The FBI is investigating what could be one of the largest exposures of government-issued identity documents in North American history. According to the cybersecurity journalist Brian Krebs, who broke the story, a dark-web service called Nexus surfaced this week selling digital scans of more than 153 million driver’s licenses from people in the United States and Canada, alongside millions of other ID cards, travel documents, and hundreds of thousands of medical records. The bureau’s New Orleans field office has opened a case.
The bitter irony is where the data appears to have come from. Krebs’s forensic analysis, based on timestamps and the presence of infrared and ultraviolet scan images, points to IDScan.net, a New Orleans identity-verification firm whose whole business is helping companies confirm that an ID is real. Many of the victims had one thing in common: they had rented a car from Hertz, one of IDScan’s clients, alongside retailers, casinos, and dispensaries. IDScan says it is investigating and has not confirmed a breach. If Krebs is right, a company built to prevent identity fraud has become the source of a colossal one.
Why this breach is worse than most
Two details make this especially alarming. First, it appears to be live. The operators claim to have been quietly siphoning fresh data for more than a year, and the number of records on the site reportedly grew by hundreds of thousands within a single day, suggesting the leak is ongoing rather than a one-time dump. Second, the stolen material is forgery-grade. These are not just license numbers but full front-and-back scans, including the infrared and ultraviolet versions used to check authenticity, the exact images that could defeat the “photograph your ID” checks now demanded everywhere online. Even the US Defense Secretary’s license reportedly turned up for sale, at $100.
That points to the deeper lesson. As more services, from rental counters to age-verification prompts, require you to hand over your license, the vendors that collect and store those scans have become enormous honeypots. Every business that outsources ID checks to a third party quietly inherits that vendor’s security, and its blast radius. It is the same third-party risk that keeps surfacing in breach after breach, now applied to the most sensitive documents most people own.
A report, and what to do about it
A necessary caveat: this is still an unfolding report. Krebs’s evidence pointing to IDScan is detailed and widely cited, but the company has not confirmed it and the FBI has not formally attributed the breach. The dark-web site itself vanished shortly after the story published, which complicates verification even as it does little to undo the exposure.
For the tens of millions potentially affected, the practical steps are the familiar ones, and worth taking calmly rather than in a panic. Consider freezing your credit, watch bank and card statements for anything unusual, and be especially wary of scams that use your real personal details to seem legitimate, since that is exactly what this kind of data enables.
So who is really responsible when your driver’s license leaks from a company you never chose to deal with? That is the uncomfortable question this breach forces. You handed your ID to a car-rental desk, not to a database on a Russian forum, and yet here it may be. Until ID-verification vendors are held to the security standard the data demands, the trade-off for proving who you are will keep getting riskier.
















Comments