Data Aggregation of Driver’s License Data Comes at a Cost (The Nexus Hack)

From Krebs on Security:

“A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada….The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards.”

Now this isn’t a hack of a single state or province, since none has 153 million records.

But there are services that aggregate driver’s license data. The first one that came to mind is the American Association of Motor Vehicle Administrators, or AAMVA. Specifically, its Driver’s License Data Verification (DLDV) Service and its State-to-State (S2S) Verification Service.

But this doesn’t mean that AAMVA was hacked, since a number of third party entities can access the AAMVA data.

  • For example, the states themselves. If you apply for a new license in a participating state, it can check to make sure you don’t have an active license in another state. Having two driver’s licenses from two separate states is bad.
  • In addition, identity verification providers can access the AAMVA data. If you present “selfie plus ID” to verify your identity, the identity verification provider may not only confirm that the ID is real, but may also check with the issuing state or province to confirm it has a record of the license.

So with all these entities that can access the AAMVA data, you have a nice little third party risk management issue.

In fact:

“The people behind Nexus claim the license images are coming from an active breach at “a major identity verification company” whose customers include multiple Fortune 500 companies.”

Of course, the Nexus hackers may be lying to misdirect anti-fraudsters and cover their tracks. Fraudsters are not trustworthy people.

But if the Nexus hackers are telling the truth about the source of the hacked driver’s license data, some identity verification company is going to be in very big trouble.

Regardless, you can buy licenses of real people. Brian Krebs says that Pete Hesgeth’s license data is on the dark web. As is Krebs’ own license. And his mother’s.

No idea if my data is out there.

But 153 million people will be very interested in the source of the hack.

Leave a Comment