax, Experian and TransUnion. A freeze restricts access to a credit report and makes it harder for an identity thief to open a new account; it does not affect a credit score and remains until the consumer lifts it.

People who discover actual misuse should use IdentityTheft.gov to create a recovery plan and contact their state motor-vehicle agency about a compromised license. Consumers should use official government and credit-bureau websites directly, not links in unsolicited breach-alert messages, and should treat anyone demanding payment to check the alleged Nexus database as a potential scammer.

Read the source: Wikimedia Commons: Public-domain FBI headquarters photograph

The evidence is serious—and still incomplete

Confirmed now: the FBI is investigating; Nexus advertised a vast collection of identity-document scans; Krebs authenticated records with nine people; and IDScan.net says it is examining whether it may be implicated.

Still unconfirmed: the seller’s 153 million driver’s-license total, the number of individual victims, the source and method of access, IDScan.net’s responsibility, the involvement of any named customer, the extent of Canadian or California exposure and whether the data has been misused.

What’s the Scoop With Broach will update this report when the FBI, IDScan.net, a state regulator or another identified authority releases a verified scope or direct-notification plan. Until then, the scale must remain labeled as a criminal marketplace’s claim rather than a completed breach assessment.

The accompanying image is an authentic public-domain FBI file photograph of the J. Edgar Hoover Building in Washington, D.C. It does not show Nexus, IDScan.net, any exposed identity document, a victim, a suspect or the current investigation.

Sources and further reading

Reuters: FBI confirms it is examining the reported driver’s-license exposure

KrebsOnSecurity: Original investigation, authentication checks and seller’s claimed totals

Federal Trade Commission: Official credit-freeze and fraud-alert guidance

IdentityTheft.gov: Official guidance when identification information is lost or exposed

Wikimedia Commons: Public-domain FBI headquarters photograph