The Nexus identity breach is far more dangerous than a typical password dump because the stolen material reportedly includes the faces, addresses, birth dates and hidden security features of government-issued IDs, cybersecurity expert Dr. Marilyne Ordekian told Bitcoin.com News.Key TakeawaysNexus claimed roughly 170 million ID records, including 153 million U.S. and Canadian licenses.Ordekian warns Nexus ID scans could fuel fraud because victims cannot simply reset their identities.Sumsub’s Popov says ID checks need a 2nd factor as the FBI investigation remains open. The dark-web marketplace surfaced in late August, claiming access to roughly 170 million records, including more than 153 million U.S. and Canadian driver’s licenses, 10 million other IDs, 3 million travel documents, and at least 579,000 medical cards. Its operators claimed the information had been siphoned for more than a year from a major identity verification company. Nexus Leak Goes Far Beyond a Password Dump A password breach is ugly, but there is usually an escape hatch: Change the password. Government identification is a different beast. Dr. Marilyne Ordekian noted that driver’s licenses contain information that follows people for years, if not forever, including their photograph, home address and date of birth. “With breaches leaking passwords, one can reset their credentials and move on,” Ordekian said. With stolen government IDs, she explained, the information is effectively baked into a person’s identity and cannot simply be reset after criminals get their hands on it. What makes Nexus particularly alarming is the reported presence of infrared and ultraviolet scans. Ordekian explained that these scans are “a security measure used to verify authenticity,” meaning they are used “to authenticate a physical document as genuine.” She warned that criminals potentially have “not just your ID, but also have the blueprint and the technical layer used to prove your ID is genuine.” That opens up a great deal of trouble. “Every ID-gated system, be it opening a bank account, a cryptocurrency exchange account, renting a car, verifying a wire transfer etc (anything that relies on this type of ID for identity verification) is now a potential attack surface which can be exploited,” Ordekian said. Stolen Security Features Raise the Stakes for Fraud Once those records reach criminal markets, identity theft is only the starting point. Stolen credentials could potentially be recycled for impersonation, fraudulent bank accounts, money laundering, and other schemes. Ordekian warned that the infrared and ultraviolet material could make fraudulent use harder for verification systems to detect because the underlying documents themselves are real. There is also a physical-security angle. “We’ve been seeing within the cryptocurrency space, for example, how some users and victims of data breaches are being identified as investors and being targeted physically to give out their assets,” Ordekian stressed. “In this situation here, it can also endanger domestic violence survivors and people in witness protection programmes.” Private keys aren’t the only crypto risk.