The FBI is reportedly investigating a major identity theft case after digital scans of more than 153 million driver's licences from the United States and Canada were offered for sale on the dark web. The data is allegedly linked to a breach involving an identity verification service, while other documents including medical and residence cards were also reportedly exposed.
What Data Is Being Sold on the Dark Web
A newly launched identity theft service known as "Nexus" is reportedly selling digital scans of more than 153 million driver's licences belonging to people in the US and Canada. The people behind the service claim the licence images came from an active breach at a major identity verification company, whose customers reportedly include several Fortune 500 companies.
The report said additional documents exposed through this wider security breach include medical cards, residence cards, and other records.
How the Alleged Breach Was Discovered
KrebsOnSecurity reported that it was able to confirm the authenticity of the criminals' claim, after they provided a scan of the reporter's own driving licence as proof. Other victims also reportedly confirmed that the scans shown to them were accurate.
The hackers were also said to be continuing to obtain data even after this initial exposure. According to the report, nearly 400,000 additional scans were added within a 24-hour period, suggesting the breach was still actively growing.
What the FBI Is Investigating
The FBI's New Orleans field office reportedly launched an official inquiry into the source of the licence images. This investigation is focused on determining exactly where the documents originated, and how such a large collection of identity records allegedly reached the criminals operating this dark web service.
The identity verification company believed to be involved is reported to be based in Louisiana, though available information doesn't identify the company by name.
Which Companies Could Be Connected to the Exposed Data
The report indicates that at least some of the information may have been stolen from a verification service used by rental car company Hertz. It also points to a New Orleans-based company as a potential source, whose reported client list includes Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment.
It's important to note that available information doesn't establish that each of these companies suffered a direct breach themselves. Rather, they're identified simply as clients of the company cited as a potential source of the leaked data.
Why Stolen Driver's Licence Scans Are Particularly Dangerous
Driver's licences contain personal information that can be genuinely valuable to criminals attempting identity theft. This reported breach is particularly concerning, because the documents were allegedly taken from a service specifically designed to verify people's identities, meaning the stolen data comes from a source that's supposed to be a trusted checkpoint, not a vulnerability.
The sale of actual digital scans could give criminals access to documents that may be misused in identity-related fraud. The presence of medical cards, residence cards, and other documents could further increase the amount of personal information exposed for each affected individual.
What Happens Next
The FBI inquiry is expected to focus on identifying the source of the images and establishing the extent of this reported breach. The claim that more than 153 million licence scans are being sold remains central to the ongoing investigation.
This case also highlights the genuine risks created when organisations holding large collections of identity documents are compromised. Determining exactly what information was accessed, where it came from, and whose records were affected will be critical as the investigation continues.
FAQs
Q1. How many driver's licences were allegedly exposed in this breach?
More than 153 million digital scans of driver's licences from the US and Canada were reportedly offered for sale on the dark web through a service called "Nexus."
Q2. How was the authenticity of the breach confirmed?
KrebsOnSecurity confirmed the claim after the hackers provided a scan of the reporter's own driving licence, and other victims also verified their scans were accurate.
Q3. Which companies are potentially connected to the exposed data?
The report points to a New Orleans-based identity verification company as a potential source, with a client list reportedly including Hertz, Target, FedEx, Motorola Solutions, Jack Henry, and Caesars Entertainment, though direct breaches at these companies haven't been established.