FBI Probes Service Selling 153M+ Drivers Licenses
What Happened – A dark‑web marketplace called “Nexus” is offering digital scans of more than 153 million U.S. and Canadian driver’s licenses, plus other government‑issued IDs. The data appears to have been harvested from a widely‑used identity‑verification provider, prompting an FBI New Orleans field office investigation.
Why It Matters for Trust & Control Assurance
- The incident is a textbook example of a third‑party data breach that defeats any organization that relies on that verification service without continuous oversight.
- Continuous control‑assurance programs require documented vendor‑risk assessments, ongoing monitoring of third‑party security posture, and defensible evidence that data handling agreements are being honored.
- Verisq’s Vendor Risk Management capability supplies the audit‑ready evidence stream needed to prove you’re actively managing and monitoring such suppliers.
Who Is Affected – Companies that integrate external identity‑verification APIs (financial services, SaaS platforms, e‑commerce, health‑tech, etc.).
Recommended Actions
- Initiate an urgent third‑party risk review of any identity‑verification provider you use; verify breach notifications and assess data‑handling controls.
- Collect and map evidence of vendor due‑diligence (contracts, security questionnaires, monitoring logs) to the relevant control objective in your audit framework.
- Update incident‑response playbooks to include a “third‑party breach” scenario and test the communication flow.
Technical Notes – The service claims the source is an “active breach” at a major verification company; records include driver’s licenses, commercial driver’s licenses, Common Access Cards, and medical cards. No specific CVE is cited; the vector is likely a compromised internal system or API used by the provider to collect and store scanned IDs. Source: Krebs on Security