A massive trove of driver’s license images has been put up for sale on a dark web identity theft service, compromising the personal data of over 153 million individuals in the United States and Canada. The leak is believed to have originated from an active breach at IDScan.net, a Louisiana-based company that provides identity verification services to major brands across various industries.
According to investigative journalist Brian Krebs, who first broke the story, the stolen documents include not only driver’s licenses but also identification cards, travel documents, international IDs, and medical cards. The threat actor behind the dark web service, called Nexus, claimed to have possession of over 170 million individual identities. While the majority of the compromised records are from the United States, around 1.1 million driver’s licenses belong to Canadians.
The leaked data is likely to be a treasure trove for identity thieves and scammers, who can use the images to create fake IDs or steal sensitive information such as names, addresses, and dates of birth. The fact that some of the compromised records belong to FBI agents only adds to the severity of the breach.
IDScan.net provides ID fraud prevention services to numerous Fortune 500 companies, performing over 21 million verifications each month at more than 20,000 locations. The company’s platform is used by various industries, including banking and fintech, gaming, education, transportation, hospitality, law enforcement, retail, and security.
While the Nexus service has been shut down since Krebs’ article was published, the potential data breach remains a pressing concern for those affected. As IDScan.net investigates the incident, individuals are advised to be cautious when sharing copies of their driver’s licenses or presenting them for verification. It is recommended that they ask whether it can be checked without being scanned, photographed, or retained.
Security experts warn that this breach highlights the importance of robust identity systems and responsible data handling practices. Organizations should prioritize logging, data segregation, retention, incident notification, access to evidence, and independent assurance when working with identity providers. They should also monitor for abnormal bulk access and potential data exfiltration, including unusual activity involving service accounts, application programming interfaces, and administrative accounts.
In light of this breach, individuals should exercise caution when sharing personal identification documents, and organizations must take proactive steps to protect sensitive information from falling into the wrong hands.
Source: SecurityWeek — 2026-09-03