FBI Probes Dark Web Sale of 153 Million Driver's License Scans
Federal authorities are investigating a massive breach exposing high-resolution ID data from the U.S. and Canada.
The FBI has launched an investigation into a massive data breach involving the theft and sale of millions of driver's license scans. The breach represents a significant escalation in identity theft risks due to the high fidelity of the stolen documents.
According to verified reports, more than 153 million driver's licenses from the United States and Canada are currently for sale on the dark web. The stolen data is being distributed through a dark-web service known as "Nexus." Unlike typical breaches that leak text-based personal information, this cache includes high-resolution digital scans. These files reportedly contain photographic images as well as UV and IR scans, which are typically used by authorities to verify the authenticity of a physical ID.
The Nature of the Threat
Data breaches involving government-issued identification are treated as high-priority targets by federal law enforcement. While many leaks involve Social Security numbers or passwords—which can be changed or monitored—a driver's license is a primary physical anchor for identity. The inclusion of UV and IR scans is particularly alarming, as these security features are designed to prevent forgery. When these scans are digitized and sold, they provide bad actors with a blueprint to create near-perfect fraudulent documents.
Industry Implications
This breach exposes millions of citizens to long-term identity theft and sophisticated fraud. Because driver's licenses are used to open bank accounts, rent vehicles, and verify identities for government services, the scale of this leak could undermine trust in digital verification systems. The ability for criminals to acquire high-resolution scans allows them to bypass basic "Know Your Customer" (KYC) checks used by financial institutions, making it easier to commit large-scale financial crimes.
What's Next
Federal investigators are currently working to determine the original source of the leak and how such a vast quantity of high-resolution scans was aggregated. It remains unconfirmed whether the data was stolen from a single government entity or compiled from multiple third-party vendors and verification services. Security experts are advising citizens to monitor their credit reports and be vigilant for unusual activity, as the data is already circulating in criminal marketplaces.