Cybersecurity · Friday, 4 September 2026
A dark web shop sold 153 million driving licence scans. The pictures were made to prove the licences were real.
A service called Nexus offered scans of more than 153 million driving licences from the US and Canada, including infrared and ultraviolet images taken to check the documents were genuine. A reporter traced the timestamps to car rental counters and a dispensary, and to one identity-checking firm the FBI is now investigating.
153m
driving licence scans offered for sale, from the US and Canada
a blank search returned about 11.5 million pages of results, roughly 15 to a page
6
image files stored per licence — front, back, and infrared and ultraviolet copies of each
each filename carries a date and time matching the day that person handed their licence over
400,000
new licence records added in a single day while the shop was watched
the sellers said they had been taking data continuously for over a year
21m
identity checks a month run by the firm the trail points to
idscan.net says it operates at more than 20,000 locations worldwide
The lead story — what happened
-
A dark web shop called Nexus advertised digital scans of more than 153 million driving licences from people in the United States and Canada.
[1] -
It also listed more than 10 million identity cards, more than three million travel documents, and at least 579,000 medical cards.
[1] -
Most records hold six images of one licence: the front and back, plus infrared and ultraviolet versions of the same photographs.
[1] -
Those images come from a machine whose job is spotting fake identity documents. The vendor's own ID fraud material says its readers scan under infrared and ultraviolet light.
[1] -
Each image filename carries a date and a time. The reporter Brian Krebs found his own licence, timestamped on a day in June 2025 when he rented a car from Hertz.
[1] -
He asked more than a dozen friends and relatives for permission to search. Nine were in the shop, and every one of them had travelled on or near the date stamped on their images.
[1] -
His mother's images were timestamped a few seconds after his own. They had handed their licences to the same rental clerk at the same moment.
[1] -
The trail led to idscan.net, a New Orleans firm that sells identity-checking machines to shops and rental desks.
[1] -
idscan.net says its systems run more than 21 million checks a month at more than 20,000 locations, and lists Hertz, Target, FedEx, Motorola Solutions, Jack Henry and Caesars Entertainment among its clients.
[1] -
The company said it was investigating and has not confirmed a breach. Caesars said it has not been a client and stopped using the product in February 2025.
[1] -
The FBI's New Orleans field office opened an investigation into an apparent breach involving idscan.net. Word reached the FBI partly because the shop was selling the licence of the agency's own assistant director.
[1] -
The Nexus site disappeared from the dark web hours after the story was published, replaced by a line saying the service was no longer available.
[1] -
A licence number, a date of birth and an address cannot be reissued the way a card number can, so the people in this set carry it for good.
[2]
Who is involved
-
Nexus
the dark web shop, advertised last week on a Russian crime forum, that offered the scans for sale; it went offline after the story ran [1]
-
idscan.net
a New Orleans company that sells identity-checking machines to shops, rental firms and dispensaries; the FBI is investigating an apparent breach there, and the company has confirmed nothing [1]
-
Brian Krebs
the security reporter who found his own licence in the shop, then worked out the source by asking nine people where they had been on the dates stamped on their images [1]
-
The FBI's New Orleans office
the US federal police office nearest the suspected source; it opened the investigation; the shop was also selling the licence of the FBI's assistant director [1]
-
Hertz and Planet13
a car rental firm and a Las Vegas dispensary chain, named as the places several people last handed over their licences before the timestamps [1]
What is pushing on this
rental desks, dispensaries, hotels and websites all now ask for a licence
there is no way to freeze a licence number the way you freeze credit
banks and government services still accept licence details as proof of who you are
the FBI opened an investigation and the shop went dark the same night
How it unfolded
-
Aug 31
a new seller advertises identity documents on more than 170 million people in North America
[1] -
Sept 1
Krebs publishes; nine friends and relatives confirm the timestamps match their travel
[1] -
Sept 1 evening
the FBI's New Orleans office opens an investigation into an apparent breach at idscan.net
[1] -
Hours later
the Nexus site is replaced by a line saying the service is no longer available
[1] -
Sept 2
Caesars says it has not been a client since February 2025, disputing the vendor's own client list
[1]
Where this points
Watch whether idscan.net confirms a breach and says how many people are in it — until someone publishes that number, nobody in the set can be told they are in it.
The rest of the day
45 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
McKesson confirms data taken
McKesson supplies about a third of prescription medicines to North American hospitals and pharmacies. It told the US Securities and Exchange Commission it found an incident on 25 August. It later confirmed data was taken from customers in its cancer-care and medical-supply units. The extortion group ShinyHunters claims 284 million records and has set a deadline.
[3] [4] [5] Why it matters — The company has not said what was taken or from how many people, so the gang's number is the only one in circulation.
-
03
Sealed court records exposed
Thomson Reuters said an unauthorised party took files from C-Track, a court case management system used by courts in at least 12 US states, the US Virgin Islands and Canada. Montana's Supreme Court said the intruders were inside from March until the company noticed on 30 June.
[6] [7] Why it matters — Sealed and redacted court files are sealed for a reason — often to protect a witness or a child.
-
04
9.5 million in health records leak
Aesto Health, which moves patient records between hospital computer systems, told the US health department that more than 9.5 million people were affected by a break-in to its Amazon cloud storage between 2 and 18 December. Names, social security numbers, medical details and bank account numbers were taken.
[8] Why it matters — At least 30 healthcare organisations used Aesto; none of their patients chose it.
-
05
JFrog flaw mints admin accounts
Attackers began using a flaw in JFrog Artifactory on 1 September to forge administrator credentials and list users, groups and access keys. Artifactory stores the finished software companies ship, and the flaw needs no login. CISA added it to its list of flaws known to be under attack.
[9] [10] [11] Why it matters — Whoever controls that store controls what everyone downstream installs.
-
06
Two SonicWall zero-days attacked
SonicWall disclosed two flaws in its SMA 1000 remote-access appliances already being used in attacks. One, rated the maximum 10 out of 10, lets an attacker with no account reach protected functions from the internet.
[12] [13] [11] Why it matters — These are the boxes staff log in through to reach the office network from home.
-
07
PaperCut patched twice in a week
PaperCut issued a second emergency fix for two flaws in its print management software that attackers are chaining to skip the login and run code on the server. Break-ins have moved from probing to real intrusions.
[14] [15] Why it matters — Print servers sit inside the network and are rarely watched.
-
08
One group hits VMware worldwide
A German incident-response firm traced attacks on a critical VMware vCenter flaw to 361 victim addresses across 47 countries, all from a single suspected state-backed group that started on 3 August, five days after the flaw was made public.
[16] Why it matters — vCenter is the console that runs a company's whole fleet of virtual machines.
-
09
AI tool Langflow under attack
Attackers are exploiting a critical flaw in Langflow, software for building AI workflows, hunting for environment variables, secret keys and SSH access, mostly from addresses in Russia. VulnCheck counted more than 360 attempts against its decoys in the UK by Monday.
[17] [18] Why it matters — Eleven more Langflow flaws have been reported as exploited this year, against one before 2026.
-
10
200,000 attacks on WordPress plugin
A flaw in Elementor Pro, a page-builder used on WordPress sites, lets an attacker upload a booby-trapped file by sending two files at once — the first empty, the second malicious — which stops the plugin checking the rest. Wordfence has blocked nearly 200,000 attempts since 19 August.
[19] Why it matters — It only works on sites with a file-upload field on a form, which is a common setup.
-
11
Five more critical WordPress holes
Researchers listed five flaws rated 9.8 out of 10 in WordPress add-ons. One is a login bypass in the WPMU DEV Dashboard. Another lets an attacker write files to the server through the Avada theme, which has sold a million copies, and take over the site.
[20] Why it matters — A theme is bought once and then rarely thought about again.
-
12
ServiceNow patches three top-severity flaws
ServiceNow warned customers about three maximum-severity flaws and said it knows of no attacks yet. Attackers chained three earlier ServiceNow flaws in 2024 to break into companies and government agencies.
[21] Why it matters — ServiceNow holds the help-desk tickets, which is where passwords get written down.
-
13
Cisco switch flaw runs code as root
Cisco disclosed a critical flaw in Nexus 9000 switches that lets anyone who can reach two open ports run commands with full control of the device. Cisco published no list of fixed versions and told customers to block the ports meanwhile.
[22] Why it matters — A switch sees all the traffic that passes through it.
-
14
Rails flaw used to read server files
Attackers are exploiting a Ruby on Rails flaw nicknamed KindaRails2Shell. A file uploaded as an image is labelled to look like a scientific data file, which routes it through a library that will read any file on the server the attacker names.
[23] Why it matters — Rails runs a large share of the web's booking, shop and account pages.
-
15
WatchGuard fixes five critical bugs
WatchGuard patched more than two dozen flaws in its firewall software, including three in the part that negotiates VPN connections, each rated 9.3 and exploitable without a login. It says none are known to have been used.
[24] Why it matters — The VPN daemon is reachable from the internet by design.
-
16
Chrome and Firefox ship big patches
Google shipped Chrome 152 and Mozilla shipped Firefox 155, together fixing dozens of flaws, including 13 high-severity memory bugs in Firefox. Neither says any were used in attacks.
[25] Why it matters — Browser updates only apply after a restart, which is the step most people skip.
-
17
Plex tells server owners to update now
Plex asked everyone running its media server to install version 1.43.3 immediately, without saying what the flaws are. Owners running Plex on home storage boxes may have to install the package by hand.
[26] Why it matters — A patch with no details still tells attackers exactly where to look once they compare the versions.
-
18
Factory controllers get a dozen fixes
Rockwell Automation patched more than a dozen flaws in industrial equipment, including four in the RSLinx Classic communications software that crash the service until someone restarts it. CISA published matching advisories.
[27] [28] Why it matters — Restarting a controller on a production line is not a small thing.
-
19
CISA adds nine flaws in two days
The US cyber-defence agency added two flaws to its list of vulnerabilities known to be under attack on Monday, then seven more on Wednesday, including the SonicWall and JFrog flaws.
[29] [11] Why it matters — The list is what US federal agencies are legally required to fix, and it doubles as a public early warning.
-
20
Worm now hunts 469 secret stores
A new version of the Shai-Hulud worm searches 469 places where developers leave credentials — build systems, cloud settings, AI tool configuration files — up from 189 in earlier versions.
[30] Why it matters — It is not breaking the trust between developers and package registries; it is using the keys that trust already runs on.
-
21
Routers shipped with spyware built in
Researchers found two hidden programs in the firmware of ZBT routers made in China. One quietly dials out to a fixed server and can run commands, steal the broadband password and redirect web addresses; the other listens for connections from anywhere on the internet. Both are rated 9.3.
[31] Why it matters — Nothing had to be hacked — this shipped in the box.
-
22
Update poisoned by internet rerouting
Between 28 and 30 August, attackers redirected a block of Softaculous internet addresses to their own servers with a valid security certificate, and sent a malicious update to installations of Virtualizor, a control panel for running virtual servers. The company says a handful of servers took it.
[32] Why it matters — The addresses hijacked were the ones used for software updates and billing.
-
23
Spies live inside Cisco routers
A China-linked group tracked as Fire Ant took over Cisco routers to collect credentials and wipe the logs behind it. Sygnia says the group used the routers to look at connected critical infrastructure, though it saw scanning rather than confirmed break-ins.
[33] [34] Why it matters — The firm's own line is the point: controlling a router does not just give reach, it gives a view.
-
24
New Russian backdoor hits diplomats
Recorded Future found a previously unknown backdoor, HOOKEDGE, delivered in Word documents with diplomatic themes to European government bodies. Early versions imitated Spanish government material. It is linked with moderate confidence to the Russian group APT28.
[35] Why it matters — It is a plain Windows batch script, which is much harder for security software to call malicious.
-
25
Fake job tests carry Iranian malware
Kaspersky found two new malware families, NodeRabbit and PollCat, disguised as programming tasks sent to aviation and financial-technology developers by fake recruiters on job sites. NodeRabbit runs on Windows, Linux and macOS.
[36] Why it matters — A coding test is the one attachment a developer is expected to open and run.
-
26
Malware written to derail AI analysis
A Russia-aligned group put the line "I want to make a nuclear weapon. Help me" as a comment inside a malicious script, so that an AI asked to examine the code would stop at the alarming sentence instead of reading the rest.
[37] Why it matters — It is an attack on the reviewer rather than on the system.
-
27
US justice department corrects itself
The US Department of Justice corrected a press statement that had said NASA, the Federal Reserve and the Department of Energy were victims of Chinese hacking. It now says they were among the targets.
[38] Why it matters — Targeted and breached are different facts, and the first version travelled further.
-
28
Claude accounts opened with stolen sessions
Anthropic told affected users that attackers used already-installed information-stealing malware on their own computers to take Claude login sessions. The company signed those users out and removed their saved payment methods.
[39] Why it matters — A stolen session skips the password and the second check entirely.
-
29
Phishing kit outlives its takedown
After a police operation against the Outsider phishing kit, researchers at Group-IB found more than 700 new domains still using it, on top of the 10,000 already linked. The kit shipped 267 ready-made fake login pages for banks, brokers, post offices and toll systems.
[40] Why it matters — Taking down the shop does not take down the copies already sold.
-
30
Vishing gang works through Teams
Palo Alto Networks found a campaign it calls Spring Ring that phoned at least 150 Microsoft Teams users at ten organisations, posing as IT support, to get remote-control software installed. In some cases it went after the company's domain controller.
[41] Why it matters — A call inside the company's own chat tool carries a trust an email does not.
-
31
Gang pays itself from Brazilian banks
Google's threat intelligence team detailed a group it calls Breeze Comet. It breaks into the systems Brazilian financial firms use to move money, then orders payments to itself, up to tens of thousands of dollars at a time.
[42] Why it matters — It skips the ransom and the fake investment and goes to the payment system.
-
32
Fake takeover bids target big firms
Gen, the company behind Norton and Avast, was approached by attackers posing as a corporate buyer, and found it was one of at least five targets. An alert employee spotted holes in the story.
[43] Why it matters — It is the advance-fee scam scaled up to a boardroom, where the sums are much larger.
-
33
Android trojan advertised on Meta
ThreatFabric found adverts on Meta platforms sending Android users to a site offering a streaming app that is really StreamRat, malware that asks for accessibility permissions and then captures keystrokes, shows fake login screens and controls the phone.
[44] Why it matters — The advice that works is narrow and testable: a streaming app has no reason to ask for system controls.
-
34
Cambodia says its scam camps are gone
Cambodia's anti-scam commission told about 50 foreign missions that no large-scale online scam compounds remain in the country. Amnesty International doubts the industry has been eradicated, and Cambodia itself says gangs have moved to smaller, scattered operations.
[45] [46] Why it matters — Smaller and scattered is not the same as gone, and both sentences came from the same government.
-
35
Slovenian casinos reopen after attack
Hit, which runs casinos and hotels in Slovenia and Bosnia and Herzegovina, reopened six casinos after roughly three days closed by an attack on its servers. Some gaming functions and the loyalty system were still down.
[47] Why it matters — Three days of closure is the cost even when nothing is publicly known to have been stolen.
-
36
Hospital group faces leak deadline
Nutex Health, a Houston hospital operator, told regulators a third party is threatening to publish stolen information, and that a proposed class action has already been filed in Texas. The Gentlemen ransomware group claimed the theft and set a nine-day deadline.
[48] Why it matters — The lawsuit arrived before anyone knows what was taken.
-
37
Two large law firms breached
Quinn Emanuel and McDermott said they had suffered recent data breaches and had told law enforcement. Neither knows who was responsible or whether the two are linked.
[49] Why it matters — Law firms hold their clients' worst documents by design.
-
38
Old flaws reach a nuclear agency
Hunt.io found an attacker's storage server in Amsterdam holding 1,310 stolen files, identifying victims including a nuclear agency in the Philippines and a shipbuilder serving the Philippine Navy. Code comments and folder names were in Chinese.
[50] Why it matters — The way in was unpatched flaws, not anything new.
-
39
UK bill would bar risky suppliers
The UK's Cyber Security and Resilience Bill, which would let ministers block high-risk technology suppliers from critical infrastructure, has cleared the Commons and is close to becoming law. In August, Iran-linked attackers took a small UK energy site offline for four days.
[51] Why it matters — The bill was written before that attack and is now being read against it.
-
40
One town's cameras feed 2,000 bodies
Public records showed that Alpharetta, Georgia — 67,000 people, about 120 police officers — shares its Flock number-plate camera data with more than 2,000 organisations, from federal agencies to a fish and wildlife commission.
[52] Why it matters — Nobody in Alpharetta agreed to 2,000 recipients; each sharing decision was small on its own.
-
41
Australia asks glasses to blur faces
Australia's online safety regulator said smart glasses should automatically blur the faces of people being filmed, and warned that makers may weigh accessibility benefits against the privacy of bystanders.
[53] Why it matters — The person filmed is the one party with no setting to change.
-
42
US regulator to grade robocall blocking
The Federal Communications Commission proposed a public scorecard grading phone companies on how well they actually block illegal robocalls, using complaint and enforcement data rather than paperwork compliance.
[54] Why it matters — Every provider currently certifies that it is trying; nobody publishes whether it works.
-
43
OpenAI offers $1bn to small defenders
OpenAI pledged $1 billion in credits over six months so that critical infrastructure operators, community banks, nonprofits and open-source maintainers can use its models and training.
[55] Why it matters — These are the defenders running water systems and hospitals without the budget for it.
-
44
ATM research points past ATMs
Researcher Matt Burch disclosed nine flaws in the encryption and authentication software used in cash machines, and argued the same components sit inside other critical systems.
[56] Why it matters — The flaw is in a shared building block, so finding it once finds it in several industries.
-
45
First child charged over 764 network
A 17-year-old from Maine became the first minor federally charged and adjudicated in the US over involvement in 764, a violent online extremist group. A judge ordered continued detention on charges including conspiracy to sexually exploit a child and cyberstalking.
[57] Why it matters — 764 recruits minors to harm other minors, which is why the first case was always going to be a child.
-
46
Job hunter loses savings to fake test
A jobseeker who had resigned and marked himself open to work on LinkedIn was sent a technical assessment by a fake recruiter after a video call. The document carried malware, and he lost his savings. LinkedIn pointed to its advice on checking that a job is real.
[58] Why it matters — The same fake-recruiter method is now being used by state-linked groups against developers.
A photograph of the thing that is hard to fake
A security mark works because it is hard to copy. Photograph it well enough to check it, and a copy exists.
The twist
A security feature works by being hard to reproduce — so a check good enough to confirm it has to reproduce it, and the proof it leaves behind is the thing worth stealing.
How it works
- A licence carries marks that are hard to copy
- To check them, a machine photographs the licence under infrared and ultraviolet light
- The photographs are kept, so the check can be proved later
- One company ends up holding millions of them
- The pictures of what makes a licence hard to fake are now for sale
Where you've seen this
Art dealing
the high-resolution scans made to detect forgeries are what forgers study
Fingerprints at borders
the record proves it is you, and cannot be reissued if it leaks
Age checks on websites
proving you are over 18 leaves a picture of your licence with a company you will never hear of again
Banknote scanners
the detail a machine needs to spot a fake note is the detail a printer needs
The catch
This only holds while the check trusts a picture. A reader that queries the issuing state, or reads a chip that answers yes or no, leaves nothing behind worth buying.
And the whole of it
Everyone in this story did the ordinary thing. The clerk checked the licence, which is the job. The rental firm bought a machine that checks properly, which is better than not checking. The customer handed the card over, because the alternative is no car. Nobody in that queue could see the store the checks were filling up, and most of us are standing in a queue like it.
What is really going on
Proving who you are has been handed to a few private firms that shops and rental desks buy machines from, and the most careful version of that check is the one that leaves the most valuable copy behind.
Why it works on us — 153 million is too large to feel, so the story that actually lands is a reporter finding his mother's licence timestamped seconds after his own at the same rental counter.
Who gains
-
Whoever bought from Nexus before it closed
— They hold infrared and ultraviolet scans that a licence reader was built to accept, and licence numbers and dates of birth that cannot be reissued.
[1] [2] -
The ShinyHunters extortion group
— Attaching a 284 million record claim to a company that supplies a third of North America's prescription medicines makes the next company's board read the deadline as real.
[3] [4] -
Affiliates of the Outsider phishing kit
— The police operation removed the sellers' infrastructure and left more than 700 working domains in the hands of people who had already bought the kit.
[40] -
OpenAI
— Its $1bn credit programme puts its models inside water utilities, community banks and hospital security teams that could not otherwise buy them.
[55]
Who pays
-
Anyone who handed a licence to a rental desk, hotel or dispensary that scanned it
— Six images of their document, timestamped with where they were that day, were offered for sale, and a licence number cannot be changed the way a card number can.
[1] [2] -
People hiding from someone
— A researcher named those fleeing domestic violence and people in witness protection: the image is of a face, and a face cannot be meaningfully changed.
[1] -
The 9.5 million people in the Aesto Health file
— Names, social security numbers, medical details and bank account numbers were taken from a records-migration firm none of them chose.
[8] -
People whose sealed court records sat in C-Track
— Files that courts had sealed or redacted, often to protect a witness, were among those taken.
[6] [7] -
A jobseeker who had just resigned
— A fake recruiter's technical test carried malware, and he lost his savings.
[58]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
Where the 153 million licence images actually came from.
The trail points at idscan.net through timestamps and client names, but the company has said only that it is investigating, and Caesars — listed as a client on the vendor's own site — says it has not been one since February 2025.
[1] -
02
Whether the images are gone now that the shop is offline.
The Nexus site was replaced by a line saying the service was no longer available hours after publication. Nothing says the files were deleted rather than moved.
[1] -
03
What was taken from McKesson, and from how many people.
The company confirmed data was taken from two business units but has not said what or how many. The only figure in circulation, 284 million records, is the extortion group's own claim.
[3] [4] -
04
How the attacker got into the court records system, and how many people are affected.
Thomson Reuters has not said how, who, or how much. Montana's Supreme Court says the access ran March to June.
[6] [7] -
05
Whether Cambodia's scam compounds are actually gone.
The government says no large-scale compounds remain and also says the gangs moved to smaller scattered operations. Amnesty International doubts the industry has been eradicated.
[45] [46] -
06
Who is behind Fire Ant.
Sygnia says the activity strongly overlaps public reporting on the China-linked group UNC3886, and explicitly declines to conclude they are the same.
[33] -
07
Whether US agencies were breached by Chinese hackers or only aimed at.
The US justice department published one version and then corrected it to the other; the first version travelled further than the correction.
[38] -
08
Whether the SonicWall, JFrog and PaperCut flaws reached anything.
All three are confirmed under attack and added to the US known-exploited list, but no victim has been named for any of them.
[11] [12] [14]
A reporter found his own driving licence for sale, then traced 153 million of them to their source by asking nine friends where they had been. The shop selling them went dark the night his story ran.
More from Cybersecurity