pull down to refresh

IDs are not private information at this point and the possession of information contained on an ID should not indicate any participation on the part of an individual.

On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit.
The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.
The record that features my drivers license includes six image files — three pairs of photos of the license’s front and back — a basic image scan — as well as infrared and ultraviolet versions of the same images. A date and timestamp is appended to each image file, and the timestamp on my license scan corresponds to a date in June 2025 when I took a flight to the midwest United States to attend a family funeral.
Intent on discovering the source of this data, KrebsOnSecurity asked more than a dozen friends and family members for permission to search for their licenses in this service. Each person whose license could be found (nine of them) confirmed having traveled on or very close to the dates in the timestamps attached to their images. It is unclear what timezone these timestamps are in, but from reviewing car rental records shared by several people who helped with this research, it appears the timezone is set to Greenwich Mean Time (GMT).

At first, I thought the source of the data might have something to do with airports. However, that theory went out the window when it became apparent there were no passports in this data set. Also, only some of those who helped with this research said they showed their drivers license at the airport on the day of their travel. One person whose license was in Nexus hadn’t flown at all recently, but was renting a car from Hertz for several months around the date of their timestamp.

Two of those who agreed to help are federal employees who said they shared other forms of government identification when passing through airport security. However, those individuals each said they shared their state-issued drivers licenses later that day when renting vehicles at their respective destinations, and that both rented their cars from Hertz.

After finding a note in my calendar for the day of my June 2025 flight reminding me to bring my passport, I remembered that I also never actually shared my drivers license when I went through security at Reagan National Airport on that day because I did not yet have a Real ID, a security-enhanced drivers license that is now required by the Transportation Security Administration (TSA) for all domestic travel. Instead, I showed the TSA agent my government-issued U.S. passport.

Here’s where it gets interesting: I was able to find my mother’s drivers license in this service as well, and the timestamps for her images are just a few seconds apart from mine. That’s notable because we both handed our licenses to the Hertz rental car representative at the same time.

According to my mom, the only place she gave her drivers license to that day was the rental car company, and if memory serves that is also true for me. I don’t recall if the rental car representative inserted our licenses into any kind of machine, but I remember they held onto them for several minutes behind the counter while we were signing various forms. KrebsOnSecurity sought comment from Hertz and will update this story in the event they reply.

It's crazy how this kind of article does not seem to bother the majority of people.

reply

Such articles as these I often read at a skim. I don't care too much how the author says things, but rather I'm looking for derails in the article. As long as they provide them and links to verify in some way, I'm usually happy.

In this case the article was light on verification links, but i found the first-hand accounts useful.

Why does it bother you of they generated most of the article's text?

reply

I meant in the sense that this kind of article about data leaks flies under the radar. Only on SN do I see them once in a while. Now, the algorithm is slowly picking up on my interest in them, but before that, I almost never saw them in mainstream media.

EDIT: but i understand the confusion, I've been ranting a few times about LLM generated stuff. I don't mind generally, as long as I can see there is genuine human input/insights before AI slopified it.

reply

Ah! Sorry to have misunderstood!

In my daily life I encounter just about zero people who are at all concerned about privacy. The idea of not wanting to enter an address or phone number is shocking to most people I know.

I don't know how we change that.

reply
The idea of not wanting to enter an address or phone number is shocking to most people I know.

Ditto. Tbf, I was there not long ago. And I'm not actively fighting it yet.
Convenience is a drug.

reply
Edwards said that as more in-person and online experiences require sharing drivers licenses, vendors who collect this sensitive data need to be held to a higher standard.

OR, stop playing that 1984 playbook, bro. it was a warning, not an instruction manual

reply
it was a warning, not an instruction manual

@optimism got trained on LLM material, or did LLMs get trained on @optimism material?

I do wonder though if the next generation will start talking more like LLMs due to their abundant interaction with it from an early age. I think I read a headline about that a while ago, but guess it's too early to quantify it.

reply

What makes you say that though? It can be that bots are rubbing off on me.

reply

The typical It was this, not that pattern. Tbf, it already existed before LLMs, it just became so much more prevalent.

reply

Oh yeah I think I did that before Sam Altman was a bad dream in his dad's nutsack, but you are right... last couple of months this is prevalent and it spread wide because they all RL on the same traces now.

It can be I use it more now. This morning alone I read 30 issues of slop. I didn't even get to do my "work on shit while bots are busy" because I'm once again the bottleneck.

reply

I don't envy you. I missed the screenshot earlier.

reply

I'll be fine, this is just one ecosystem. I haven't even had time to dig through today's signal release yet.

I have 29 pending followup tasks queued from this alone right now, after I ran through all these. But now Claude is down and my ppq runner is also down due to me experimenting too much. Means I won't have to read slop for at least an hour now though! But the backlog is real and I'm not looking forward to my evening.

reply

Having recently crossed a few borders, the only thing I can say is that we are doomed. They scan, image, fingerprint, and record everything. In one airport alone, I believe I went through three separate identity screenings. There is absolutely Nero chance they safely segregate that data. So we must all get used to the idea that all identifying data is publicly available (fingerprints included).

By the time governments (who seem to drive most of this ID craze) finally wise up, we will be entirely pwnd.

reply
I believe I went through three separate identity screenings.

Interesting. Last time I was at DFW I got 3 as well, but that was on me. One because coming in from international, went out for a smoke so I had to go through TSA (=2) on the way back in, then my connecting flight had a disconnect so I went back into the parking area and loaded up on nicotine once more, to go through TSA back the second time (=3). I think that if I were to just have a smooth connection it would've just been 2? One for coming in, and one for TSA to get the permission to enter a domestic flight.

we will be entirely pwnd.

I think that eventually they'll have to do something about it. If too many identities are stolen, there will eventually be no point to asking for the identifier. I think that SSNs will be replaced by biometrics for the government things.

reply