Skip to main content
Identity VerificationSecurity Investigation· 4 min read· in Technology

FBI Investigates Dark Web Sale of 153 Million Driver's Licenses Linked to IDScan.net

A dark web marketplace claimed to possess 153 million digital scans of driver's licenses from the U.S. and Canada. The FBI has opened an investigation into the breach, which security researchers have linked to Louisiana-based identity verification vendor IDScan.net.

By Diego Navarro

Cybersecurity Researchers 40%Identity Verification Vendors 30%Consumer Privacy Advocates 30%
Cybersecurity Researchers
Focus on the concentration risk, arguing that retaining high-resolution scans creates a single point of failure.
Identity Verification Vendors
Focus on fraud prevention and compliance, arguing centralized databases are necessary to catch sophisticated fake IDs.
Consumer Privacy Advocates
Focus on the lack of transparency, arguing users are forced to hand over biometric data without knowing how long it is stored.

Perspectives this story doesn't cover

  • Affected consumers whose data was exposed
  • Client businesses whose customers were compromised

The operators of a newly launched dark web marketplace claim they spent the last year quietly exfiltrating 153 million driver's license scans from a major corporate database, packaging the high-resolution infrared and ultraviolet images for sale to identity thieves. Louisiana-based identity verification vendor IDScan.net, whose hardware and software process millions of those exact scans each month for Fortune 500 clients, maintains that it is actively investigating the reports but has not confirmed any unauthorized access to its systems. The Federal Bureau of Investigation's New Orleans field office has opened an official inquiry into the incident, declining to comment on the source or scope of the data while the investigation remains active.[3][4]

The database emerged this week on Exploit, a Russian-language cybercrime forum, under the marketplace name "Nexus." The operators advertised a staggering inventory: 153 million U.S. and Canadian driver's licenses, 10 million identification cards, 3 million travel documents, and 579,000 medical and dispensary cards. While threat actors frequently inflate record counts to attract buyers, independent cybersecurity journalists who accessed the Nexus portal before it vanished reported that a blank search returned approximately 11.5 million pages of results, suggesting the volume claims were mathematically plausible.[1][2][4]

The evidence linking the cache to IDScan.net relies on the metadata attached to the stolen images. Cybersecurity reporter Brian Krebs located his own Virginia driver's license in the database, complete with front and back scans. The file's timestamp matched a June 2025 transaction where he presented the ID at a Hertz rental counter. Similarly, security researcher Zach Edwards found his license with a timestamp corresponding to a visit to a Planet13 cannabis dispensary in Las Vegas.[4]

The Nexus marketplace claimed to possess over 166 million digital identity documents, predominantly U.S. and Canadian driver's licenses.

Both Hertz and Planet13 are publicly advertised clients of IDScan.net. The vendor markets its technology as a comprehensive fraud prevention and age verification suite, claiming its systems perform over 21 million verifications each month across 20,000 locations. The hardware captures the barcode data, magnetic stripe information, and specialized security features of government-issued IDs, centralizing that data to verify authenticity.[2][4]

Both Hertz and Planet13 are publicly advertised clients of IDScan.net.

When presented with the timestamp correlations, IDScan.net acknowledged the inquiry but offered no technical explanation. Jillian Kossman, a marketing and operations leader at the company, told researchers that the provided updates were "helpful to our team's investigation," but stated she was unable to share additional information. The Nexus marketplace disappeared from the dark web shortly after the initial reports were published, a common tactic when threat actors attract unwanted federal attention.[1][3][4]

The incident exposes the mechanical reality of modern identity verification. When a consumer hands their license to a retail clerk or uploads it to an app, the business rarely processes the data itself. Instead, it routes the image through specialized third-party vendors. This architecture solves the immediate fraud problem for the retailer but creates massive, centralized repositories of the exact documents that banks, government agencies, and telecom providers use to establish identity.[3][4]

The FBI's New Orleans field office has opened an official inquiry into the reported data theft.

If the Nexus operators' claims hold true, the breach represents a catastrophic failure of data retention policies. In their introductory forum post, the threat actors stated, "We have been continuously exfiltrating new data for over a year into our private database." The presence of year-old scans in an active database suggests that the verification vendor was not merely checking the IDs and discarding the images, but storing the high-resolution files indefinitely.[1][3]

The long-term utility of this data makes it uniquely dangerous. Unlike a compromised credit card, which a bank can cancel and reissue in minutes, a driver's license contains static biometric and demographic information. James E. Lee, President of the Identity Theft Resource Center, noted that this specific dataset will retain massive value to the cybercriminal community for years, providing the foundational documents required to bypass two-factor authentication and execute account takeovers.[1]

The stakes

Businesses increasingly require digital ID scans for routine transactions, centralizing highly sensitive biometric data in third-party vendors. If confirmed, this breach means millions of consumers have lost control of the exact documents financial institutions use to verify identity, significantly elevating the risk of account takeover.

The essentials

  1. A dark web marketplace claimed to possess 153 million digital scans of U.S. and Canadian driver's licenses.
  2. The FBI's New Orleans field office has opened an official investigation into the reported data theft.
  3. Cybersecurity researchers linked the stolen files to IDScan.net by matching timestamps to specific retail transactions.
  4. The exposed data reportedly includes high-resolution infrared and ultraviolet scans used to verify document authenticity.
  5. IDScan.net acknowledged the reports and stated it is actively investigating the claims.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Cybersecurity Researchers 40%Identity Verification Vendors 30%Consumer Privacy Advocates 30%
  1. [1]TIMEConsumer Privacy Advocates

    FBI Probes Report of Breach Exposing 153 Million Driver's License Scans

    Read on TIME
  2. [2]SecurityWeekIdentity Verification Vendors

    153 Million Driver License Images Offered on Dark Web

    Read on SecurityWeek
  3. [3]CSO OnlineCybersecurity Researchers

    FBI investigates breach of 153 million driving license records at IDscan.net

    Read on CSO Online
  4. [4]eSecurity PlanetCybersecurity Researchers

    FBI Investigates Dark Web Trove of 153 Million Driver's Licenses

    Read on eSecurity Planet
  5. [5]RH-ISACConsumer Privacy Advocates

    FBI Investigates Listing of 153M+ Drivers Licenses for Sale

    Read on RH-ISAC
  6. [6]KIRO 7Consumer Privacy Advocates

    FBI investigates theft of 153M drivers licenses

    Read on KIRO 7

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.