A security research publication reported Tuesday that a new identity theft service, called Nexus, was offering access to more than 153 million driver’s licenses for sale, including one belonging to an Ars Technica reporter who had rented a car just hours earlier. The service, detailed by KrebsOnSecurity, marketed scans that captured both the front and back of the licenses, along with images taken in infrared and ultraviolet spectrums. According to the report, those additional image formats could allow counterfeit ID makers to produce cloned documents that pass hologram verification tests used by businesses.

The exposed records also included driver’s licenses belonging to journalist Brian Krebs, his mother, an FBI assistant director, and several security researchers, as stated in the article. Beyond standard state-issued licenses, Nexus advertised other forms of identification, with some records labeled with a source of “CDL,” possibly meaning commercial driver’s license, and others marked “CAC,” which the report identified as likely Common Access Cards used by the US government for physical access to secure buildings. The service also claimed to sell scans of marijuana dispensary cards, with one victim reporting they had visited a Las Vegas outlet of Planet13, a multi-state dispensary chain.

The timing of the scans’ availability pointed to a near real-time pipeline, as new listings appeared within hours or a day after the reporter and a small sample of other victims presented their IDs at rental car companies or similar businesses. Over a 24-hour period, the number of available driver’s licenses grew by nearly 400,000, indicating an ongoing breach where harvested cards were posted quickly. KrebsOnSecurity identified IDScan.net, a New Orleans-based scanning service, as a likely source, noting the company has an exclusive arrangement with Planet13 and lists Hertz and 11 other companies as clients. IDScan.net’s own materials confirm that its scans capture both infrared and ultraviolet data, according to the research.

Representatives from IDScan.net did not immediately respond to email questions from the reporter, though a spokesperson told Krebs the company is investigating the matter. The reporter’s car rental company also did not answer immediate inquiries. The availability of the license is more troubling than past data breaches, the source article stated, because of the purported inclusion of ultraviolet and infrared scans, which add a layer of threat beyond typical personal data exposure.

The Nexus service went offline within hours of the KrebsOnSecurity report, which also means individuals have no way to check whether their own IDs are included in the stolen cache. The FBI is currently investigating the incident, according to the article. The federal probe offers some consolation, but the exposure of the reporter’s license - along with those of government officials and security experts - underscores a direct risk to US consumers who present IDs at rental counters and other businesses relying on third-party scanning services.

More cybersecurity news from TechManNews.