Breaking News

153 Million Driver's License Scans Went Up for Sale on the Dark Web. The FBI Found Its Own Agents in the Pile.

A site called Nexus advertised front-and-back images, plus infrared and ultraviolet scans, of American and Canadian IDs. Investigators suspect the source is a Louisiana verification firm that runs more than 21 million ID checks a month.

· 3 min read
153 Million Driver's License Scans Went Up for Sale on the Dark Web. The FBI Found Its Own Agents in the Pile.

More than 153 million scanned American and Canadian driver's licenses were put up for sale this week on a dark web identity-theft service called Nexus, alongside over 10 million state identification cards, more than 3 million passports and other international travel documents, and roughly 580,000 medical cards, including marijuana dispensary cards.

The trove was first reported by investigative journalist Brian Krebs, who has been tracking the seller. The operator promoted the service on a Russian-language cybercrime forum and claimed to be holding identity documents belonging to more than 170 million people. Only about 1.1 million of the driver's licenses in the collection were Canadian; the overwhelming majority were issued by U.S. states.

What makes the collection unusual is not the count but the fidelity. These are not text records scraped out of a database. They are photographs of the physical documents — front and back, plus the infrared and ultraviolet captures that verification hardware takes to confirm a license is not a forgery. Several carried timestamps that lined up with the moment the holder was renting a car or checking in somewhere, which is exactly what an identity check at a rental counter looks like from the inside.

Krebs identified the likely source as IDScan.net, a Louisiana-based identity verification company. IDScan.net sells ID fraud prevention, access management, and age verification tools, and says it performs more than 21 million verifications a month at over 20,000 locations. Its customer list runs through automotive, banking, gaming, education, transportation, hospitality, law enforcement, retail, and security — Fortune 500 companies among them. A person handing a license to a car rental agent, a casino cage, or a dispensary counter has no way of knowing whose software is reading it.

The FBI opened an investigation after learning that some of the compromised licenses belonged to its own agents. The Nexus platform went dark shortly after Krebs published, which is the usual pattern when a marketplace draws federal attention, and which does nothing about the copies already sold.

The practical exposure here is worse than a leaked password. A license image is the raw material for opening accounts, taking over existing ones, passing "upload a photo of your ID" checks at banks and crypto exchanges, and defeating the exact verification step the industry built to stop fraud. Passwords can be rotated in an afternoon. A driver's license number and a photograph of the card are good until the state reissues them, and most states will not reissue on request without a documented reason.

Anyone who has rented a car, opened a bank account in person, or been age-checked at a licensed retailer in the last several years should assume their document may be in a collection like this one and watch their credit accordingly.

Originally reported by SecurityWeek.

data breach dark web drivers licenses identity theft fbi idscan