153 Million Driver’s Licenses Hit the Dark Web. The FBI Is Investigating
- The Mess: A dark web identity theft service called Nexus was offering digital scans of more than 153 million U.S. and Canadian driver’s licenses, alongside millions of other identity documents. The FBI has opened an investigation into where the data came from and how it ended up in the hands of cybercriminals.
This isn’t another leak containing email addresses and hashed passwords.
These are identity documents.
According to the investigation by KrebsOnSecurity, Nexus advertised access to more than 153 million driver’s licenses, alongside millions of additional identification and travel documents.
The collection reportedly included more than 10 million other ID cards, millions of travel documents and international IDs, and hundreds of thousands of medical cards.
Krebs was able to verify the authenticity of records, including his own driver’s license, which was allegedly offered as a sample by the operator.
That changed the story very quickly.
This wasn’t just another cybercriminal claiming to possess a giant database.
Real people were finding their own documents inside it.
The FBI’s New Orleans field office is now investigating.
The identity verification company IDScan.net has emerged as a possible source of the documents based on reporting and analysis surrounding the leaked records, but the company has not publicly confirmed that its systems were the source of the breach.
That distinction matters.
Right now, investigators are still working through the evidence.
The suspected source is not the same thing as confirmed attribution.
- The Damage: A stolen password can be changed. A stolen driver’s license cannot.
A full scan of a government-issued identity document can contain exactly the information criminals need for a much wider range of fraud.
Names.
Addresses.
Dates of birth.
License numbers.
Photographs.
Document images.
Potentially enough information to support identity fraud, impersonation and attacks against systems that treat a driver’s license as proof that you are who you claim to be.
That is what makes this incident particularly ugly.
Companies increasingly ask customers to upload or scan government-issued identification.
Banks do it.
Financial services do it.
Rental companies do it.
Age-verification systems do it.
Retailers and other physical businesses do it.
Every one of those systems creates another place where an identity document can become a permanent digital asset.
And once the document escapes, there is no password-reset button.
The scale is also difficult to ignore.
More than 153 million driver’s licenses were reportedly available through Nexus, with only a relatively small portion coming from Canada.
The service itself disappeared shortly after the investigation became public.
That doesn’t mean the documents disappeared with it.
Once data reaches a cybercrime ecosystem, copies can move quickly between operators, marketplaces and private channels.
Taking one website offline doesn’t necessarily put 153 million identity documents back in the box.
The suspected breach also exposes a larger problem with the identity-verification industry.
Organizations often treat identity documents as a temporary verification step.
Scan the license.
Confirm the person.
Continue the transaction.
But the document may still pass through infrastructure operated by third-party verification providers.
That creates a concentration problem.
One service can process identity documents for thousands of locations and multiple industries.
If that service is compromised, the attacker isn’t stealing data from one company.
They may be stealing the identities collected by everyone connected to that verification pipeline.
That’s a much more valuable target.
And potentially a much more damaging single point of failure.
- The Fix: Treat unexpected identity-verification requests, phishing attempts and account-recovery messages with extreme suspicion, and assume that information printed on a government-issued ID can now be used to make social-engineering attacks more convincing.
There is no universal “replace everything” button for an incident like this.
A new driver’s license may give you a new document number in some jurisdictions, but it does not erase your name, address, date of birth or photograph from stolen copies.
The most realistic defensive step is to expect follow-up fraud.
Watch for unexpected account-recovery attempts.
Be suspicious of callers who already know personal information about you.
Don’t trust an email simply because it contains your real address or license-related details.
And be particularly careful when a company asks you to verify your identity because of a supposed security incident.
Criminals love turning one breach into the pretext for the next attack.
Organizations that collect identity documents should also be asking a harder question.
Do we really need to keep the full image?
The more copies of a driver’s license that exist, the more places an attacker can eventually steal it from.
Data minimization suddenly looks a lot less like a compliance buzzword when 153 million documents are allegedly sitting in a cybercrime marketplace.
Bugstoday Opinion
Passwords were supposed to be the thing you changed after a breach.
Then companies started asking for something more permanent.
Your face.
Your address.
Your government-issued identity.
And they called it verification.
Now more than 153 million driver’s licenses have reportedly passed through a dark web marketplace, and the FBI is investigating where the collection came from.
The uncomfortable part isn’t just the number.
It’s what the number represents.
A driver’s license is increasingly becoming the master key for proving who you are online.
Want to recover an account?
Show ID.
Want access to a financial service?
Show ID.
Want to prove your age?
Show ID.
Want to pass identity verification?
Upload the same document again.
Every time we normalize handing a permanent identity document to another company, we create another high-value vault.
And eventually somebody will try to empty it.
The password can be changed.
The driver’s license can be replaced.
But your identity is a much harder credential to rotate.
The dark web doesn’t need your password if it can buy your face, your address and your government ID instead.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
KrebsOnSecurity — FBI Probes Service Selling 153M+ Drivers Licenses
Reuters — FBI Probes Report of Data Breach Exposing Millions of Drivers’ Licenses
SecurityWeek — 153 Million Driver License Images Offered on Dark Web
:::




