Breaking NewsUpdated as information becomes available
News·Breach Analysis·16 September 2026·Breaking

FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
Stack of driving licence cards swept by a red scan line in front of a dark server cabinet
Stack of driving licence cards swept by a red scan line in front of a dark server cabinet

Why it matters

What this means for organisations holding critical data

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

An identity theft service advertised on a Russian cybercrime forum claimed to be selling digital scans of more than 153 million drivers licenses held by people in the United States and Canada, and the FBI has opened an official inquiry into the source of the images.

The service, known as Nexus, appeared on the long-established Exploit forum at the end of August. Alongside the licenses, it claimed to hold more than 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. The journalist Brian Krebs, whose own license was offered as a free sample in the sales thread, traced the archive to a Louisiana-based identity verification company whose customers have included FedEx and Hertz. Among the records reportedly visible in the service was the license of the United States Defense Secretary, Pete Hegseth. The FBI's New Orleans field office has since launched an investigation, and the Nexus service has apparently removed itself from the dark web.

The common thread was a routine check

Krebs found that the people he could locate in the database shared one experience: they had all hired a car from the same company. Nobody handed their license to a criminal. They handed it to a counter, an app or a scanner as part of an ordinary identity check, and the scan was kept long after the hire ended.

That is the uncomfortable part of this story. The weakness was not a stolen password or an unpatched server in the victim's life. It was a decision, made by companies acting on other companies' behalf, to retain high-resolution images of identity documents in a connected system long after the reason for collecting them had passed.

One connected repository, national-scale exposure

A single identity verification company sits between thousands of businesses and millions of people. When that company's archive is taken, the exposure is not one customer's breach. It is everyone whose identity passed through the pipeline, assembled into a single, searchable, for-sale dataset.

This is the same failure mode seen in supply chain breaches: the victim never chose the system that lost their data. The difference here is scale. One connected repository created exposure measured in nations, and the dataset will keep its value to criminals for years, as the Identity Theft Resource Center has warned.

The service stayed online. The retained data did not have to.

Verification businesses need live systems: checks happen in seconds at counters and on phones. What they do not need is years of historical scans sitting in the same connected estate, reachable by whatever path eventually fails.

Retained identity documents are the definition of data that must be kept but rarely needs to be connected. Held in Offline Secure Storage, on dedicated hardware that is physically disconnected when not in use, an archive of scans is not a searchable product on a criminal forum. It is a locked copy that only an approved, logged retrieval can reach.

What organisations should take from this

First, treat identity scans like the assets they are. A license image is enough to open accounts, pass checks and impersonate someone for years.

Second, set a retention limit and keep it. If a scan is no longer needed for the purpose it was collected, delete it. If it must be retained, move it out of the connected estate.

Third, put the question to every supplier that verifies identity on your behalf: where do the scans go, how long do they stay, and are they connected? The answer in this case appears to have been: kept for years, in a place that was reachable. Yours should be: kept briefly, and kept offline.

Sources

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Access decided by you, not assumed by the network

Control by Firevault removes standing pathways and replaces them with connection windows you approve, so stolen credentials and compromised suppliers have nothing standing to abuse.

No standing accessPaths exist only when you open them
VerificationIdentity confirmed before any connection is made
ContainmentA compromised account cannot reach what is disconnected
ControlEvery window and closure is under your command