Slatesource
PrivacyTerms© 2026 Slatesource
153 Million Driver's Licenses Are for Sale

153 Million Driver's Licenses Are for Sale

The biggest driver's license breach in history

On August 31, 2026, independent cybersecurity journalist Brian Krebs found his own Virginia driver's license listed as a free sample on a dark web marketplace called Nexus. The service, advertised on the Russian cybercrime forum Exploit, claimed to hold 153 million scanned US and Canadian driver's licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards. Krebs published his findings the same day. The prior record for driver's license data leaked in a single incident was roughly 6 million records, from Louisiana's 2023 exposure through the MOVEit file-transfer exploit. This breach is 25 times larger. James E. Lee, President of the Identity Theft Resource Center, which has tracked breaches since 2005, said the Nexus collection represents "one of the most extensive single leaks of driver's license data" his organisation has ever catalogued.

IDScan.net: the invisible company behind your next ID check

Krebs traced the breach to IDScan.net, a New Orleans-based company that most people have never heard of. Its scanning software sits at car rental counters, retailers, cannabis dispensaries, and age-verification checkpoints across North America. Every time a customer hands their licence to a Hertz agent or enters a Planet13 cannabis store, IDScan.net's system reads and stores it. The company did not issue a public statement. Jillian Kossman, IDScan.net's marketing and operations lead, told Krebs: "I'm not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team's investigation." The FBI's New Orleans field office opened a formal investigation on September 1, 2026. The Nexus website was taken down by September 2, but the data it was selling had already been distributed across the forum.

Six images per person. Not just a number in a database.

Most identity breaches expose text: name, date of birth, social security number. The Nexus collection is different. Each record consists of six image files: front and back photographs of the licence, a standard scan, and infrared and ultraviolet captures that reveal the security features designed to detect fakes. That last point matters. The infrared and ultraviolet images expose the hidden patterns used to distinguish a real licence from a forgery. Anyone with those images does not merely know who you are. They can replicate the document credibly. Zach Edwards, a security researcher who reviewed the data, said the breach illustrates a structural problem: "Systems are putting sensitive data into more and more third-party vendors," and those vendors do not always receive the same scrutiny as the companies that deployed them.

"

This presents multiple serious security threats. The photographic quality means these can be used to defeat facial recognition, produce convincing forgeries, and open financial accounts remotely. Larry Baldwin, principal intelligence researcher, Cybera

"
Steph
Steph
21st of September 2026

Scanned driver's licences exposed

153 million

ID cards exposed

10 million+

Travel documents exposed

3 million+

Medical cards (including cannabis dispensary)

579,000+

Images per record (including UV and infrared scans)

6

Prior single-incident DL breach record (Louisiana MOVEit, 2023)

6 million

This breach vs that record

25x larger

The Defense Secretary's licence is in there

Among the records available on Nexus was the driver's licence of US Defense Secretary Pete Hegseth. Brian Krebs found it while testing the service. It was not an edge case. Records for multiple senior US government officials were present. The breach demonstrates that the exposure is not a function of how secure any individual company is. IDScan.net's customers include some of the largest car rental and retail chains in North America. Their data sat inside a third-party verification system that the end-user companies and their customers had no visibility into. Edgar Whitley, Professor of Information Systems at the London School of Economics, described the pattern as a systemic one: institutions outsource identity verification to specialist firms, and the security of 153 million people becomes contingent on a company whose name none of them recognise.

What comes next

The Nexus site is down. The data is not. Forum posts on Exploit confirm it was downloaded extensively before the shutdown. The FBI has opened an investigation, but the agency has not confirmed whether IDScan.net is the source, and no charges have been filed. The practical exposure for the 153 million people in the database is not identity theft in the narrow sense. The larger risk is in the systems that rely on licence scans as verification. Rental car companies, banks, cryptocurrency exchanges, and dispensaries all use scan-based ID checks to onboard customers remotely. A high-quality scan, complete with ultraviolet security features, is a credible substitute for the physical document in most of those workflows. The breach does not close when the dark web site does. It opens a window that stays open for whoever downloaded the archive first.