Full Report
Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Amberleigh Jack. This week's edition is sponsored by Authentik.You can hear a podcast discussion of this newsletter by searching for "Risky Business News" in your podcatcher or subscribing via
Analysis Summary
# Incident Report: Nexus Identity Data Exfiltration
## Executive Summary
A dark web service named "Nexus" offered for sale a database containing 153 million genuine U.S. and Canadian driver's licenses. The data was allegedly exfiltrated over the course of a year from IDScan, an identity verification company, via a continuous compromise. This breach is considered a national security disaster due to the potential for foreign intelligence services to link disparate datasets for counter-intelligence and espionage purposes.
## Incident Details
- **Discovery Date:** September 2026 (via Krebs On Security report)
- **Incident Date:** Ongoing for "more than a year" prior to discovery
- **Affected Organization:** IDScan (Identity verification service)
- **Sector:** Information Technology / Identity Verification
- **Geography:** United States and Canada
## Timeline of Events
### Initial Access
- **Date/Time:** Approximately Mid-2025
- **Vector:** Unauthorized access to a major identity verification provider (IDScan).
- **Details:** Attackers secured a foothold within the IDScan environment, allowing for prolonged access to incoming verification data.
### Lateral Movement
- **Details:** The threat actor established a mechanism to "continuously" exfiltrate new data as it was processed by the victim organization.
### Data Exfiltration/Impact
- **Details:** 153 million driver's license records were stolen. The database grew by approximately 400,000 records in a single day during observation, indicating real-time or frequent batch exfiltration. The data includes full names, home addresses, photos, and license numbers.
### Detection & Response
- **Detection:** Discovered when the "Nexus" service was advertised on dark web forums and subsequently investigated by Brian Krebs.
- **Response actions:** The FBI launched an investigation; IDScan confirmed a data security incident; the Nexus dark web service went offline shortly after public disclosure.
## Attack Methodology
- **Initial Access:** Compromise of an identity verification service provider.
- **Persistence:** Continuous exfiltration mechanism maintained for over 12 months.
- **Collection:** Automated gathering of identity documents (licenses) during the verification workflow.
- **Exfiltration:** Systematic transfer of data to a private "Nexus" database.
- **Impact:** Mass identity theft risk and long-term national security implications regarding person-tracking.
## Impact Assessment
- **Financial:** High potential for identity fraud; long-term costs for credit monitoring and document re-issuance.
- **Data Breach:** 153,000,000 records involving PII (Personally Identifiable Information) and biometric-adjacent data (photos).
- **Operational:** Disruption to IDScan operations and loss of trust in identity verification supply chains.
- **Reputational:** High; high-ranking government officials, including the Secretary of War and FBI leadership, were confirmed victims.
## Indicators of Compromise
- **Network indicators:** Nexus dark web service (URL defanged: hxxps[://]nexus[.]onion - *hypothetical example as specific onion addresses were not provided in text*).
- **Behavioral indicators:** Unusual outbound data spikes to unauthorized external databases; unauthorized API access to identity document storage.
## Response Actions
- **Containment:** IDScan initiated internal investigations to close the exfiltration point.
- **Eradication:** Law enforcement (FBI) intervention to track the "Nexus" operators.
- **Recovery:** Public notification of the breach and ongoing forensic audit of the affected systems.
## Lessons Learned
- **Supply Chain Vulnerability:** Identity verification services are "honey pots" for both cybercriminals and state-sponsored actors.
- **Continuous Exfiltration:** Traditional "smash and grab" detection failed to identify a year-long slow-bleed of data.
- **Data Aggregation Risks:** The value of this data is amplified when combined with previous breaches (OPM, Equifax, Anthem) to deanonymize intelligence assets.
## Recommendations
- **Zero Trust Architecture:** Implement strict segmentation between public-facing verification portals and backend storage.
- **Enhanced Monitoring:** Deploy behavioral analytics to detect "trickle" exfiltration that bypasses traditional volume-based alerts.
- **Encryption at Rest/Transit:** Ensure all identity documents are encrypted with keys managed in secure hardware modules, limiting the ability for attackers to read exfiltrated files.
- **Government Oversight:** Increased regulatory scrutiny for third-party identity providers handling sensitive government personnel data.