A trove of identity documents allegedly containing more than 153 million US and Canadian driver’s licenses has drawn the attention of the FBI after appearing for sale in the cybercrime underground. The collection also reportedly included millions of passports, identification cards and other sensitive records, according to Yahoo News and Tom's Hardware.
Cybersecurity journalist Brian Krebs investigated the database after a copy of his own driver’s license was posted as a promotional sample on Exploit, a Russian-language cybercrime forum. The seller operated a service known as Nexus, which allowed prospective customers to search its collection. Nexus has since gone offline.
Krebs tested the database with several people he knew, after obtaining their permission, and found records that appeared authentic. He also reported seeing a preview of information associated with US Secretary of Defense Pete Hegseth. That discovery raised the stakes of the incident, given the potential security implications of exposing identification belonging to senior government officials.
Rather than originating directly from the businesses where customers presented their IDs, the data may have passed through a common third-party verification provider. Several affected people had previously supplied identification while renting vehicles from Hertz. Security researcher Zach Edwards, whose information also appeared in Nexus, traced his record to an ID check performed at Planet 13, a cannabis dispensary.
The Yahoo report says that both companies relied on Louisiana-based IDScan for identity-verification services, according to Krebs. Timestamps attached to some of the exposed scans reportedly corresponded with the dates and times the individuals had presented their identification. That overlap led investigators to focus on IDScan as a possible common link, although the precise cause and scope of the apparent compromise have not been publicly established.
The scale extends well beyond driver’s licenses. Nexus claimed its inventory included roughly 10 million ID cards, 1.9 million travel documents, 1.3 million international driving permits, hundreds of thousands of medical, residence and employment-related records, and about five million documents in other categories.
IDScan told Krebs that it was examining the information he provided but was not yet in a position to disclose further details. Meanwhile, the FBI’s New Orleans field office has reportedly opened an investigation into the incident.
Beyond the sheer number of records, the type of information involved makes the apparent breach particularly significant. Detailed scans of government-issued identification can provide criminals with material for impersonation, fraudulent financial applications and other forms of identity theft. Some leaked licenses reportedly included photographic as well as UV and infrared scan data, potentially making misuse more sophisticated.
The episode also illustrates a broader privacy concern surrounding outsourced identity checks. When businesses rely on centralized verification companies, large volumes of highly sensitive documents can flow through a relatively small number of providers. A compromise at one point in that chain can therefore expose customers from multiple unrelated businesses at once, while creating potentially serious consequences for people whose personal information or whereabouts require additional protection.