TechNewsReel
Live

FBI Investigates Breach of 153 Million Driver's Licenses Linked to IDScan

A massive leak of U.S. and Canadian identity documents on the dark web has triggered federal investigations and multiple lawsuits.

TechNewsReel Newsroom · September 9, 2026

A massive leak of over 153 million U.S. and Canadian driver's licenses has surfaced on the dark web, sparking a federal investigation and a wave of litigation. The data, offered for sale via a service called Nexus, is believed to have originated from identity verification provider IDScan.net.

Security researchers Brian Krebs and Zach Edwards linked the stolen records to IDScan after discovering their own licenses within the database. The researchers validated the connection by matching the timestamps of the stolen records with the timing of their own real-world ID scans. In response to the exposure, the FBI's New Orleans field office has opened an investigation into the breach. Additionally, IDScan is now facing multiple lawsuits filed in Louisiana.

The Vulnerability of Digital Verification

Identity verification firms typically store high-resolution scans of government-issued IDs to authenticate users. These archives often include specialized infrared and ultraviolet images designed to detect forgery. While these tools are intended to secure the verification process, they create high-value targets for cybercriminals. Because these documents are difficult for victims to replace and contain immutable personal data, they are prized assets on the dark web.

Industry-Wide Implications

This breach underscores a systemic vulnerability within the identity verification industry, specifically regarding the retention of sensitive documents long after the initial check is complete. When providers retain sensitive documents after they are checked, it can create lasting exposure for millions of users.

The consequences of this specific leak are particularly severe because the stolen data includes the same infrared and ultraviolet scans used for authentication. This allows attackers to potentially create fraudulent IDs that are convincing enough to bypass the very automated verification systems designed to stop them, effectively weaponizing the industry's own security standards against its users.

Next Steps

Attention now turns to the FBI's investigation in New Orleans to determine the exact scope of the intrusion and how the data was exfiltrated. While the link to IDScan has been established by independent researchers, the full extent of the company's liability and the precise duration of the exposure remain central points of the ongoing legal battles.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.