FBI Probes Service Selling 153M+ Drivers Licenses
A dark web service called Nexus is selling digital scans of over 153 million U.S. and Canadian drivers licenses, plus millions of additional identity documents The data appears to originate from a breach at a Louisiana-based identity verification company serving Fortune 500 clients, with exfiltration ongoing for over a year FBI's New Orleans field office has launched an official inquiry into the source of the stolen images Timestamps on the license scans correlate with real-world events such as
Analysis
TL;DR
- A dark web service called Nexus is selling digital scans of over 153 million U.S. and Canadian drivers licenses, plus millions of additional identity documents
- The data appears to originate from a breach at a Louisiana-based identity verification company serving Fortune 500 clients, with exfiltration ongoing for over a year
- FBI's New Orleans field office has launched an official inquiry into the source of the stolen images
- Timestamps on the license scans correlate with real-world events such as car rentals and travel, suggesting the data is captured during active identity verification processes
- The dataset includes high-profile individuals, including U.S. Defense Secretary Pete Hegseth, and contains multi-spectral images (infrared, ultraviolet) indicating access to professional-grade verification equipment
Why It Matters
This breach represents one of the largest compilations of government-issued identity documents ever sold on the dark web, directly compromising the privacy and security of over 153 million individuals. For AI and cybersecurity practitioners, it highlights the critical risk posed by third-party identity verification vendors that aggregate sensitive biometric and document data, and underscores the need for stricter data handling audits across the verification supply chain.
Technical Details
- The Nexus service provides search access to a database containing 153M+ drivers licenses, 10M+ ID cards, 3M+ travel documents, and 579K+ medical cards, with records growing by approximately 400,000 drivers license entries within a 24-hour window
- Each compromised record can include up to six image files: three pairs of front/back license photos, a basic scan, and infrared and ultraviolet versions, with timestamps appended to filenames
- Timestamp analysis across multiple verified records correlates with real-world activities such as car rentals (Hertz) and travel, with timezones appearing to align with GMT
- The data source is attributed to a major identity verification company in Louisiana whose client base includes multiple Fortune 500 companies, suggesting the breach exploits the document capture infrastructure used during customer onboarding and KYC (Know Your Customer) verification flows
- The dataset also contains records marked with source notations such as "CDL" (commercial drivers license) and "CAC" (Common Access Cards), indicating the breach extends beyond standard consumer licenses into government and specialized identity documents
Industry Insight
- Organizations relying on third-party identity verification vendors must urgently audit their providers' security postures, data retention policies, and access controls, as a single compromised vendor can expose millions of customers across multiple Fortune 500 companies simultaneously
- The continuous exfiltration over more than a year suggests the breach may involve insider access or persistent unauthorized API/database access, reinforcing the need for real-time data loss prevention monitoring and anomaly detection on identity verification pipelines
- The inclusion of multi-spectral license images indicates the source has access to professional verification hardware, not just standard camera captures; companies should evaluate whether their verification partners are implementing proper device security, encryption at rest, and strict access logging on all document capture endpoints
Disclaimer: The above content is generated by AI and is for reference only.