---
title: "FBI investigates 153 million drivers licenses p… | Firevault"
description: "A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026#webpage",
      "url": "https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026",
      "name": "FBI investigates 153 million drivers licenses p…",
      "description": "A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/news/fbi-drivers-licenses-dark-web-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "FBI investigates 153 million drivers licenses put up for sale on a criminal forum",
          "item": "https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "FBI investigates 153 million drivers licenses put up for sale on a criminal forum",
      "description": "A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.",
      "url": "https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/fbi-drivers-licenses-dark-web-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/fbi-drivers-licenses-dark-web-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/fbi-drivers-licenses-dark-web-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/news/fbi-drivers-licenses-dark-web-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-16T16:24:20.99349+00:00",
      "dateModified": "2026-09-16T16:45:23.845613+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 675,
      "keywords": "Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "An identity theft service advertised on a Russian cybercrime forum claimed to be selling digital scans of more than 153 million drivers licenses held by people in the United States and Canada, and the FBI has opened an official inquiry into the source of the images. The service, known as Nexus, appeared on the long-established Exploit forum at the end of August. Alongside the licenses, it claimed ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What happened with the 153 million drivers licenses?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A dark web service called Nexus, advertised on the Russian cybercrime forum Exploit, claimed to be selling digital scans of more than 153 million drivers licenses from the United States and Canada, along with millions of other identity documents. The FBI New Orleans field office has opened an inquiry into the source of the images."
          }
        },
        {
          "@type": "Question",
          "name": "Whose licenses were in the dataset?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The records reportedly included the license of the United States Defense Secretary, Pete Hegseth, and the security journalist Brian Krebs, whose own license was offered as a free sample in the sales thread on Exploit."
          }
        },
        {
          "@type": "Question",
          "name": "Where did the scans come from?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The investigation by Brian Krebs traced the archive to a Louisiana-based identity verification company whose customers have included FedEx and Hertz. A common factor among the people he located in the database was that they had all hired a car from the same company."
          }
        },
        {
          "@type": "Question",
          "name": "Has the Nexus service been taken down?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The service has apparently removed itself from the dark web since the story became public. However, the Identity Theft Resource Center has warned that a dataset of this size will keep its value to criminals for many years, and a similar service is likely to appear again."
          }
        },
        {
          "@type": "Question",
          "name": "Why do companies keep driving licence scans?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Identity verification companies retain scans for age checks, fraud prevention and regulatory record keeping. The risk is retention without limit: once the reason for the check has passed, an archive of identity images that stays connected becomes a target rather than an asset."
          }
        },
        {
          "@type": "Question",
          "name": "How can organisations reduce this risk?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Set a retention limit and delete scans that are no longer needed. Where documents must be retained, hold them in offline storage on dedicated hardware that is physically disconnected when not in use, so the archive cannot be searched, copied or sold from a distance."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Breaking News Updated as information becomes available 

Overview

The common thread was a routine …One connected repository, nation…The service stayed online. The r…What organisations should take f…SourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 16 September 2026 · Breaking 

# FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-investigates-153-million-drivers-licenses-dark-web-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-investigates-153-million-drivers-licenses-dark-web-2026&text=FBI%20investigates%20153%20million%20drivers%20licenses%20put%20up%20for%20sale%20on%20a%20criminal%20forum%0A%0AA%20dark%20web%20service%20claimed%20to%20be%20selling%20scans%20of%20more%20than%20153%20million%20drivers%20licenses%2C%20apparently%20taken%20from%20a%20Louisiana%20identity%20verification%20company%20used%20by%20household%20names.%20The%20FBI%20has%20opened%20an%20inquiry%2C%20and%20the%20case%20shows%20how%20long%20retention%20turns%20a%20routine%20check%20into%20national-scale%20exposure.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-investigates-153-million-drivers-licenses-dark-web-2026)[](mailto:?subject=FBI%20investigates%20153%20million%20drivers%20licenses%20put%20up%20for%20sale%20on%20a%20criminal%20forum&body=A%20dark%20web%20service%20claimed%20to%20be%20selling%20scans%20of%20more%20than%20153%20million%20drivers%20licenses%2C%20apparently%20taken%20from%20a%20Louisiana%20identity%20verification%20company%20used%20by%20household%20names.%20The%20FBI%20has%20opened%20an%20inquiry%2C%20and%20the%20case%20shows%20how%20long%20retention%20turns%20a%20routine%20check%20into%20national-scale%20exposure.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Ffbi-investigates-153-million-drivers-licenses-dark-web-2026)

![Stack of driving licence cards swept by a red scan line in front of a dark server cabinet](/news/fbi-drivers-licenses-dark-web-2026.jpg)

Stack of driving licence cards swept by a red scan line in front of a dark server cabinet

Why it matters

## What this means for organisations holding critical data

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

In this analysis

1.  01 [The common thread was a routine …](#section-0)
2.  02 [One connected repository, nation…](#section-1)
3.  03 [The service stayed online. The r…](#section-2)
4.  04 [What organisations should take f…](#section-3)

**On this page**[The common thread was a routine …](#section-0)[One connected repository, nation…](#section-1)[The service stayed online. The r…](#section-2)[What organisations should take f…](#section-3)

An identity theft service advertised on a Russian cybercrime forum claimed to be selling digital scans of more than 153 million drivers licenses held by people in the United States and Canada, and the FBI has opened an official inquiry into the source of the images.

The service, known as Nexus, appeared on the long-established Exploit forum at the end of August. Alongside the licenses, it claimed to hold more than 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. The journalist Brian Krebs, whose own license was offered as a free sample in the sales thread, traced the archive to a Louisiana-based identity verification company whose customers have included FedEx and Hertz. Among the records reportedly visible in the service was the license of the United States Defense Secretary, Pete Hegseth. The FBI's New Orleans field office has since launched an investigation, and the Nexus service has apparently removed itself from the dark web.

## The common thread was a routine check

Krebs found that the people he could locate in the database shared one experience: they had all hired a car from the same company. Nobody handed their license to a criminal. They handed it to a counter, an app or a scanner as part of an ordinary identity check, and the scan was kept long after the hire ended.

That is the uncomfortable part of this story. The weakness was not a stolen password or an unpatched server in the victim's life. It was a decision, made by companies acting on other companies' behalf, to retain high-resolution images of [identity documents](/oss-for-identity-documents) in a connected system long after the reason for collecting them had passed.

## One connected repository, national-scale exposure

A single identity verification company sits between thousands of businesses and millions of people. When that company's archive is taken, the exposure is not one customer's breach. It is everyone whose identity passed through the pipeline, assembled into a single, searchable, for-sale dataset.

This is the same failure mode seen in supply chain breaches: the victim never chose the system that lost their data. The difference here is scale. One connected repository created exposure measured in nations, and the dataset will keep its value to criminals for years, as the Identity Theft Resource Center has warned.

## The service stayed online. The retained data did not have to.

Verification businesses need live systems: checks happen in seconds at counters and on phones. What they do not need is years of historical scans sitting in the same connected estate, reachable by whatever path eventually fails.

Retained identity documents are the definition of data that must be kept but rarely needs to be connected. Held in [Offline Secure Storage](/offline-secure-storage), on dedicated hardware that is physically disconnected when not in use, an archive of scans is not a searchable product on a criminal forum. It is a locked copy that only an approved, logged retrieval can reach.

## What organisations should take from this

First, treat identity scans like the assets they are. A license image is enough to open accounts, pass checks and impersonate someone for years.

Second, set a retention limit and keep it. If a scan is no longer needed for the purpose it was collected, delete it. If it must be retained, move it out of the connected estate.

Third, put the question to every supplier that verifies identity on your behalf: where do the scans go, how long do they stay, and are they connected? The answer in this case appears to have been: kept for years, in a place that was reachable. Yours should be: kept briefly, and kept offline.

## Sources

-   [TechRadar: FBI launches investigation after 153 million drivers licenses apparently leaked on Russian cybercrime forum](https://www.techradar.com/pro/security/fbi-launches-investigation-after-153-million-drivers-licenses-apparently-leaked-on-russian-cybercrime-forum)
-   [KrebsOnSecurity: FBI Probes Service Selling 153M+ Drivers Licenses](https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/)
-   [TIME: FBI Probes Possible Dark Web Sale of Over 153 Million Driver's License Scans](https://time.com/article/2026/09/03/fbi-probes-reported-dark-web-drivers-license-breach/)
-   [Tom's Hardware: FBI investigating 153 million US and Canadian driver's licenses leaked on Russian cybercrime forum](https://www.tomshardware.com/tech-industry/cyber-security/fbi-investigating-153-million-us-and-canadian-drivers-licenses-leaked-on-russian-cybercrime-forum-including-that-of-us-secdef-pete-hegseth-data-is-suspected-to-have-come-from-an-id-authentication-service-provider)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Access decided by you, not assumed by the network

Control by Firevault removes standing pathways and replaces them with connection windows you approve, so stolen credentials and compromised suppliers have nothing standing to abuse.

[Get started](/get-started)[Talk to the team](/demo)

**No standing access**Paths exist only when you open them 

**Verification**Identity confirmed before any connection is made 

**Containment**A compromised account cannot reach what is disconnected 

**Control**Every window and closure is under your command 

Related Reading

## You may also find these useful

[

![Southport court files breach: the access was authorised, the purpose was not](/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg)

Breach Analysis 

### Southport court files breach: the access was authorised, the purpose was not

The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.

16 Sept 2026 4 min 







](/news/southport-court-files-insider-access-breach-2026)[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)[

![Quinn Emanuel and McDermott breached as law firms become the soft route to client data](/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg)

Breach Analysis 

### Quinn Emanuel and McDermott breached as law firms become the soft route to client data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

8 Sept 2026 4 min 







](/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026)[

![Mathspace breach exposes more than one million students, staff and parents](/images/news/mathspace-data-breach-one-million-students-2026.jpg)

Breach Analysis 

### Mathspace breach exposes more than one million students, staff and parents

An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

8 Sept 2026 4 min 







](/news/mathspace-data-breach-one-million-students-2026)[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)