A threat actor began offering digital scans of more than 153 million U.S. and Canadian driver’s licenses on the dark web this week, in what investigative journalist Brian Krebs has linked to a likely breach at identity-verification firm IDScan.net.
A Large, Verified Identity Document Cache
The documents surfaced on an identity-theft service called Nexus, while a threat actor simultaneously promoted the same data on a Russian-language cybercrime forum, claiming to hold identification documents for more than 170 million individuals. According to Krebs, a blank search on Nexus returned approximately 153 million driver’s license results, of which only around 1.1 million were Canadian, alongside more than 10 million identification cards, over 3 million travel documents and international IDs, and roughly 580,000 medical cards.
Krebs reported that after confirming his own driver’s license, and those of other individuals, appeared on the platform, he concluded the documents were likely siphoned from IDScan.net, a Louisiana-based identity-verification provider whose services include ID fraud prevention, access management, age verification, ID-activated door locks and mobile ID scanners. The company says it performs more than 21 million verifications per month across more than 20,000 locations for clients spanning automotive, banking, gaming, education, transportation, hospitality, law enforcement, retail and security industries.
FBI Investigation and Shutdown
The Nexus platform was taken offline shortly after Krebs published his findings. Separately, the FBI opened an investigation into the suspected IDScan breach after determining that some of the exposed driver’s licenses belonged to its own agents. IDScan.net had not issued a public statement on the incident as of this writing.
What Organizations Should Take From It
NCC Group senior adviser Tim Rawlins said the incident underscores that identity systems should be designed on the assumption that identity evidence will eventually be compromised. “A genuine-looking document cannot remain sufficient proof of identity indefinitely,” Rawlins said, adding that organizations should inventory what identity data they hold, establish clear retention and deletion policies, and set contractual requirements with identity vendors covering logging, data segregation, incident notification and independent assurance. He also recommended monitoring for abnormal bulk access to identity systems, including unusual service-account and API activity.

Leave a Reply