Skip to content
Tech News
← Back to articles

America's Driver's License Breach Is a National Security Disaster

read original get Identity theft protection subscription (e.g., LifeLock) → more articles
Why This Matters

A massive breach exposing 153 million U.S. and Canadian driver's licenses and 3 million travel documents—reportedly including those of senior U.S. officials—highlights how identity verification services can become single points of catastrophic failure. Beyond enabling everyday identity theft and phishing, the scale and inclusion of government officials' data raises serious national security concerns, as adversaries could exploit the trove for intelligence operations.

Key Takeaways
Worth a Look

Identity theft protection subscription (e.g., LifeLock) — With hundreds of millions of driver's licenses reportedly exposed, monitoring your identity has never been more relevant. A dedicated identity protection service can alert you to fraudulent use of your personal information and help you respond quickly if your data turns up in a breach like this one.

See Identity theft protection subscription (e.g., LifeLock) on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

America's Driver's License Breach is a National Security Disaster

Last week, Krebs on Security broke the story of a newly launched dark web service calling itself Nexus that was selling access to identity documents, including 3 million travel documents and 153 million driver's licenses from U.S. and Canadian citizens. This is a huge breach that not only will be used for run-of-the-mill cybercrime but also will feed the intelligence machines of America's adversaries.

Nexus claimed that it had gained unauthorized access to a major identity verification company and had spent more than a year "continuously" exfiltrating new data into a private database. Krebs on Security noted that in a single day the number of licenses in the database increased by nearly 400,000, suggesting regular ingestion of new data.

Krebs on Security was able to verify that the driver's licenses held by the service were genuine. In addition to Krebs’s own, it contained licenses from nine of his friends and family members. Secretary of War Pete Hegseth, an assistant director at the FBI and other high-ranking U.S. government officials also had licenses in the mix.

Based on a variety of circumstantial evidence, Krebs linked the incident to identity verification service IDScan. The service's website says it helps to reduce fraud by confirming that an ID is authentic and being presented by its legitimate owner and by detecting fraudulent documents.

The FBI is looking into the incident, and IDScan has confirmed it is investigating a data breach. The Nexus service also disappeared from the dark web shortly after Krebs published his story, although the people responsible for the hack do not claim to have deleted the data. Presumably they are lying low till the publicity dies down.

Licenses and identity documents can be used to facilitate identity theft and phishing attacks, but because the data can be used to inform intelligence operations, an incident like this also has national security implications.

For the intelligence world, licenses are particularly valuable because they're key identity documents and license numbers are often used in other databases. These databases, whether hacked or purchased, become much more valuable when records can be linked directly to a particular person with home address and photo included.

And it's not a theoretical threat.

In the mid-2010s, Chinese cyber espionage actors stole complementary data from a variety of sources that, together, would be useful for analyzing the U.S. intelligence apparatus. Various Chinese APT groups stole information from the health insurance company Anthem, credit reporting company Equifax, Marriott hotels, United Airlines, and, perhaps most significantly, security clearance information from the Office of Personnel Management.

... continue reading