The FBI is investigating the sale of millions of stolen driver’s licenses

The FBI is investigating the theft and sale of scans of millions of IDs belonging to people in the United States and Canada.

The documents were advertised in a database called Nexus, which this week advertised in a dark corner of the Internet as containing a total of about 170 million identity documents.

She announced the availability of the documents on Tuesday Krebs on security, a blog run by Brian Krebs, a former Washington Post reporter with a background in cybersecurity.

The FBI declined to provide details on the origin of the breach, citing an open investigation. However, it confirmed in an emailed statement “that it is looking into the incident”.

The breach, which reportedly includes digital copies of driver’s licenses, travel documents and medical cards, is part of an increasingly common pattern of fraud and scams in which stolen materials can be used to create fake identity documents, said James E. Lee, president of the Identity Theft Resource Center, a nonprofit that tracks breaches and advises victims.

Adding photos in this particular theft can make it easier to create fake credentials.

“Unfortunately, the size of this breach is no longer unusual, but the nature of the data that was compromised makes it a particularly risky breach,” Mr Lee said.

Nexus first promoted the sale of stolen scanned IDs on a Russian cybercrime website called Exploit, Mr. Krebs said.

Previews of the site’s offering, some complete with photographs, included a driver’s license belonging to Pete Hegseth, the defense secretary, Mr. Krebs said.

“The Department is aware of these reports and is evaluating them,” the Defense Department said in an emailed statement.

Infoblox, a network security company that maintains a database derived from its access to dark web forums, provided a statement via email on Friday that cited Nexus’ ad in which it offered millions of documents for purchase for the first time.

In addition to 160 million North American driver’s license and identification card records, Nexus said it also offers more than 10 million international IDs, travel documents, residency cards and health cards for sale.

About 500,000 documents were added every day.

“We offer access to our own and exclusive database of compromised IDs,” the ad said.

Nexus added that it has “enduring access to a major identity verification company and its customers,” including “multiple Fortune 500 companies.”

“We have been continuously adding new data for over a year to our private database,” the ad said.

Zach Edwards, researcher with Infoblox Threat Intelsaid in a statement that the breach was notable because of its size and the access it gained over such a long period of time.

“This attack would be shocking if the threat actors only stole a database of more than 150 million driver’s licenses and other credentials,” he said. “But the fact that this was also allegedly a continuous, real-time breach with new credentials submitted by vendors and stolen by threat actors, and that those credentials were submitted from countless enterprise providers, means that this attack created legitimate national security risks for high-profile individuals.”

Mr. Edwards said in an interview that because of the sheer scale of the breach and because not all stolen documents have addresses, notifying victims would be a challenge.

Krebs on Security reported that identity theft service Nexus disappeared from the dark web after it released its report on Tuesday, citing unsearchable parts of the Internet that are often used for criminal activity.

Mr. Lee of the Identity Theft Resource Center urged Americans and Canadians to be vigilant in responding to theft.

“We still don’t know much about the data and the source, but people should be aware of signs that their identity is being compromised and the rise of highly personalized phishing attacks,” he said.