Drooid Logo
Back to story perspectives

Full Breakdown

Massive Dark-Web Sale of North American Driver’s Licenses Triggers FBI Probe

9/7/2026, 11:40:37 AM

How the Breach Was Discovered

Cybersecurity journalist Brian Krebs reported that a dark-web marketplace called Nexus was offering searchable access to digital scans of driver’s licenses from the United States and Canada. The site listed records for more than 150 million licenses and included a Virginia license as a free sample to prove authenticity. After Krebs’ initial story, the Nexus site vanished from the dark web, and its login page was replaced with a notice that the service was “no longer available.”

Scope of the Compromised Data

Researchers estimate the database contained up to six image files per license—front and back scans in standard, infrared and ultraviolet formats—sufficient for the verification processes used by car-rental counters, retail kiosks and age-verification systems. A blank search of the Nexus database returned roughly 11.5 million pages of results, aligning with the claimed 153 million records. The breach also encompassed other identification and medical documents, including dispensary cards. Among the exposed records were the licenses of senior federal officials, such as U.S. Secretary of War Pete Hegseth, raising concerns that the incident extends beyond consumer privacy to national-security implications.

Responses from Authorities and Companies

The FBI’s New Orleans field office confirmed it has opened a formal investigation after learning that some stolen documents may belong to its own agents. The bureau declined to comment further while the probe remains active. IDScan.net, the identity-verification firm identified by Krebs as a likely source, said it is investigating the issue but could not share additional details. Jillian Kossman, IDScan’s marketing and operations lead, acknowledged that Krebs’ updates have been helpful to the company’s internal review.

Recommended Protective Actions

Cybersecurity experts advise anyone who has presented a driver’s license to a third-party verification service to treat the exposure as a tangible risk of document forgery and identity fraud. Recommended steps include placing a fraud alert or credit freeze with major credit bureaus, monitoring for new-account fraud, and reporting suspected misuse through the FBI’s Internet Crime Complaint Center or the Federal Trade Commission’s identity-theft recovery portal. Researchers warn that the data set is likely to retain value for cybercriminals for years, and similar services could reappear on the dark web.