153M U.S. and Canadian driver’s license scans offered on dark web

More than 153 million U.S. and Canadian driver’s license images were posted for sale on a dark web marketplace. A seller claimed the files came from an identity verification firm; the FBI is investigating.
More than 153 million U.S. and Canadian driver’s license scans were listed for sale on a dark web marketplace called Nexus. The seller posted the files alongside other identity documents and claimed they were taken from an identity verification provider. Federal authorities have opened a criminal investigation.
The Nexus listing included over 153 million driver’s licenses, more than 10 million other identification cards, over 3 million travel documents and international IDs, and roughly 580,000 medical cards. The seller promoted the cache on a cybercrime forum and claimed to hold IDs for more than 170 million people. A site search returned about 153 million driver’s license results, with roughly 1.1 million identified as Canadian.
An investigative journalist checked the data and found his own driver’s license and those of other people in the cache. He concluded the records were likely taken from a Louisiana-based identity verification firm, IDScan.net. The company provides ID fraud prevention, access management and age verification services, along with mobile ID scanners and an ID-activated door lock. IDScan.net performs more than 21 million verifications each month at more than 20,000 locations across industries. The company did not respond to requests for comment.
The Nexus marketplace was taken offline soon after the data was publicly reported. The FBI has opened an investigation into the alleged data theft. Some of the driver’s licenses in the cache appear to belong to FBI personnel, which contributed to the federal probe.
Collections of scanned IDs can be used to commit identity fraud, open financial accounts, bypass age checks or produce counterfeit credentials. Organizations that accept scanned IDs for onboarding or access control may need to review whether verification can be completed without creating or retaining image copies.
Tim Rawlins, senior adviser and director at NCC Group, urged organizations to assume identity evidence can be compromised and to track the identity data they collect. He recommended contracts with identity providers require logging, data segregation, retention limits, incident notification and independent assurance, and to monitor for unusual bulk access and administrative activity. Rawlins added: “A genuine-looking document cannot remain sufficient proof of identity indefinitely. Organizations should inventory identity data and establish who collects it, why it is needed, where it flows, and when it is deleted.”
Individuals are advised to avoid sharing copies of driver’s licenses unless strictly necessary and to ask whether an ID can be checked without being scanned, photographed or retained. Law enforcement and companies that rely on identity documents are reviewing controls and notification procedures as the federal investigation continues.








