153 Million Licenses Leaked With Their Infrared and Ultraviolet Scans Attached. The Anti-Counterfeiting Data Is Now the Counterfeiting Data. Krebs Found the Source by Reading Timestamps.
- Patrick Duggan
- 1 day ago
- 8 min read
Brian Krebs published the story on September 1. A new service on the Russian cybercrime forum Exploit, calling itself Nexus, is selling digital scans of identity documents for more than 170 million people in North America. Over 153 million driver's licenses from the United States and Canada. More than 10 million identification cards. More than three million travel documents. At least 579,000 medical cards. The FBI's New Orleans field office opened an inquiry the same day.
The counts are not marketing. A blank search on Nexus returns roughly 11.5 million pages at about fifteen results each. The catalog grew by nearly 400,000 licenses in a single twenty-four-hour window, and the operators say they have been continuously exfiltrating for over a year. This is not a dump. It is a tap that is still running.
Krebs traced it to IDScan.net, a Louisiana identity-verification company, and the way he did it is the most instructive part of the whole affair.
Six images, and two of them should stop you cold
Each record carries six image files: three pairs of the license front and back. One pair is an ordinary scan. The other two are infrared and ultraviolet captures of the same document.
That detail is the story, and most of the coverage has walked straight past it.
Nobody's phone takes an infrared photograph of a driver's license. IR and UV imaging exist for exactly one purpose — they reveal the security features states embed in licenses precisely so a machine can tell a real one from a forgery. The ghost images, the UV-reactive overlays, the IR-absorbing inks. That is the anti-counterfeiting layer, and it works because forgers historically could not see it, let alone reproduce it.
153 million genuine IR and UV reference captures are now for sale.
Turn that around and look at what it means. The data that existed to prove a license was authentic is now the data that lets somebody manufacture one that passes the same test. Every verification system that checks the UV overlay is now checking against a feature the attacker has a genuine reference image of, at scale, indexed and searchable by name. The control did not just fail. The control's own evidence base was inverted and put on sale.
We write a lot about controls that hold while the handoff around them fails. This is a rarer and worse thing: a control whose secret was the whole mechanism, and the secret is gone for a third of the North American adult population.
CAC. Read that line again.
Buried in the record types are entries whose source field reads CAC.
If that is what it appears to be — Common Access Card — those are the credentials that grant physical access to United States government buildings and secure rooms. Not a bank login. A door.
The catalog also includes CDL entries, commercial driver's licenses, which sit upstream of hazardous-materials transport and port access. And the service offered the driver's license of the sitting US Defense Secretary among its records, alongside other senior government officials. Krebs's own Virginia license was posted as a free sample in the initial sales thread, which is a choice that tells you something about who the operators think their audience is.
We are going to be careful here, because CAC is an inference from a three-letter source field and not a confirmed finding. But it is the single item in this dataset most worth an authoritative answer, and it is the question a federal reader should be carrying into Monday.
How he actually found it, which is the transferable part
Krebs did not get a tip naming the company. He worked it out from metadata, and the method is worth stealing.
Every image file carries an appended date and timestamp, apparently in GMT. His own license timestamp matched a June 2025 flight he took to the midwest for a family funeral. He then asked more than a dozen friends and family for permission to search for their licenses; nine were present, and every one of them confirmed traveling on or very near the timestamped date.
Airports were the obvious hypothesis and it collapsed, for a precise reason: there are no passports in the dataset. Krebs himself had shown a passport at Reagan National that day because he did not yet have a Real ID — he never handed a license to TSA at all. But he did hand it to a Hertz representative when he picked up a car.
Then the detail that closes it. His mother's license is also in Nexus, and her timestamps are a few seconds apart from his — because they handed their licenses to the same rental counter agent at the same moment. Two federal employees who helped with the research had used other government identification at airport security, and both had rented from Hertz at their destination.
That is a clean piece of work, and it is the same discipline we keep insisting on internally: do not accept the plausible story, go read the actual artifact and diff it against a second one. The airport theory was plausible, well-motivated, and wrong. What killed it was one absent record type and a pair of timestamps seconds apart.
Credit where it is owed — this is Krebs's reporting, start to finish. We are adding a read on what it means downstream, not claiming any part of the find.
What we hold, checked properly, with the dates attached
We went and looked, and the first look was wrong in a way worth showing.
Our first pass queried the indexes our public search exposes and came back empty — no IDScan, no Nexus, nothing. The honest conclusion from that would have been "we have no coverage." It would also have been false, because our dedicated phishing index is not one of the publicly-searchable ones, and it holds a great deal that is directly relevant.
Here is what is actually in it, and here is the part that matters — the dates.
Identity-verification-themed phishing domains: 1,387. Earliest indexed February 14, 2026. Of a 200-record sample, 198 were indexed before September 1 — before Krebs published. Sources are PhishTank, OpenPhish and Phishing Army.
DMV-themed: 96, going back to March 9. KYC-themed: 27, back to May 9. License-themed: 16, back to February 26.
IDScan-branded: two domains. Both indexed on September 5.
That last line is the one that decides what we are allowed to claim, so we will be blunt about it. Those two arrived four days after Krebs published, from a third-party feed. That is ingest, not detection. We did not see this coming, we have no receipt that predates the reporting, and anyone who points at those two records and calls them foresight is reading their own ingest log and calling it a lead. We have made that exact error before and published a correction for it; we are not making it again.
What we can say is narrower and, we think, more interesting.
The demand side was visible for seven months. The supply side just arrived.
Everything in our feed is the delivery layer — the fake verification page, the lookalike portal, the brand-impersonation domain. We have been indexing people building fake identity-verification flows continuously since February. Thirteen hundred of them.
What those operators did not have was convincing documents. That is why this class of page has always been the weak joint in identity fraud: the phishing page had to ask you to upload your license. The account-recovery call had to talk you into reading numbers aloud. The synthetic identity had to be assembled from fragments. Every one of those flows had a moment where the attacker needed something only you possessed, and that moment is where defenders caught them.
That moment is now optional for 153 million people.
So the useful framing is not that anyone predicted this breach. It is that the demand for exactly this data has been sitting in plain view in our feed, dated and countable, for seven months — and the supply just showed up. Those two curves have never been connected before, because the document side did not exist at this scale. It does now.
We still hold zero identity documents, and we never will. That part of the earlier draft stands.
The thing a blocklist cannot do
Here is the honest limit of our own product, said out loud.
Our feed exists so a defender can pull a list and break an attack chain — block the C2, sinkhole the domain, drop the hash. That model works because attacker infrastructure is a thing you can name and refuse.
You cannot block a leaked driver's license. There is no indicator to publish. The document is valid, it is genuinely yours, it will still be genuinely yours in ten years, and no amount of threat intelligence revokes it. States do not rotate license numbers on breach. There is no reissue path that scales to a third of the continent.
So a defender reading our feed gets nothing actionable from this, and we would rather say that than dress it up. What we can offer is the second-order work, and that is where we will put our effort: if these documents start showing up in verification flows and account-recovery attempts, the infrastructure running those attempts is trackable, and that infrastructure is squarely in our lane. We will be watching for it.
What to actually do
If you run identity verification, stop treating a document image as evidence of presence. A front-and-back scan with matching IR and UV layers was strong evidence yesterday and is weak evidence today. Liveness checks, device signals, and out-of-band confirmation carry the weight now. Any flow whose strongest control is "they uploaded a picture of a real license" should be re-scored this week.
If you rented a car in the last two years, assume you are in it. The common thread in Krebs's reporting is the rental counter, not the airport. The dispensary cards in the dataset point at the same class of scanner in a different venue. This is not something you opted into knowingly, and there is no action that removes you from the catalog.
If you are a federal reader, chase the CAC field. That is an inference and it needs an authoritative answer from someone with access, not speculation from anyone without it.
Watch your account-recovery path, not your login path. MFA holds. Account recovery is where a genuine document image becomes a skeleton key, and it is the flow that gets the least security review in most organizations because it is owned by support rather than security.
For the people this actually endangers, the risk is not credit fraud. Krebs makes the point and it deserves repeating: front-and-back identity scans in the hands of strangers are a physical safety problem for domestic-violence survivors and for people whose location is protected. That is not a rounding error in a big number. It is the reason this breach is different from a password dump.
The uncomfortable arithmetic
Over a year of continuous exfiltration. Four hundred thousand new records in a day. A company processing more than twenty-one million verifications a month for Fortune 500 clients. Discovery by a journalist who noticed his own license had been posted as a free sample.
Nobody detected the tap. It was found because the thieves advertised.
Was this useful? Rate this post — the widget is at the bottom of the page, and we read every response.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=153-million-licenses-leaked-with-their-infrared-and-ultraviolet-scans-attached-the-anti-counterfeit




Comments