The Federal Bureau of Investigation (FBI) has launched an investigation after millions of drivers’ licenses were listed for sale on the dark web.
Independent cybersecurity researcher Brian Krebs discovered the leak after threat actors uploaded his driver’s license as a free sample on the Russian-language hacking forum Exploit.
The attackers were advertising Nexus, a dark web marketplace that also listed Secretary of Defense Pete Hegseth’s documents, selling for $100.
Hackers sell 153 million drivers’ licenses on the dark web
At least 153 million drivers’ licenses from people in the United States and 10 million from Canadians were listed for sale on the dark web marketplace. For Canadian victims, most of the leaked drivers’ licenses, approximately 473,673 records, originated from the country’s central-eastern province of Ontario.
Other documents listed on the dark web marketplace included 3 million travel documents, international drivers’ licenses or IDs, and at least 579,000 medical cards, including marijuana dispensary cards.
Common Access cards used by government employees to access secure locations, travel cards, residence cards, and employment authorization documents were also listed. Some of the documents listed the source as CDL, which refers to “commercial driver’s license.”
“I am far less interested in how the threat actors gained access than in why all this data was sitting there waiting to be stolen,” said Donald McFarlane, Advisory Board Member, Xcape. “IDScan’s own documentation says their product defaults to ‘Collect all’ and retaining all records, and even touts the resulting PII and demographic data for retail and marketing purposes. For some customers, IDScan provides retention choices; remarkably, its Basic plan appears to require collecting everything and provides no option to delete it. Checking my ID is one thing. Building a permanent dossier because I showed it to you once is quite another.”
The leaked drivers’ licenses included basic and front-and-back scans, as well as infrared and ultraviolet versions. Customer photos were also displayed, if available, alongside redacted information. The filenames contained their exfiltration dates and timestamps.
“A license contains the owner’s date of birth, address, physical descriptors, and a government-issued ID number,” said Seemant Sehgal, Founder & CEO, BreachLock. “This is enough data to pass identity verification checks that most financial institutions and government agencies still treat as reliable. The harder problem is that unlike a compromised password, none of those fields can be changed, so every person in this dataset will carry this exposure with them for life. It’s good that this isn’t being taken lightly, but it may be time to raise the standard for ID verification checks.”
Dark web marketplace updates stolen drivers’ licenses in real time
Krebs traced the leak to a breach of popular Louisiana-based identity verification service IDScan.net, which serves numerous organizations, including Fortune 500 companies. The company says it scans identity documents using both ultraviolet and infrared light.
The documents were obtained from various establishments, such as bars, a weed store, a car rental service, and airports that potentially use IDScan for identity verification. All domestic travel currently requires identity verification, creating numerous opportunities for threat actors to access personal information.
Planet 13, a Las Vegas-based marijuana dispenser, car rental giant Hertz, and 11 other companies mentioned in the report had identity verification arrangements with IDScan. However, they could not be directly linked to the personal information breach.
Nevertheless, most of the analyzed documents matched the victims’ travel and car rental history, or their visits to various establishments that use IDScan for identity verification.
“One person whose license was in Nexus hadn’t flown at all recently, but was renting a car from Hertz for several months around the date of their timestamp,” he wrote.
Krebs validated the authenticity of the leaked documents by conducting blank searches and cross-referencing details from nine known victims, including some relatives and federal employees.
He also noted that the dark web marketplace was updating the stolen drivers’ licenses in real time, adding over 400,000 records within 24 hours. The rapid update frequency suggests that the threat actors maintained access and relied heavily on automation.
“This looks less like someone stole a database once and more like someone had persistent access to trusted systems or identities,” said Kevin Surace, CEO, Token. “If an attacker gets in as an employee, administrator, contractor or service account, database encryption does not save you because the system treats them as authorized. We do not yet know whether compromised credentials or legacy MFA were the entry point, but that seems likely.”
However, the dark web service was taken offline after the report was published, and the FBI and IDScan are investigating the matter.

