FBI investigates 153 million drivers licenses put up for sale on a criminal forum
A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

Why it matters
What this means for organisations holding critical data
A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.
An identity theft service advertised on a Russian cybercrime forum claimed to be selling digital scans of more than 153 million drivers licenses held by people in the United States and Canada, and the FBI has opened an official inquiry into the source of the images.
The service, known as Nexus, appeared on the long-established Exploit forum at the end of August. Alongside the licenses, it claimed to hold more than 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. The journalist Brian Krebs, whose own license was offered as a free sample in the sales thread, traced the archive to a Louisiana-based identity verification company whose customers have included FedEx and Hertz. Among the records reportedly visible in the service was the license of the United States Defense Secretary, Pete Hegseth. The FBI's New Orleans field office has since launched an investigation, and the Nexus service has apparently removed itself from the dark web.
The common thread was a routine check
Krebs found that the people he could locate in the database shared one experience: they had all hired a car from the same company. Nobody handed their license to a criminal. They handed it to a counter, an app or a scanner as part of an ordinary identity check, and the scan was kept long after the hire ended.
That is the uncomfortable part of this story. The weakness was not a stolen password or an unpatched server in the victim's life. It was a decision, made by companies acting on other companies' behalf, to retain high-resolution images of identity documents in a connected system long after the reason for collecting them had passed.
One connected repository, national-scale exposure
A single identity verification company sits between thousands of businesses and millions of people. When that company's archive is taken, the exposure is not one customer's breach. It is everyone whose identity passed through the pipeline, assembled into a single, searchable, for-sale dataset.
This is the same failure mode seen in supply chain breaches: the victim never chose the system that lost their data. The difference here is scale. One connected repository created exposure measured in nations, and the dataset will keep its value to criminals for years, as the Identity Theft Resource Center has warned.
The service stayed online. The retained data did not have to.
Verification businesses need live systems: checks happen in seconds at counters and on phones. What they do not need is years of historical scans sitting in the same connected estate, reachable by whatever path eventually fails.
Retained identity documents are the definition of data that must be kept but rarely needs to be connected. Held in Offline Secure Storage, on dedicated hardware that is physically disconnected when not in use, an archive of scans is not a searchable product on a criminal forum. It is a locked copy that only an approved, logged retrieval can reach.
What organisations should take from this
First, treat identity scans like the assets they are. A license image is enough to open accounts, pass checks and impersonate someone for years.
Second, set a retention limit and keep it. If a scan is no longer needed for the purpose it was collected, delete it. If it must be retained, move it out of the connected estate.
Third, put the question to every supplier that verifies identity on your behalf: where do the scans go, how long do they stay, and are they connected? The answer in this case appears to have been: kept for years, in a place that was reachable. Yours should be: kept briefly, and kept offline.
Sources
- TechRadar: FBI launches investigation after 153 million drivers licenses apparently leaked on Russian cybercrime forum
- KrebsOnSecurity: FBI Probes Service Selling 153M+ Drivers Licenses
- TIME: FBI Probes Possible Dark Web Sale of Over 153 Million Driver's License Scans
- Tom's Hardware: FBI investigating 153 million US and Canadian driver's licenses leaked on Russian cybercrime forum
How Firevault would handle this
Access decided by you, not assumed by the network
Control by Firevault removes standing pathways and replaces them with connection windows you approve, so stolen credentials and compromised suppliers have nothing standing to abuse.






