America's Driver's License Breach Is a National Security Disaster
- ID
- 24986
- Status
- summarized
- Published
- 15 Sep 2026, 11:58 PM
- Fetched
- 17 Sep 2026, 11:47 PM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://www.lawfaremedia.org/article/america%27s-drivers-licence-breach-is-a-national-security-disaster
- Source URL
- https://hnrss.org/best
Summary
- Score
- 6.0
- Created
- 18 Sep 2026, 12:54 AM
- Tags
- Audience
- developerssaas_founders
What happened
A dark web service called Nexus was selling access to 153 million US and Canadian driver's licenses and 3 million travel documents, exfiltrated continuously for over a year from identity verification service IDScan. Krebs on Security verified the licenses were genuine and linked the breach to IDScan, which has confirmed it is investigating. The FBI is involved, and the data has national security implications beyond routine identity theft because license numbers are key identity documents used in intelligence operations.
Why it matters
If you build KYC or identity verification flows using third-party ID scanning services, this is a concrete reminder that your vendor can become the breach vector — IDScan's entire value proposition was fraud reduction, yet it allegedly leaked for over a year undetected. Malaysian builders using similar identity verification APIs should ask vendors about continuous exfiltration detection, not just one-time breach response, and consider what happens to scanned ID images after verification succeeds.
Discussion angle
What due diligence should you do on identity verification vendors before piping your users' ID documents through them — and do you actually need to retain scanned ID images after verification, or can you delete them immediately?