FBI Investigates Dark Web Leak of 153 Million Driver’s License Scans
Key Takeaways A dark web service called Nexus offered over 153 million driver’s license scans from North American individuals. The FBI has initiated an investigation, with early indications...
Key Takeaways
- A dark web service called Nexus offered over 153 million driver’s license scans from North American individuals.
- The FBI has initiated an investigation, with early indications pointing to Louisiana-based identity verification provider IDScan.net as a potential source.
- The exposed data includes detailed front, back, infrared, and ultraviolet scans, highly valuable for sophisticated identity fraud.
- Unlike passwords, compromised physical ID scans cannot be “reset,” posing long-term risks for victims.
FBI Probes Massive Dark Web Leak of Driver’s License Scans
A clandestine dark web marketplace, known as Nexus, has reportedly been facilitating the sale of more than 153 million driver’s license scans belonging to individuals across the United States and Canada. This significant data exposure has prompted an active investigation by the FBI.
Table Of Content
Investigation Focuses on Potential Source
The New Orleans field office of the FBI has launched a probe into the origins of this vast collection of personal identification documents. Early findings suggest a possible link to IDScan.net, a Louisiana-based company specializing in identity verification services. IDScan.net processes over 21 million verifications monthly for more than 20,000 locations globally, making it a potentially lucrative target for cybercriminals.
The Nexus service first surfaced on the Russian cybercrime forum Exploit on August 31, advertising access to identity documents from over 170 million North American residents. The advertised database purportedly contained more than 153 million driver’s licenses, over 10 million additional identification cards, upwards of 3 million travel and international identity documents, and at least 579,000 medical cards.
Scope and Detail of the Compromised Data
Researchers who examined the Nexus service found the claimed number of driver’s licenses to be credible. A basic search reportedly yielded approximately 11.5 million pages of results, with each page displaying roughly 15 records. While the collection encompassed records from both countries, the majority appeared to be from U.S. residents. Approximately 1.1 million Canadian driver’s licenses were found, including 473,673 records specifically from Ontario.
The leaked material reportedly included high-resolution front and back scans of licenses, along with infrared and ultraviolet versions. These additional image layers are critical, as identity verification platforms frequently utilize them to authenticate document security features and detect fraudulent IDs. Some entries also featured date and time stamps associated with the image files, potentially indicating when the documents were originally scanned.
KrebsOnSecurity found that several individuals whose licenses appeared in the Nexus database had used their IDs for activities like travel or vehicle rentals around the timestamps present in the records. In one instance, a researcher discovered their own license scan linked to a visit to a marijuana dispensary, highlighting the specificity of the data.
IDScan.net Responds to Allegations
While IDScan.net has not confirmed a breach, the company stated it is actively investigating the claims to ascertain whether unauthorized access occurred and what information might have been compromised. Initial statements from the company emphasized that the full nature and scope of the potential incident had not yet been determined. The FBI’s involvement underscores the serious implications of such a leak.
Long-Term Risks and Aftermath
The exposure of driver’s license scans presents significant and enduring risks to victims. Unlike passwords, physical identity documents cannot simply be reset or changed after compromise. Criminals can leverage these detailed images to facilitate a wide array of illicit activities, including account takeovers, synthetic identity fraud, fraudulent loan and credit applications, SIM-swapping attacks, and sophisticated social engineering schemes. Furthermore, high-quality facial images could pose privacy and safety concerns for individuals seeking to remain unlocated.
Following public disclosure, Nexus reportedly ceased operations, replacing its login page with a message indicating the service was no longer available. However, the disappearance of one dark web storefront does not guarantee the data’s removal. The records may have already been copied, resold, or migrated to other criminal marketplaces, ensuring their continued illicit availability.
This incident critically highlights the inherent risks associated with organizations collecting and retaining large volumes of sensitive identity documents. It reinforces the necessity for robust security practices within companies that handle such data.
What You Should Do
- Monitor Credit and Financial Accounts: Regularly check your credit reports for any suspicious activity or unauthorized accounts. Consider placing a credit freeze.
- Enable Multi-Factor Authentication (MFA): Activate MFA on all online accounts, especially financial, email, and social media, to add an extra layer of security.
- Be Wary of Phishing Attempts: Exercise extreme caution with unsolicited emails, calls, or texts, as fraudsters may use leaked information to craft more convincing social engineering attacks.
- Review Privacy Settings: Limit the amount of personal information you share online and review privacy settings on all accounts.
- Report Suspicious Activity: If you suspect your identity has been compromised, report it to relevant authorities and financial institutions immediately.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.