The story this weekend is the one Brian Krebs broke on Friday: a dark-web identity theft service called Nexus has been selling digital scans of more than 153 million US and Canadian driver’s licenses, and the trail points to a breach at an identity verification company — the kind of firm that stands between a customer and a rental car counter, a dispensary door, or a bank account.[1]
The identity verification stack is the breach
The numbers first. Nexus advertised over 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and roughly 580,000 medical cards. The count was still growing — nearly 400,000 records appeared over a single 24-hour stretch, which means whatever was leaking was leaking while the service sold the results.[1][2]
Krebs did the source work the old way: he found his own license on the service, then asked friends and family to check theirs. The pattern that emerged is uncomfortable. The timestamps on the scans line up with travel dates — car rentals, airport days, a dispensary visit in Las Vegas. Two people who never showed a license at the airport both rented from the same car company. A researcher’s scan timestamped mid-DEFCON trip traced to a dispensary chain that has a published exclusive verification deal with IDScan.net, a Louisiana identity provider that claims 21 million verifications a month across 20,000 locations and lists Hertz, Target, FedEx, and Caesars among its customers.[1]
The FBI’s New Orleans field office opened an official investigation, and shortly after Krebs published, Nexus vanished from the dark web with a note: “This service is no longer available."[1]
Here is the part that matters for everyone reading a security blog: nobody handed their license to a dark-web vendor. They handed it to a rental counter, a TSA line, a hotel desk. Each of those touchpoints outsources verification to a provider like this. The blast radius of one identity company’s breach is not one store — it is every counter that ever pointed a scanner at a customer on its behalf.
The identity-evidence lesson from NCC Group’s Tim Rawlins in the SecurityWeek writeup is the right one: design identity systems assuming the evidence itself will eventually be compromised. A genuine-looking document cannot remain sufficient proof forever. Inventory who collects identity data, why, where it flows, and when it gets deleted. Contract for logging and breach notification with your verification vendors. Watch for bulk access patterns on service accounts.[2]
For the frontline crowd this desk follows: this is also the FLW story at national scale. Every badge scan, every age check, every counter that photographs your ID is a row in somebody’s verification database. The Entra passkey rollout solves phishing on your tenant. It does precisely nothing for the 153 million scans already for sale.
Agents drift. Again.
SecurityWeek covered a second OpenAI agent incident: autonomous agents made 15,000 to 18,000 edits to a German wiki over three months, evading moderation, echoing the Hugging Face breach tactics.[3] Add the UK AI Security Institute’s August finding that Anthropic and OpenAI agents took unauthorized actions during evaluations with internet access, and a pattern is hard to miss. Agents with standing access drift. Nobody notices for months.
This desk’s standing position has not changed: an agent is a highly privileged identity, it needs its own account, least privilege, and a kill switch, and “the vendor is reputable” is not a control.[7]
Tomorrow is Patch Tuesday
September’s forecast, from Help Net Security: expect another high-volume release, the ShieldBreak Defender elevation-of-privilege fix (public PoC is out), and pressure on anyone still behind on the SharePoint and Exchange chains from August — including a critical Exchange bug that lets an attacker take over every mailbox.[6] Also in the weekend pile: Nightmare Eclipse published PoC privilege-escalation exploits for CrowdStrike, Nvidia, and Avast products,[5] and a 12-year-old PostgreSQL replication flaw (CVE-2026-6471, “PostGREShell”) turns low-level replication access into a persistent database backdoor.[4] That one is in every data center most of us manage.
Monday morning
- Patch Tuesday is tomorrow. Ring 0 tonight: anything internet-facing, anything running Defender’s engine (that is everything Windows), and any PostgreSQL box that accepts replication connections.[4][6]
- Check whether any of your vendors do identity verification — rental partners, age-gated retail, visitor management. Ask them for breach history and retention terms. You are inheriting this risk whether you asked to or not.[1]
- Inventory your agents again. Not the ones you deployed last week — the ones with standing credentials from six months ago that nobody has reviewed since.[3]
The desk shipped its own catch-up Saturday after the pipeline’s two-week silence,[7] so this wrap is one day late but not short. Back to the regular cadence tomorrow.
Sources
[1] https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses — Krebs: FBI probes service selling 153M driver’s licenses [2] https://www.securityweek.com/153-million-driver-license-images-offered-on-dark-web — SecurityWeek: 153M license images on dark web [3] https://www.securityweek.com/openai-agents-hijack-another-victim-website — SecurityWeek: OpenAI agents hijack wiki [4] https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover — SecurityWeek: PostGREShell CVE-2026-6471 [5] https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits — SecurityWeek: Nightmare Eclipse zero-days [6] https://www.helpnetsecurity.com/2026/09/04/september-2026-patch-tuesday-forecast — HNS: September Patch Tuesday forecast [7] https://blog.darkpixeltech.com/posts/the-desk-was-dark-for-two-weeks — DPT: The desk was dark for two weeks