FBI Investigates Dark Web Service Selling Over 153 Million Drivers Licenses
A new dark web marketplace named Nexus is offering over 153 million scanned drivers licenses from the US and Canada, believed to originate from a breach at a major identity verification firm. The FBI has launched an inquiry into the service.

A new dark web service, identified as Nexus, has emerged, offering for sale over 153 million scanned drivers licenses originating from both the United States and Canada. Initial investigations suggest the data originates from a significant breach at a prominent identity verification company based in Louisiana. The New Orleans field office of the Federal Bureau of Investigation (FBI) has reportedly launched an inquiry into the source of these compromised documents.
Among the vast trove of personal data available on Nexus are digital scans of drivers licenses belonging to high-ranking U.S. government officials, including U.S. Defense Secretary Pete Hegseth. The service was first advertised on the Russian cybercrime forum Exploit by a new user, offering access to digital scans of identity documents for more than 170 million individuals across North America. The proprietor of the service even offered a sample of the data, including a scan of the author's own Virginia driver's license.
Nexus claims to possess an extensive database, not only of 153 million drivers licenses but also over 10 million identification cards, more than three million travel documents, and at least 579,000 medical cards. A preliminary search within Nexus, without specific parameters, returned approximately 11.5 million pages of results, indicating the sheer volume of data available. While the dataset includes records from both Canada and the United States, the majority of the licenses appear to be from Americans. Canadian licenses constitute about 1.1 million records, with a significant concentration from Ontario.
The data offered includes not only standard drivers licenses but also marijuana dispensary cards. Some records are sourced as 'CDL' (Commercial Drivers License) or 'CAC' (Common Access Card), suggesting a variety of identification types have been compromised. The operators of Nexus assert that the license images are being exfiltrated from an ongoing breach at a "major identity verification company" that serves numerous Fortune 500 clients. The number of available drivers license records has shown a notable increase, with nearly 400,000 new records added in a single 24-hour period, indicating a continuous flow of freshly compromised data.
Each license scan, including the author's, reportedly includes six image files: front and back versions, along with infrared and ultraviolet scans. These image files are appended with date and timestamps, with the timestamp on the author's license corresponding to a flight taken in June 2025. While not all records contain photos, and some with photos lack associated filenames, the timestamps suggest a connection to specific events. Research indicates that the timestamps may be in Greenwich Mean Time (GMT).
Further investigation into the source of the data revealed that individuals whose licenses were found on Nexus confirmed travel or car rental activities around the dates indicated in the timestamps. While initial theories pointed towards airports, the absence of passport data and the involvement of car rentals (specifically Hertz) suggest a broader scope. Some federal employees who provided their licenses for the research had used other forms of government identification at airports but later used their state-issued driver's licenses for car rentals, aligning with the data found on Nexus.
The implications of such a large-scale sale of drivers licenses are significant. These documents contain a wealth of personally identifiable information (PII) that can be used for identity theft, financial fraud, and to bypass various security checks that rely on visual identification. The FBI's involvement underscores the severity of the breach and the potential impact on millions of individuals.
The continuous exfiltration and sale of this data highlight the persistent threats posed by compromised identity verification services and the sophisticated operations of cybercriminals in the dark web ecosystem. The FBI's investigation will be crucial in identifying the perpetrators, understanding the full scope of the breach, and potentially mitigating further harm to affected individuals.