Driver's License Data Breach: 153 Million Scans Sold on the Dark Web as FBI Investigates
A dark-web identity theft service called Nexus is selling scans of more than 153 million driver's licenses belonging to people in the United States and Canada, one of the largest troves of raw identity documents ever offered for sale. The suspected driver's license data breach surfaced in late August on a Russian-language cybercrime forum, and the FBI's New Orleans field office has opened an inquiry into the records' origin. The files appear to have been siphoned from IDScan.net, a widely used identity verification company based in Louisiana that has not confirmed any unauthorized access.
The storefront went offline on September 1, hours after security journalist Brian Krebs published his account of the operation. Before it vanished, Nexus had advertised the cache on the Exploit forum on August 31, describing a stock that included millions of additional identity and medical cards alongside the license images. The cybersecurity research group vx-underground was first to flag the scale of the offering.
Raw document scans carry a different risk profile than the payment-card numbers sold on earlier dark-web markets. A license image contains a photo, date of birth, home address, and a government document number, the elements a criminal needs to impersonate a victim when opening accounts, renting property, or applying for credit. Reissuing a card does not invalidate the copy a thief already holds, which makes the exposure effectively permanent.
Why a Verification Vendor Held the Files
IDScan.net and firms like it form a middle layer between businesses and their customers. Merchants and services use the platform to check that a license or passport is genuine before onboarding a user, and the scanned documents are kept on file as verification records afterward. Consumers rarely deal with IDScan.net directly, and most never choose to have copies of their documents stored by a third party.
That structure concentrates risk. A single compromised vendor can expose records collected on behalf of thousands of businesses, and the people affected may not learn of it until the images are already in circulation. The same dynamic showed up in the cloud-attack campaign that a Canadian hacker pleaded guilty to earlier this year, a spree that used stolen login credentials to reach 165 organizations through one software provider.
If the Nexus allegations hold up, this driver's license data breach would cover more than 153 million people in the US and Canada. IDScan.net has not confirmed the incident or its scope, leaving open how the images left the company and which of the businesses relying on its checks are affected. For the people in the cache, there is no notification to work from, only a marketplace listing to react to.
The Driver's License Data Breach Fits a Troubling Pattern
Verification and background-check firms have become favored targets because the material they hold is ready to exploit. Insurer AssuranceAmerica disclosed this year that a March attack exposed 6,998,886 people, including driver's license numbers and, in many cases, Social Security numbers. Background-check firm National Public Data remains in litigation two years after a hacker claimed 2.9 billion records and asked $3.5 million for the database.
The medical cards bundled into the Nexus cache widen the danger beyond credit fraud. Medical identifiers feed insurance fraud and targeted phishing, and unlike a bank account they cannot simply be closed. National Public Data is also a reminder that a listing disappearing changes little: two years on, there is still no confirmation that its database has stopped circulating.
What Consumers Can Do Now
For people who may be caught in the leak, the practical first step is a credit freeze at Equifax, Experian, and TransUnion plus a fraud alert on their credit files. Those controls block new credit lines but leave gaps: they do not stop fraud committed with a scanned license in person, and they do not cover existing bank or insurance accounts. Freezes and alerts should be paired with close monitoring of statements and transaction alerts at financial institutions, since account takeover is a common follow-on after document theft.
Breach victims are also a favorite target of follow-up scams. Anyone contacted with an offer to recover lost money or fix credit for an upfront fee should treat it as fraud, and suspicious contacts should be reported to the FTC and the FBI's Internet Crime Complaint Center. People whose scans may be in the Nexus cache should be especially wary of messages that claim to be from IDScan.net or a bank asking them to confirm personal details.
The longer-term fix is not individual. After a driver's license data breach of this size, the pressure on regulators to hold verification vendors to retention limits, encryption standards, and timely breach notification will decide whether the next cache is ever assembled. Businesses that outsource identity checks now have a concrete reason to ask vendors how long document images are kept and whether the originals are deleted once the check is complete.
Why this matters
The Nexus sale is the clearest sign yet that the identity checks people complete for everyday services leave a permanent, centralized archive that criminals can buy in bulk. If the alleged IDScan.net breach is confirmed, it shows consumers can be pulled into mass identity theft by companies they never dealt with directly, with no opt-out and little recourse beyond freezes and alerts. The open question is whether verification vendors will shrink the archives they keep before the next marketplace lists them.
AI-generated image.
Related Articles
- UK Airport Data Breach: 8.7 Million Travelers Face a Phishing Threat
- 23andMe Data Breach Settlement: States Win $18 Million Over 6.9 Million Genetic Records Exposed
- Framework Data Breach: Metabase Zero-Day Exposed Every Customer's Details
✔Human Verified
Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.