The F.B.I. is investigating the theft and sale of scans of millions of identity documents belonging to people in the United States and Canada.
The documents were being promoted on a database called Nexus, which advertised on a dark corner of the internet this week as including about 170 million identity documents in all.
The availability of the documents was reported on Tuesday by Krebs on Security, a blog run by Brian Krebs, a former Washington Post reporter with an expertise in cybersecurity.
The F.B.I. declined to provide details about the origins of the breach, citing an open investigation. But in an emailed statement, it confirmed “that it is looking into the incident.”
The breach, which is said to include digital copies of driver’s licenses, travel documents and medical cards, is part of an increasingly common pattern of scams and frauds in which stolen materials can be used to create fake identity documents, said James E. Lee, the president of the Identity Theft Resource Center, a nonprofit that tracks breaches and advises victims.
The addition of photographs in this particular theft can make it easier to create fake credentials.
“Unfortunately, the size of this breach is no longer uncommon, but the nature of the data that has been compromised makes it a particularly risky breach,” Mr. Lee said.
Nexus first promoted the sale of the stolen scanned identity documents on a Russian cybercrime site called Exploit, Mr. Krebs reported.
Previews of the site’s offerings, some accompanied by photographs, included a driver’s license belonging to Pete Hegseth, the defense secretary, Mr. Krebs reported.
“The department is aware of these reports and is evaluating them,” the Defense Department said in an emailed statement.
Infoblox, a network security company that maintains a database derived from its access to dark web forums, provided a statement by email on Friday that quoted Nexus’s advertisement in which it first offered the millions of documents for purchase.
The Nexus advertisement said that, in addition to 160 million records of North American driver’s licenses and identification cards, it was also offering for sale more than 10 million international identity documents, travel documents, residency cards and medical cards.
It said about 500,000 documents were being added every day.
“We are offering access to our proprietary and exclusive database of breached identity documents,” the advertisement said.
Nexus added that it had “persistent access to a major identity verification company and its customers,” including “multiple Fortune 500 companies.”
“We have been continuously exfiltrating new data for over a year into our private database,” the advertisement said.
Zach Edwards, a researcher with Infoblox Threat Intel, said in the statement that the breach was remarkable because of its size and the access it gained over such a long period.
“This attack would have been shocking if the threat actors merely stole a database with over 150+ million driver’s licenses and other credentials,” he said. “But the fact that this was also allegedly a real-time ongoing breach with new credentials being submitted to the vendor and stolen by the threat actors, and that these credentials were being submitted from countless enterprise providers, means that this attack created legitimate national security risks for high-profile individuals.”
Mr. Edwards said in an interview that, because of the enormous scope of the breach, and because not all of the stolen documents have addresses, notifying victims would be a challenge.
Krebs on Security said that, after it published its report on Tuesday, the Nexus identity theft service vanished from the dark web, referring to parts of the internet that are not searchable and that are often used for criminal activity.
Mr. Lee of the Identity Theft Resource Center encouraged Americans and Canadians to be vigilant in response to the theft.
“There’s still a lot we don’t know about the data and the source, but people should be on the lookout for signs their identities are being misused and an increase in highly personalized phishing attacks,” he said.
The post F.B.I. Investigates Sale of Millions of Stolen Driver’s Licenses appeared first on New York Times.




