VYPR
breachPublished Sep 1, 2026· Updated Sep 11, 2026· 10 sources

FBI Investigates Dark Web Service Selling Over 153 Million Drivers Licenses

A new dark web marketplace named Nexus is offering over 153 million scanned drivers licenses from the US and Canada, believed to originate from a breach at a major identity verification firm. The FBI has launched an inquiry into the service.

A new dark web service, identified as Nexus, has emerged, offering for sale over 153 million scanned drivers licenses originating from both the United States and Canada. Initial investigations suggest the data originates from a significant breach at a prominent identity verification company based in Louisiana. The New Orleans field office of the Federal Bureau of Investigation (FBI) has reportedly launched an inquiry into the source of these compromised documents.

Among the vast trove of personal data available on Nexus are digital scans of drivers licenses belonging to high-ranking U.S. government officials, including U.S. Defense Secretary Pete Hegseth. The service was first advertised on the Russian cybercrime forum Exploit by a new user, offering access to digital scans of identity documents for more than 170 million individuals across North America. The proprietor of the service even offered a sample of the data, including a scan of the author's own Virginia driver's license.

Nexus claims to possess an extensive database, not only of 153 million drivers licenses but also over 10 million identification cards, more than three million travel documents, and at least 579,000 medical cards. A preliminary search within Nexus, without specific parameters, returned approximately 11.5 million pages of results, indicating the sheer volume of data available. While the dataset includes records from both Canada and the United States, the majority of the licenses appear to be from Americans. Canadian licenses constitute about 1.1 million records, with a significant concentration from Ontario.

The data offered includes not only standard drivers licenses but also marijuana dispensary cards. Some records are sourced as 'CDL' (Commercial Drivers License) or 'CAC' (Common Access Card), suggesting a variety of identification types have been compromised. The operators of Nexus assert that the license images are being exfiltrated from an ongoing breach at a "major identity verification company" that serves numerous Fortune 500 clients. The number of available drivers license records has shown a notable increase, with nearly 400,000 new records added in a single 24-hour period, indicating a continuous flow of freshly compromised data.

Each license scan, including the author's, reportedly includes six image files: front and back versions, along with infrared and ultraviolet scans. These image files are appended with date and timestamps, with the timestamp on the author's license corresponding to a flight taken in June 2025. While not all records contain photos, and some with photos lack associated filenames, the timestamps suggest a connection to specific events. Research indicates that the timestamps may be in Greenwich Mean Time (GMT).

Further investigation into the source of the data revealed that individuals whose licenses were found on Nexus confirmed travel or car rental activities around the dates indicated in the timestamps. While initial theories pointed towards airports, the absence of passport data and the involvement of car rentals (specifically Hertz) suggest a broader scope. Some federal employees who provided their licenses for the research had used other forms of government identification at airports but later used their state-issued driver's licenses for car rentals, aligning with the data found on Nexus.

The implications of such a large-scale sale of drivers licenses are significant. These documents contain a wealth of personally identifiable information (PII) that can be used for identity theft, financial fraud, and to bypass various security checks that rely on visual identification. The FBI's involvement underscores the severity of the breach and the potential impact on millions of individuals.

The continuous exfiltration and sale of this data highlight the persistent threats posed by compromised identity verification services and the sophisticated operations of cybercriminals in the dark web ecosystem. The FBI's investigation will be crucial in identifying the perpetrators, understanding the full scope of the breach, and potentially mitigating further harm to affected individuals.

The new article from Malwarebytes Labs provides further details on the dark web platform Nexus, including the specific types and quantities of documents being sold, such as 153 million driver's licenses, 10 million ID cards, and hundreds of thousands of travel and medical cards. It also highlights the concerning inclusion of high-resolution front-and-back scans, infrared, and ultraviolet images, which are far more valuable to identity thieves than basic personal information. The article further elaborates on the risks associated with age-verification systems and the broader implications of identity documents being collected across numerous services.

The FBI is investigating a potential breach involving over 153 million driver's licenses, with scans of these licenses reportedly being offered for sale on the dark web. The scale of the incident suggests a significant compromise of personal identification data, with the data potentially originating from a breach at a major identity verification company. The FBI is reportedly probing the incident, which could impact millions of North American individuals.

This new report from SecurityWeek identifies IDScan.net as the likely source of the massive driver's license data leak, specifying that the stolen information consists of 153 million scanned US and Canadian driver's licenses. The data is being offered for sale on the dark web, raising significant concerns about potential identity theft and fraud.

The newly surfaced article provides additional details regarding the dark web service Nexus, including its advertisement on the Russian cybercrime forum Exploit and the specific types of documents offered beyond driver's licenses, such as other IDs, travel documents, and medical cards. It also elaborates on the technical aspects of the exposed data, noting the inclusion of front-and-back scans, infrared and ultraviolet images, and timestamps, which are crucial for identity verification systems. Furthermore, the article highlights the potential link to IDScan.net and mentions that Nexus has since disappeared from the web, though the data may have been copied.

The FBI's investigation into the sale of 153 million U.S. driver's licenses on an illicit marketplace is a key development. This massive data exposure, reportedly including names, addresses, and license numbers, underscores the ongoing risks associated with identity verification services and dark web marketplaces.

The article from Schneier on Security provides a high-level overview of the reported sale of a database containing 153 million driver's licenses on the dark web. While the FBI investigation mentioned in the existing story focuses on the marketplace and origin, this new piece highlights the sheer scale of the compromise and the potential impact on a vast number of individuals due to the significant amount of personal identification information involved.

IDScan has now confirmed the data breach, stating that an unauthorized third party may have accessed and copied customer information, including full names and driver's license numbers. The company's announcement, initially unindexed on its website, was made public after cybersecurity journalist Brian Krebs reported on the sale of 153 million driver's license scans on the dark web marketplace Nexus. The FBI has confirmed it is investigating the incident.

IDScan.net has now officially confirmed the data breach, acknowledging that hackers accessed customer data stored on its cloud platform. The identity verification firm stated that an unauthorized third party "may have accessed and/or copied certain customer information," including names and government-issued identification numbers. The company is cooperating with federal law enforcement on their investigation and offering affected individuals free credit monitoring and identity protection.

IDScan.net has officially confirmed the data breach, detailing that unauthorized access was detected around September 1, 2026. The company is cooperating with an FBI inquiry into the matter and is offering affected individuals credit monitoring services. The breach reportedly involves over 153 million driver's licenses and 10 million other ID documents, including commercial licenses and medical cards, with attackers claiming continuous exfiltration for over a year.

Synthesized by Vypr AI