153 Million Driver’s Licenses Hit the Dark Web. FBI Is Investigating
- The Mess: A dark-web service called Nexus surfaced with more than 153 million U.S. and Canadian driver’s license scans. The FBI is investigating where the data came from.
- The Damage: These aren’t email addresses or password hashes — the dataset contains images of government-issued identity documents, including front, back and additional scans.
- The Fix: Organizations handling identity documents need to assume the data may be actively abused for impersonation, fraud and targeted social engineering.
This is what happens when identity verification turns into a giant database of things people cannot replace easily.
A cybercrime service named Nexus appeared on a Russian-language criminal forum offering access to an enormous collection of identity documents. The advertised dataset contains more than 153 million U.S. and Canadian driver’s licenses, over 10 million identification cards, more than three million travel or international identity documents, and hundreds of thousands of medical cards.
The numbers are not just marketing noise.
KrebsOnSecurity searched the service and found millions of individual records. Researchers also checked licenses belonging to people who voluntarily agreed to have their identities searched. Multiple matching records were found.
The FBI’s New Orleans field office has opened an investigation into the source of the data.
The Data Is Much Worse Than a Database Dump
Some records contain several images of the same document.
Researchers found examples containing front and back photographs, basic scans and additional infrared or ultraviolet images.
That gives criminals far more material than a stolen name and address.
A driver’s license can contain:
- full legal name;
- date of birth;
- photograph;
- address;
- document number;
- physical descriptors;
- state or provincial information;
- machine-readable information.
The additional images can make automated document verification easier to defeat.
That creates a very different risk profile from an ordinary credential breach.
The Source Points Toward Identity Verification
The evidence collected so far suggests that the material may have been taken from an identity-verification provider.
KrebsOnSecurity linked multiple records to real-world interactions where users had presented identification documents. The timestamps attached to some images also corresponded with dates when the individuals had actually used their licenses.
The reporting points toward IDScan.net as a possible source, but that attribution has not been conclusively established as the confirmed origin of the entire dataset.
That distinction matters.
There is a massive difference between data appears to originate from a company’s systems and the company has confirmed that its systems were breached.
At publication time, the latter had not been established.
Nexus Was Apparently Still Receiving Data
One of the nastier details is the apparent growth of the database.
KrebsOnSecurity observed the advertised number of driver’s license records increasing by hundreds of thousands within roughly 24 hours.
That suggests this may not be an old archive dumped onto a forum.
If the observations are accurate, someone may have had — or still have — access to a source capable of supplying new identity records.
That turns the incident from a static breach into a potential ongoing collection operation.
This Is Perfect Material for Fraud
A stolen password can be changed.
A stolen driver’s license is different.
You cannot rotate your date of birth.
You cannot simply replace your face.
You cannot revoke every copy of an identity document that has already been downloaded.
Criminals can use this kind of material to build convincing impersonation packages, pass weak KYC checks, create fraudulent accounts, target financial institutions or make social-engineering attacks look legitimate.
And the more complete the document package, the easier it becomes to combine the stolen identity with information obtained from other breaches.
The Identity Verification Problem
Companies increasingly ask customers to upload government IDs for onboarding, age verification and account recovery.
That creates a tempting target.
A single successful intrusion can produce an inventory of identities instead of a collection of usernames.
The security requirement should therefore be much higher than simply encrypting a database and calling the job finished.
Systems processing identity documents need strict retention limits, strong access controls, detailed audit logging, segmentation and aggressive monitoring for bulk extraction.
The less data retained, the less data an attacker can steal.
Bugstoday Opinion
This incident exposes a particularly ugly security equation:
You cannot change the identity document after somebody copies it.
Passwords have reset buttons. Identity documents don’t.
The 153-million figure is enormous, but the more worrying detail is the apparent presence of fresh records and the possibility that the underlying source may still be accessible.
The FBI investigation should establish whether IDScan.net was actually breached, how the records were obtained and whether the collection is still growing.
Until then, anyone operating an identity-verification platform should assume attackers are looking at the same business model: collect once, monetize forever.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
KrebsOnSecurity — FBI Probes Service Selling 153M+ Drivers Licenses
Federal Bureau of Investigation — New Orleans field office investigation
SecurityWeek — 153 Million Driver License Images Offered on Dark Web
TIME — FBI Probes Report of Breach Exposing 153 Million Driver’s Licenses




