TechNewsReel
Live

FBI Probes Sale of 153 Million U.S. and Canadian Driver's License Scans

A massive leak of high-resolution identity documents linked to verification vendor IDScan.net threatens to undermine global ID authentication systems.

TechNewsReel Newsroom · September 10, 2026

The FBI has launched an investigation into the attempted sale of more than 153 million driver's license scans from the United States and Canada. The breach, discovered on the dark-web service Nexus, represents one of the largest exposures of government-issued identification in history.

The FBI's New Orleans field office is leading the official probe. The dataset offered by Nexus contains high-resolution front and back scans of licenses. Crucially, the records include infrared and ultraviolet images—specialized captures typically available only to commercial verification terminals rather than consumer-grade scanners.

The Link to IDScan.net

Security journalist Brian Krebs and researcher Zach Edwards have linked the stolen data to IDScan.net, an identity verification vendor based in New Orleans. The investigation into the source of the leak relied on forensic analysis of the images and metadata.

Evidence connecting the breach to the vendor included timestamps on the stolen licenses that matched specific real-world transactions. Specifically, researchers found data corresponding to visits to Planet 13, a dispensary that partnered with IDScan.net, providing a concrete link between the stolen records and the vendor's processing pipeline.

A Critical Security Failure

This breach is uniquely dangerous because it exposes the exact security features used to prevent fraud. Most high-security identity verification systems rely on infrared and ultraviolet passes to authenticate the authenticity of a physical ID card. By possessing these specific scans, attackers can potentially create fraudulent digital submissions that are nearly indistinguishable from legitimate documents.

Because these images bypass the traditional hurdles of identity verification, the leak undermines trust in automated KYC (Know Your Customer) systems used by banks, rental agencies, and government portals globally. The ability to spoof these high-level security markers allows for a level of identity theft that far exceeds the risk posed by simple photo leaks.

What Remains Unconfirmed

While the FBI continues its investigation, the full extent of the compromise remains unclear. It is not yet officially confirmed how the data was exfiltrated or how long the vulnerability existed. Investigators are expected to focus on whether the breach resulted from a direct attack on IDScan.net's infrastructure or a failure in a third-party integration. For now, the industry is watching to see if other verification vendors using similar technology have been targeted in a coordinated campaign.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.